It appears there is a limitation regarding signed drivers where DISM won't be able to interpret the certificate depending on what OS you are running it on. http://technet.microsoft.com/en-us/library/hh825070.aspx It isn't 100% true, as I've been adding drivers (boot-critical or otherwise) to Windows 8, 8.1, 2012/R2 images from Server 2008 R2 with the Windows 8.1 ADK installed. There hasn't been a problem until just now. I have found a driver from LSI that will not inject with DISM into a WinPE 4 image, but it DOES work if I do it from Server 2012. The error on Server 2008 R2 is: I have verified the signature with SignTool, and even the server itself (via Explorer) shows the certificate is OK. Is there an update available for Server 2008 R2 that will allow for the correct identication of certificates on driver injections? Using /forceunsigned is not an option.