WeSearch

Secure Boot and Microsoft CA Rollover – a heads-up for distributions

·5 min read · 0 reactions · 0 comments · 21 views
#technology#security#linux
TL;DR · WeSearch summary

Microsoft's Secure Boot root certificates are set to expire soon, impacting Linux distributions. The current certificates, in use since 2011, will expire in October 2026, while a second certificate for signing shim will expire in just five weeks. New certificates have been issued, but the late rollout may cause issues for users with older machines.

Key facts
About this source

Hacker News (Newest) files mainly under programming. We currently carry 5,257 of its stories.

Original article
Einval
Read full at Einval →
Opening excerpt (first ~120 words) tap to expand

Friday, 22 May 2026 Secure Boot and Microsoft CA Rollover - a heads-up for distributions Background I'm a member of the EFI team in Debian, and I've done much of the work for Debian to support UEFI Secure Boot (SB) in recent years. We have included that support for a number of releases now, starting back with Debian 10 (aka Buster). I'm also a long-time accredited member of the shim-review team, the group that checks and approves shim binaries before Microsoft will sign them. See the Debian wiki for lots of background details about Secure Boot and how we do things in Debian. Secure Boot depends on signatures, which are verified during boot using a chain of X.509 certificates.

Excerpt limited to ~120 words for fair-use compliance. The full article is at Einval.

Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments

More from Einval