Secure Boot and Microsoft CA Rollover – a heads-up for distributions
Microsoft's Secure Boot root certificates are set to expire soon, impacting Linux distributions. The current certificates, in use since 2011, will expire in October 2026, while a second certificate for signing shim will expire in just five weeks. New certificates have been issued, but the late rollout may cause issues for users with older machines.
- ▪The Microsoft UEFI CA certificates have been in use since 2011 and are crucial for Secure Boot functionality.
- ▪The current certificates will expire in October 2026, with a second certificate expiring in five weeks.
- ▪New certificates have been introduced, but older machines may face compatibility issues due to the late rollout.
Hacker News (Newest) files mainly under programming. We currently carry 5,257 of its stories.
Opening excerpt (first ~120 words) tap to expand
Friday, 22 May 2026 Secure Boot and Microsoft CA Rollover - a heads-up for distributions Background I'm a member of the EFI team in Debian, and I've done much of the work for Debian to support UEFI Secure Boot (SB) in recent years. We have included that support for a number of releases now, starting back with Debian 10 (aka Buster). I'm also a long-time accredited member of the shim-review team, the group that checks and approves shim binaries before Microsoft will sign them. See the Debian wiki for lots of background details about Secure Boot and how we do things in Debian. Secure Boot depends on signatures, which are verified during boot using a chain of X.509 certificates.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at Einval.