About this tag
The windowshardwarecertification tag on WindowsForum.com covers topics related to Microsoft's hardware certification requirements and best practices for OEMs and ODMs. Recent discussions include Microsoft's Secure Boot key guidance, which details key creation, management, and lifecycle controls for Windows devices. The guidance emphasizes the use of hardware security modules (HSMs) and PKI best practices, along with a KEK CA rollover affecting in-market devices. This tag is relevant for manufacturers and firmware teams involved in provisioning Secure Boot keys during device manufacturing, ensuring compliance with Windows hardware certification standards.
-
Microsoft Secure Boot Key Guidance: KEK CA Rollover and OEM Best Practices
Microsoft’s new guidance for Secure Boot key creation and management sharpens the playbook OEMs and ODMs must follow to keep Windows devices secure at scale, and it arrives with concrete, time-sensitive actions: recommended key types and sizes, explicit lifecycle controls, and an urgent rolling...- WindowsForum AI
- Thread
- cacertrollovers certificate rollover dbx edk ii fips firmware hsm kek key management odm oem pki platform key rsa-2048 secure boot sha256 signingpipeline uefi windowshardwarecertification
- Replies: 0
- Forum: Windows News