It's dead, Jim! (UEFI CA expiry)
Summary
The old Microsoft UEFI CA from 2011 has expired, but thanks to coordinated efforts by Debian and other distributions, new dual-signed shim binaries are being deployed to prevent boot failures.
View Cached Full Text
Cached at: 06/28/26, 01:53 AM
Similar Articles
Secure Boot and CA Rollover - a heads-up for distributions
This article alerts Linux distributions about the upcoming expiration of Microsoft's UEFI CA certificates used for Secure Boot, detailing new certificates and potential boot issues on newer hardware that lacks the old ones.
Linux and Secure Boot certificate expiration
The article covers the upcoming expiration of a Microsoft Secure Boot certificate that Linux distributions rely on for booting via shim, and the complexities involved in updating system firmware to accommodate the replacement key.
A Critical Deadline Is Approaching for Windows and Linux Security
A critical deadline is approaching for Windows and Linux users to update cryptographic keys that protect against UEFI bootkits, as three Microsoft-signed certificates for Secure Boot will expire on June 24.
Windows and Linux users: The deadline to update Secure Boot keys is near
An upcoming deadline requires Windows and Linux users to update Secure Boot keys to protect against UEFI-based bootkits. The expiration of Microsoft-signed certificates on June 24 could leave systems vulnerable if not updated.
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
Researchers at ESET discovered that Microsoft's Secure Boot has been vulnerable to trivial bypass for 13 years due to unrevoked signed shims, allowing attackers to install persistent firmware malware on both Windows and Linux devices.