Tag
The old Microsoft UEFI CA from 2011 has expired, but thanks to coordinated efforts by Debian and other distributions, new dual-signed shim binaries are being deployed to prevent boot failures.
The article covers the upcoming expiration of a Microsoft Secure Boot certificate that Linux distributions rely on for booting via shim, and the complexities involved in updating system firmware to accommodate the replacement key.