{"id":111168,"date":"2026-02-10T19:41:14","date_gmt":"2026-02-10T19:41:14","guid":{"rendered":"https:\/\/www.europesays.com\/ro\/111168\/"},"modified":"2026-02-10T19:41:14","modified_gmt":"2026-02-10T19:41:14","slug":"certificatele-secure-boot-vor-expira-pe-pc-urile-vechi-si-acestea-vor-deveni-vulnerabile","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ro\/111168\/","title":{"rendered":"Certificatele Secure Boot vor expira pe PC-urile vechi \u015fi acestea vor deveni vulnerabile"},"content":{"rendered":"<p><img loading=\"lazy\" data-od-removed-fetchpriority=\"high\" data-od-xpath=\"\/HTML\/BODY\/DIV[@id='td-outer-wrap']\/*[2][self::DIV]\/*[2][self::DIV]\/*[1][self::DIV]\/*[1][self::ARTICLE]\/*[1][self::DIV]\/*[1][self::DIV]\/*[3][self::DIV]\/*[1][self::DIV]\/*[2][self::DIV]\/*[2][self::DIV]\/*[5][self::DIV]\/*[3][self::DIV]\/*[1][self::FIGURE]\/*[1][self::IMG]\" decoding=\"async\" width=\"1024\" height=\"379\" src=\"https:\/\/www.europesays.com\/ro\/wp-content\/uploads\/2026\/02\/windows_update-1024x379.jpg\" alt=\"Certificatele folosite de Secure Boot sunt pe cale s\u0103 expire pe PC-urile mai vechi de 2023 \u015fi dac\u0103 nu le actualiza\u021bi pute\u021bi s\u0103 ave\u021bi probleme.\" class=\"wp-image-111440\"  \/>Certificatele folosite de Secure Boot sunt pe cale s\u0103 expire pe PC-urile mai vechi de 2023 \u015fi dac\u0103 nu le actualiza\u021bi pute\u021bi s\u0103 ave\u021bi probleme.<\/p>\n<p>Anul acesta expir\u0103 certificatele Secure Boot de pe PC-urile mai vechi de 2023 \u0219i f\u0103r\u0103 ele vor deveni vulnerabile. Dac\u0103 la fel ca mine v-a\u021bi g\u00e2ndit c\u0103 odat\u0103 expirate, va fi imposibil s\u0103 porni\u021bi respectivele PC-uri, nu e chiar a\u0219a. Ele devin nefolosibile, dar sistemul de boot va func\u021biona \u2013 efectul este c\u0103 PC-ul este vulnerabil pentru c\u0103 anumite bariere de protec\u021bie nu vor mai func\u021biona.<\/p>\n<p>Conform Microsoft, aproape 1 miliard de PC-uri ce \u00eenc\u0103 func\u021bioneaz\u0103, sunt expuse. Practic orice PC produs \u00eentre 2011 \u2013 2023 este expus, f\u0103r\u0103 certificat valid, solu\u021bia de securitate ce permite doar aplica\u021biilor semnate s\u0103 func\u021bioneze, va deveni inutil\u0103, pe aceste sisteme fiind posibil s\u0103 se instaleze \u0219i software necertificat.<\/p>\n<p>Secure Boot se bazeaz\u0103 pe un sistem de certificate care verific\u0103 fiecare component\u0103 ce este \u00eenc\u0103rcat\u0103 \u00een procesul de pornire a PC-ului \u0219i apoi \u00een cea de lansare a sistemului de operare. CEl mai important este Key Exchange Key (KEK), ce st\u0103 \u00een UEFI \u0219i e folosit de Trusted Platform Module (TPM) pentru permisiunea acordat\u0103 boot loader-ului. Informa\u021bia st\u0103 \u00een Allowed Signature Database (DB) \u0219i Forbidden Signature Database (DBX).<\/p>\n<p>Un PC din ultimii 15 ani e posibil s\u0103 aib\u0103 un astfel de certificat creat \u00een 2011 \u0219i pentru c\u0103 durata de via\u021b\u0103 este de 15 ani, el va expira \u00een iunie 2026, deci e momentul s\u0103 \u00eel schimba\u021bi. Odat\u0103 ce va expira, nu va mai putea fi folosit pentru a verifica autenticitatea aplica\u021biilor ce sunt rulate \u00een momentul pornirii PC-ului.<\/p>\n<p>Trebuie s\u0103 \u0219ti\u021bi c\u0103 \u00eencep\u00e2nd cu 2023, Microsoft a lucrat cu produc\u0103torii \u0219i aceste modele de PC-urio\/laptop-uri au deja certificate noi, pe care nu e nevoie s\u0103 le actualiza\u021bi.<\/p>\n<p>B\u0103nuiesc c\u0103 \u0219ti\u021bi faptul c\u0103 toate versiunile de Windows folosesc SecureBoot, precum \u0219i distribu\u021biile majore de Linux.<\/p>\n<p>Ce e de f\u0103cut?<\/p>\n<p>Bun. Acum c\u0103 \u0219tim c\u0103 unele certificate stau s\u0103 expire, e important s\u0103 \u0219tim ce avem de f\u0103cut. Microsoft anun\u021b\u0103 c\u0103 actualizarea certificatelor se va face automat pe sistemele Windows ce au \u00eenc\u0103 suport de update, adic\u0103 toate versiunile de Windows 11 \u0219i cele de Windows 10 care au intrat \u00een programul extins de suport.<\/p>\n<p>Acestea vor primi setul de patch-uri de februarie \u0219i odat\u0103 cu ele certificatele necesare, ceea ce \u00eenseamn\u0103 c\u0103 majoritatea utilizatorilor nu ar trebui s\u0103 fac\u0103 nimic special.<\/p>\n<p>Pute\u021bi verifica dac\u0103 sistemul pe care \u00eel folosi\u021bi are nevoie de certificate noi, rul\u00e2nd urm\u0103toarea comand\u0103 \u00eentru-un PowerShell lansat cu drepturi de Administrator:<\/p>\n<p>([System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match &#8216;Windows UEFI CA 2023&#8217;)<\/p>\n<p>Dac\u0103 r\u0103spunsul primit e True, \u00eenseamn\u0103 c\u0103 ave\u021bi certificat emis \u00een 2023, deci sunte\u021bi ok pentru urm\u0103torii 15 ani. Altfel, trebuie s\u0103 aplica\u021bi pachetul de update din aceast\u0103 lun\u0103.<\/p>\n<p><img data-od-added-loading=\"\" data-od-replaced- data-od-xpath=\"\/HTML\/BODY\/DIV[@id='td-outer-wrap']\/*[2][self::DIV]\/*[2][self::DIV]\/*[1][self::DIV]\/*[1][self::ARTICLE]\/*[1][self::DIV]\/*[1][self::DIV]\/*[3][self::DIV]\/*[1][self::DIV]\/*[2][self::DIV]\/*[2][self::DIV]\/*[5][self::DIV]\/*[3][self::DIV]\/*[14][self::FIGURE]\/*[1][self::IMG]\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"81\" src=\"https:\/\/www.europesays.com\/ro\/wp-content\/uploads\/2026\/02\/Screenshot-2026-02-10-210921-1024x81.png\" alt=\"\" class=\"wp-image-111441\"  \/><\/p>\n<p>\u0218i cel mai bine ar fi s\u0103 intra\u021bi pe site-ul produc\u0103torului sistemului pe care \u00eel folosi\u021bi \u0219i s\u0103 vede\u021bi dac\u0103 acolo exist\u0103 pachete de update dedicate acestor probleme.<\/p>\n<p>Acum e hilar s\u0103 discut\u0103m c\u0103 Microsoft blocheaz\u0103 folosirea noului Windows 11 pe sisteme mai vachi, dar din cauza faptului c\u0103 au fost obliga\u021bi de UE s\u0103 ofere suport extins, acum sunt nevoi\u021bi <a href=\"https:\/\/blogs.windows.com\/windowsexperience\/2026\/02\/10\/refreshing-the-root-of-trust-industry-collaboration-on-secure-boot-certificate-updates\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">s\u0103 lanseze certificate \u0219i pentru acele PC-uri<\/a> ce \u00eenc\u0103 sunt func\u021bionale \u0219i au nevoie de update. \u0218i e posibil s\u0103 vorbim de aproape 1 miliard de PC-uri \u2026<\/p>\n<p>Partea bun\u0103: \u0219i dac\u0103 nu actualiza\u021bi acum certificatele, mai ave\u021bi timp p\u00e2n\u0103 \u00een iunie \u0219i dup\u0103. \u00cen cel mai r\u0103u caz, ave\u021bi sistemul expus, dar \u00eenc\u0103 func\u021bional \u2013 aplica\u021bi atunci noile certificate.<\/p>\n<p>Dar c\u0103 nu merit\u0103 s\u0103 a\u0219tepta\u021bi p\u00e2n\u0103 atunci. Recomandare mea este s\u0103 mai porni\u021bi sistemele mai vechi \u0219i le mai pune\u021bi ni\u0219te actualiz\u0103ri, c\u0103 nu stric\u0103. Eu tocmai am pornit un laptop Toshiba \u0219i de vreo 3 ore \u00eei fac update de la Windows 10 18H2 la 22H2 \ud83d\ude42 \u0219i sper s\u0103 rezolv \u0219i certificatul UEFI.<\/p>\n<p>via <a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/windows-secure-boot-certificate-expiration-and-ca-updates-7ff40d33-95dc-4c3c-8725-a9b95457578e\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Microsoft<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Certificatele folosite de Secure Boot sunt pe cale s\u0103 expire pe PC-urile mai vechi de 2023 \u015fi dac\u0103&hellip;\n","protected":false},"author":2,"featured_media":111169,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[34952,796,41,40,38,39,34953,141,124,34954,1281],"class_list":{"0":"post-111168","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tehnologie","8":"tag-certificate","9":"tag-microsoft","10":"tag-ro","11":"tag-romana","12":"tag-romania","13":"tag-romanian","14":"tag-secure-boot","15":"tag-technology","16":"tag-tehnologie","17":"tag-updates","18":"tag-windows"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ro\/116048041305528152","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ro\/wp-json\/wp\/v2\/posts\/111168","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ro\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ro\/wp-json\/wp\/v2\/comments?post=111168"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ro\/wp-json\/wp\/v2\/posts\/111168\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ro\/wp-json\/wp\/v2\/media\/111169"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ro\/wp-json\/wp\/v2\/media?parent=111168"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ro\/wp-json\/wp\/v2\/categories?post=111168"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ro\/wp-json\/wp\/v2\/tags?post=111168"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}