NINTENDO SWITCH Unpetrified: Echoes of Nature Console Release Confirmed for Fall 2026 PHONES Huawei Leads China Smartphone Market as Apple Grows Amid 2% Decline GAMES Phasmophobia Gets Deildegast Ghost and 13 Willow Street Rework STEAM Fallout 76 Update 2.28 Released: Infestations Rebalanced and Boss Loot Fixed GAMES Former Forza Director Calls Xbox Game Pass ‘A Real Shame’ GAMES Bethesda Takes Fallout 76 Servers Offline for July 21 Title Update INTEL Kirin 9030 Pro Teardown Shows SMIC N+3 Beats Intel 18A Pitch PLAYSTATION 5 Wreckreation 2 Announced for PS5, Xbox Series, and PC NINTENDO SWITCH Dear Passengers Console Status: PS, Xbox, PC, and Switch Availability XBOX SERIES X Xbox Game Pass Adds 6 New Games in July 2026, Including Halo GAMES Xbox Game Pass Price Cuts to $22.99 as Seven New Titles Join Service GAMES Hunty Zombie July 2026 Reward Codes: Free Items for Roblox Players GAMES Dear Passengers Release News & Demo Details for 2026 Launch HANDHELD GAMING Anbernic RG SP Launches with GBA SP Design and Thinner Chassis

Windows Secure Boot Certificates Expire June 24, October 2026

Owen Carter 0 comments 1 min read

Three 2011-era Microsoft Secure Boot certificates expire in June and October 2026. Windows 11 users get automatic updates; older hardware may need OEM firmware patches.

Windows Secure Boot Certificates Expire June 24, October 2026
SOFTWARE AND UPDATES

Microsoft is rolling out an update to Windows Secure Boot certificates, with three 2011-era certificates set to expire in June and October 2026. The Microsoft Corporation KEK CA 2011 certificate expires on June 24, followed by the Microsoft UEFI CA 2011 on June 27. The final certificate, which signs the Windows bootloader itself, will expire on October 19.

Devices with expired certificates lose future boot-level security patches and revocation lists

Devices with expired certificates will continue to boot normally but lose access to future boot-level security patches and certificate revocation lists. Windows 11 users on supported builds receive these updates automatically through Windows Update. Microsoft has been advancing the rollout of replacement certificates each month since January.

Older hardware may require a matching OEM firmware update to support the new certificate chain, as the updated chain must anchor directly in UEFI firmware. Some manufacturers have stopped issuing firmware updates for older systems, which could leave those devices on the expiring 2011 certificates regardless of Windows updates.

Users can check their Secure Boot status through Windows Security under Device Security. Microsoft provides guidance via support article KB5062710 to help users verify if their system has received the necessary updates or requires additional steps from the device manufacturer.

Source: NotebookCheck

Discussion

0 comments

Leave a comment