Microsoft is rolling out an update to Windows Secure Boot certificates, with three 2011-era certificates set to expire in June and October 2026. The Microsoft Corporation KEK CA 2011 certificate expires on June 24, followed by the Microsoft UEFI CA 2011 on June 27. The final certificate, which signs the Windows bootloader itself, will expire on October 19.
Devices with expired certificates lose future boot-level security patches and revocation lists
Devices with expired certificates will continue to boot normally but lose access to future boot-level security patches and certificate revocation lists. Windows 11 users on supported builds receive these updates automatically through Windows Update. Microsoft has been advancing the rollout of replacement certificates each month since January.
Older hardware may require a matching OEM firmware update to support the new certificate chain, as the updated chain must anchor directly in UEFI firmware. Some manufacturers have stopped issuing firmware updates for older systems, which could leave those devices on the expiring 2011 certificates regardless of Windows updates.
Users can check their Secure Boot status through Windows Security under Device Security. Microsoft provides guidance via support article KB5062710 to help users verify if their system has received the necessary updates or requires additional steps from the device manufacturer.
Source: NotebookCheck




Discussion
0 comments