内核模式驱动程序证书更新及到期后签名流程咨询
Hey there, let's break down your two questions about kernel-mode driver certificates clearly:
1. 如何更新内核模式驱动程序证书?
Updating a kernel-mode driver certificate involves a few key steps, tailored to how you originally obtained your signature:
- Step 1: Secure a valid new certificate
If you're renewing an existing certificate (either an EV code-signing cert or one tied to Microsoft's WHQL program), make sure you go through the official renewal process with your certificate authority (CA) or the Windows Hardware Developer Center. Ensure the new certificate meets Microsoft's current requirements for kernel-mode driver signing. - Step 2: Re-sign your driver package
Use thesigntoolutility (included with the Windows SDK) to re-sign your driver files with the new certificate. A typical command looks like this:
Critical note: Always include a trusted timestamp—this ensures your driver remains valid even after the new certificate expires, as it proves the signature was applied while the cert was active.signtool sign /f "new_certificate.pfx" /p "your_cert_password" /t "http://timestamp.digicert.com" /v "your_driver.sys" - Step 3: Replace and distribute the updated driver
Swap out the old signed driver files with the newly signed ones. If you distribute via Windows Update, you'll need to upload the re-signed driver package to the Windows Hardware Developer Center to update your listing. For manual distribution, ensure users install the new version (old versions with expired certs will be blocked by Windows' driver signature enforcement).
2. 证书到期后,需要重新提交微软驱动签名流程还是仅重新签名?
This depends on the type of signature you're using:
- If you have a WHQL-signed driver
You don't need to re-submit the entire WHQL compatibility test process when your certificate expires. Just use your renewed certificate to re-sign the driver package (with a timestamp, as mentioned earlier) and distribute it. The underlying WHQL cross-signature from Microsoft remains valid, so the re-signed driver will still be trusted by Windows. That said, if you make significant changes to the driver (like adding new features or changing compatibility), you'll need to re-run WHQL testing. - If you're using an EV code-signing certificate (without WHQL)
Similarly, you only need to re-sign the driver with your renewed EV certificate (plus a timestamp). No need to re-submit to Microsoft's driver signature process—so long as the new certificate is valid and issued by a CA trusted by Microsoft, the re-signed driver will pass Windows' signature checks.
Again, the timestamp is non-negotiable here—it's what keeps your driver working long after the certificate itself expires.
内容的提问来源于stack exchange,提问作者MrLister
相关产品推荐
相关产品推荐

