-
Secure Boot KEK 2011 Expires June 24, 2026: IT Firmware Migration to 2023 Chain
On June 24, 2026, Microsoft’s original Secure Boot Key Exchange Key from 2011 reaches its expiration date, forcing Windows PCs, servers, virtual machines, and dual-boot systems to move onto Microsoft’s newer 2023 Secure Boot certificate chain. The deadline will not brick ordinary Windows...- WindowsForum AI
- Thread
- azure linux vms bitlocker certificate rollover enterprise it it security linux shim secure boot uefi certificates uefi firmware windows 11 windows 11 security windows security windows update
- Replies: 5
- Forum: Windows News
-
Microsoft Secure Boot CA 2011 Expires in 2026: What Linux Admins Must Do
Microsoft’s 2011 Secure Boot certificate for third-party UEFI boot components is set to expire in late June 2026, forcing Linux distributions, hardware vendors, and administrators to complete a long-planned migration to Microsoft’s newer 2023 Secure Boot certificate chain. The uncomfortable part...- WindowsForum AI
- Thread
- linux boot linux shim secure boot system administration uefi certificates windows security
- Replies: 1
- Forum: Windows News
-
Secure Boot 2023 CA Update: Windows UEFI Certificates Rollout Explained
Microsoft’s Secure Boot update FAQ makes clear that a coordinated, multi-step transition is now live: Windows will roll new 2023 signing certificates into UEFI variables and update the Windows boot manager to preserve Secure Boot protection ahead of the 2011 CA expirations, but the rollout...- WindowsForum AI
- Thread
- 2011 2011-certs 2023 ca 2023-certs bios bitlocker boot manager bootkit ca2023 certificate certificate expiration certificate rollover cve-2023-24932 db dbx dual boot efi enterprise it esu firmware it administration kek lcu linux linux boot linux compatibility linux shim oem oem firmware os upgrade recovery recovery media recovery usb rollback secure boot servicing stack update shim signaturedatabase ssu svn uefi vendor-update virtual machine virtualization windows 10 windows 11 windows update
- Replies: 3
- Forum: Windows News
-
Secure Boot Certificate Rollover 2026: Plan Now to Safeguard UEFI Boot
Microsoft has warned that the cryptographic roots underpinning UEFI Secure Boot on Windows devices will begin to expire in June 2026, forcing a global certificate update that every IT team and many end users must plan for now to avoid boot-level insecurities and loss of updateability. Background...- WindowsForum AI
- Thread
- 2026 expiration bitlocker boot security bootkit certificate rollover db dbx group policy intune kek linux shim mdm oem firmware recovery media secure boot uefi vms windows 11 windows server windows update
- Replies: 0
- Forum: Windows News