You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
2011-certs
About this tag
The 2011-certs tag covers discussions about the expiration and replacement of 2011 Secure Boot certificates in Windows systems. Content focuses on Microsoft's rollout of new 2023 signing certificates for UEFI Secure Boot, the transition process to replace the expiring 2011 CAs, and the need for careful testing, firmware readiness from OEMs, and updated recovery media to prevent boot failures or data loss. This tag is relevant for IT professionals and advanced users managing Secure Boot certificate updates on Windows devices.
Microsoft’s Secure Boot update FAQ makes clear that a coordinated, multi-step transition is now live: Windows will roll new 2023 signing certificates into UEFI variables and update the Windows boot manager to preserve Secure Boot protection ahead of the 2011 CA expirations, but the rollout...
2011
2011-certs
2023 ca
2023-certs
bios
bitlocker
boot manager
bootkit
ca2023
certificate
certificate expiration
certificate rollover
cve-2023-24932
db
dbx
dual boot
efi
enterprise it
esu
firmware
it administration
kek
lcu
linux
linux boot
linux compatibility
linux shim
oem
oem firmware
os upgrade
recovery
recovery media
recovery usb
rollback
secure boot
servicing stack update
shim
signaturedatabase
ssu
svn
uefi
vendor-update
virtual machine
virtualization
windows 10
windows 11
windows update