It's dead, Jim! (UEFI CA expiry)

Lobsters Hottest News

Summary

The old Microsoft UEFI CA from 2011 has expired, but thanks to coordinated efforts by Debian and other distributions, new dual-signed shim binaries are being deployed to prevent boot failures.

<p><a href="https://lobste.rs/s/xz51yj/it_s_dead_jim_uefi_ca_expiry">Comments</a></p>
Original Article
View Cached Full Text

Cached at: 06/28/26, 01:53 AM

# Steve's blog Source: [https://blog.einval.com/2026/06/27](https://blog.einval.com/2026/06/27) Saturday, 27 June 2026**It's dead, Jim\!** I previously wrote about the upcoming[UEFI CA rollover](https://blog.einval.com/2026/06/05#secure_boot_ca_rollover_docs)\. Well, it's happened now \- the old Microsoft UEFI CA from 2011 expired**yesterday**: **Third Party Marketplace Root \(used for signing option ROMs and other software\)** ``` Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation UEFI CA 2011 Validity Not Before: Jun 27 21:22:45 2011 GMT Not After : Jun 27 21:32:45 2026 GMT ``` **It's dead \- it's not coming back\.\.\.** The world doesn't seem to have ended yesterday, so I guess we did ok? :\-\) ## How did we do? After a lot of prodding behind the scenes, Debian and many other distributions managed to get new shim binaries dual\-signed with both the old and new CAs\. The members of the shim\-review team did a sterling job with reviews in the last few weeks\. Since I started pushing people in May, we've had 21 reviews accepted successfully \- see[here](https://github.com/rhboot/shim-review/issues?q=is%3Aissue%20-label%3Ameta%20-label%3APSA%20created%3A%3E2026-05-01)for the list\. Great stuff\! Microsoft have also been working quickly \- many of those shim submissions were accepted and signed by Microsoft very quickly too, with a turnaround time of less than 1 day in some cases\. Not all of those signed shims have been published and used by the distros involved yet, but expect to see them in the wild in the coming weeks and months\. These binaries should be good for people to use for the foreseeable future, until either we need to do another CA rollover or \(sadly, more likely\) we find an issue in shim that necessitates a new release\. ## What's next? We already have**one**of our new dual\-signed shim binaries in place in Debian, in unstable and testing \(Forky\) right now\. In a couple of weeks from now, we'll be rolling out very similar new dual\-signed shim binaries in the next point releases for Debian 12 \(bookworm\) and Debian 13 \(trixie\)\. We'll also be upgrading`fwupd`in both those point releases, to make DB and KEK updates work better\. For more information about these updates, see[https://wiki\.debian\.org/SecureBoot/CAChanges](https://wiki.debian.org/SecureBoot/CAChanges)\. For your own safety, validate that your systems are updated when possible\. If you don't, they may fail to boot in future\. 22:33 ::[\#](https://blog.einval.com/2026/06/27#its_dead_jim)::[/debian/efi](https://blog.einval.com/debian/efi)::[0 comments](https://blog.einval.com/debian/efi/its_dead_jim.comments)

Similar Articles

Secure Boot and CA Rollover - a heads-up for distributions

Lobsters Hottest

This article alerts Linux distributions about the upcoming expiration of Microsoft's UEFI CA certificates used for Secure Boot, detailing new certificates and potential boot issues on newer hardware that lacks the old ones.

Linux and Secure Boot certificate expiration

Lobsters Hottest

The article covers the upcoming expiration of a Microsoft Secure Boot certificate that Linux distributions rely on for booting via shim, and the complexities involved in updating system firmware to accommodate the replacement key.