Hi everyone and Chuwi Technical Staff,
I am reaching out to the community and Chuwi support regarding a critical security compliance issue affecting the GeminiBook Plus (Alder Lake-N100) and GeminiBook XPro (12th Gen N100) models.
We currently manage a professional deployment of these devices. While testing them for compliance with modern Windows security standards, we discovered a significant flaw regarding the Secure Boot certificate chain that requires an urgent firmware update from Chuwi.
The Problem: Stuck on the Expiring 2011 Secure Boot CA
As many of you may know, Microsoft is actively phasing out the old Microsoft Third-Party UEFI CA 2011 and transitioning to the new 2023 CA. Because the 2011 certificates are expiring in 2026, systems that do not update to the 2023 certificates will enter a degraded Secure Boot state.
Usually, Windows pushes this update automatically to the UEFI firmware. However, detailed diagnostics on multiple GeminiBook N100 units reveal that the current Chuwi firmware prevents this automatic migration.
Our technical findings:
-
Secure Boot is enabled and active.
-
The UEFI variables (PK, KEK, db, and dbx) are present but do not expose any SignatureType GUIDs.
-
The firmware does not expose X.509 certificates to Windows, which is required for the OS to push the new keys.
-
The registry keys used by Windows to track the 2023 certificate rollout exist, but no status value (such as
UEFICA2023Status) is ever created. -
Windows cannot detect the 2023 Secure Boot certificate chain on these devices.
In short: The GeminiBook Plus and XPro are permanently stuck on the expiring 2011 Secure Boot CA because the firmware does not accept the automatic key update from Windows.
The Impact
Since we are now in 2026 and the 2011 certificates are reaching the end of their lifespan, this is no longer a future warning but a current, active issue. The consequences are severe for anyone using these laptops in a professional, educational, or regulated environment:
-
Compliance Failure: The devices will fail modern Zero Trust, Intune, or MDM security baseline checks.
-
Vulnerability: We are unable to apply future Secure Boot
dbxupdates (revocation lists), leaving the devices vulnerable to known bootkits. -
OS Updates: Future versions of Windows 11 may block installation or feature updates on systems lacking updated Secure Boot trust anchors.
The Expected Solution from Chuwi
To resolve this, relying on Windows Update is not enough. We urgently need Chuwi to release an updated BIOS/Firmware for the GeminiBook Plus and GeminiBook XPro (N100 series).
This BIOS update must natively include the Microsoft 2023 Secure Boot certificate chain (updated PK, KEK, db, and dbx databases) so that these devices can remain functional and secure.
Questions for the Community & Support:
-
@Chuwi Support: Is there a BIOS update currently in development for these models to address the 2023 CA migration? If so, when can we expect the release?
-
@Community: Has anyone else run into Secure Boot compliance issues with their N100 GeminiBooks? Has anyone received a beta or custom BIOS file from support that fixes this?
Thank you for your time and assistance. I look forward to your feedback and a swift resolution from the Chuwi engineering team.