You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
db
About this tag
The db tag on WindowsForum.com covers discussions about the Secure Boot Signature Database (DB) and related certificate rollouts in Windows. Threads explain how Microsoft updates UEFI Secure Boot certificates, including the 2023 CA update and the planned 2026 certificate rollover. Topics include the DB and DBX (revoked signature database) updates, firmware readiness, recovery media, and implications for system administrators and power users. The content focuses on maintaining boot-level security through coordinated certificate transitions and avoiding unbootable systems.
Microsoft’s Secure Boot update FAQ makes clear that a coordinated, multi-step transition is now live: Windows will roll new 2023 signing certificates into UEFI variables and update the Windows boot manager to preserve Secure Boot protection ahead of the 2011 CA expirations, but the rollout...
Microsoft has warned that the cryptographic roots underpinning UEFI Secure Boot on Windows devices will begin to expire in June 2026, forcing a global certificate update that every IT team and many end users must plan for now to avoid boot-level insecurities and loss of updateability.
Background...
2026 expiration
bitlocker
boot security
bootkit
certificate rollover
dbdbx
group policy
intune
kek
linux shim
mdm
oem firmware
recovery media
secure boot
uefi
vms
windows 11
windows server
windows update
If you've been keeping an ear to the ground for updates involving Microsoft's Secure Boot mechanism, buckle up—there's a lot to unpack here. Secure Boot, a critical security feature baked right into your system's firmware as part of the Unified Extensible Firmware Interface (UEFI), often...