Windows System Software -- Consulting, Training, Development -- Unique Expertise, Guaranteed Results


Before Posting...

Please check out the Community Guidelines in the Announcements and Administration Category.

More Info on Driver Writing and Debugging

The free OSR Learning Library has more than 50 articles on a wide variety of topics about writing and debugging device drivers and Minifilters. From introductory level to advanced. All the articles have been recently reviewed and updated, and are written using the clear and definitive style you've come to expect from OSR over the years.

Check out The OSR Learning Library at:

Kernel mode driver signing

olivier_dolivier_d Member Posts: 5


Sorry for my english, it is not my first language.

I used to distribute some window kernel driver mode to help some buisiness to protect their important data.
Recently my compagny EV certificate expired and I renew it, but it seems impossible to sign any driver.
I have look for information on microsoft site where i found some informations that seems contradictory. First i read :

Using cross-certificates to sign kernel-mode drivers is a violation of the Microsoft Trusted Root Program (TRP) policy.

then I read :

Cross-signed drivers are still permitted if any of the following are true: The PC was upgraded from an earlier release of Windows to Windows 10, version 1607. Secure Boot is off in the BIOS. Drivers was signed with an end-entity certificate issued prior to July 29th 2015 that chains to a supported cross-signed CA.

I would like to know if the exception can still be used for today driver signing. Or if the security in window 10 drivers is definitly removed from user management to a third party compagny (Microsoft, in this case) in which they may or not have trust, but no choice for them.

My question is only about windows 10. The requirement of windows 11 and more explicitly removed users rights to manage their own security for kernel drivers.

Sign In or Register to comment.

Howdy, Stranger!

It looks like you're new here. Sign in or register to get started.

Upcoming OSR Seminars
OSR has suspended in-person seminars due to the Covid-19 outbreak. But, don't miss your training! Attend via the internet instead!
Kernel Debugging 13-17 May 2024 Live, Online
Developing Minifilters 1-5 Apr 2024 Live, Online
Internals & Software Drivers 11-15 Mar 2024 Live, Online
Writing WDF Drivers 20-24 May 2024 Live, Online