Skip to content

Veracrypt appears to be signed with the 2011 CA which will stop working June 27th 2026 #1655

@Motophan

Description

@Motophan

From what I can tell in June everyone w/ veracrypt will have their secureboot stop working because vc signs itself from the 2011 ca and not the 2023 ca. This means w11 will complain about secure boot not being valid, and in some cases will not show a screen / ignore the boot option instead of continuing.

Can we rush a version bump for this please?

sudo sbverify --list DcsBoot.efi

results in


    signature 1
    image signature issuers:
     - /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
    image signature certificates:
     - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Windows UEFI Driver Publisher
       issuer:  /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
     - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
       issuer:  /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation Third Party Marketplace Root

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions