• Latest
  • Trending
  • All
Answer card: Microsoft 2011 Secure Boot certificates expire in 2026, but existing Linux systems keep booting; the fix is enrolling the 2023 key with fwupd.

Secure Boot certificates expire in 2026: the Linux fix

22 June 2026
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
Answer card stating that Jev 1.13 from TypeSafe AI is a decision model in early access since 15 September 2026 that returns typed probabilities instead of text, priced at 42 dollars per billion input tokens with output tokens free, answering in 70 to 500 milliseconds, with a 64K token request budget, text input only, and a documented list of things it does badly, including counting and dates.

Jev 1.13 bills $42 a billion tokens, and it can’t count

19 September 2026
Answer card stating that Qwen3.8-Omni-Flash launched on 17 September 2026 as an API only model on Alibaba Cloud Model Studio, taking text, images, audio and video in a 1M token context and returning text only, priced at 0.15 dollars per million input tokens for every modality and 0.47 dollars per million output tokens in the international regions, with no open weights published and the Qwen-Live Harness GitHub repository returning 404.

Qwen3.8-Omni-Flash bills audio at $0.15 and ships no weights

18 September 2026
Answer card stating that on 15 September 2026 AWS said it is unable to restore access to resources and data hosted exclusively in the Middle East Bahrain region me-south-1 and in the mec1-az2 zone of the UAE region, because the damage spanned multiple Availability Zones and exceeded what multi-AZ services are designed to withstand.

AWS can’t restore me-south-1, six months after the drone strikes

17 September 2026
Answer card stating that Google released Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking on 15 September 2026 at 3 dollars per million audio input tokens and 12 dollars out, that the thinking model requires asynchronous tools, and that Artificial Analysis scores it 82.6 on its Speech to Speech Quality Index.

Gemini 3.8 Live Extended Thinking rejects any tool that blocks

16 September 2026
Answer card summarising the Atria Dawn Preview release: 744B GLM-5.2 base, MIT licence, 1.5 TB BF16 and 756 GB FP8 checkpoints, 256K context, top on five of sixteen benchmark rows and trailing on SWE-bench Pro.

Atria Dawn Preview is 744B under MIT, and the BF16 weighs 1.5 TB

15 September 2026
Answer card stating that OpenAI released the Agents API in public beta on 10 September 2026 with no separate fee, billed through model tokens, tool calls and hosted sandbox time, with a choice of OpenAI hosted, self hosted or partner sandboxes, US only data residency and no Zero Data Retention support.

OpenAI’s Agents API has no fee, no ZDR and a one hour sandbox clock

14 September 2026
Answer card: Sakana Fugu Max at $2 and $6 per million tokens, Fugu Ultra v2 unchanged at $5 and $30, and Sakana saying Ultra v2 scores without Fable 5 or GPT-6 Astra in its pool.

Fugu Max costs $2 and $6 while Fugu Ultra v2 runs without Fable 5

13 September 2026
Answer card stating that DeepSeek released DeepSeek-V4.1-Flash on 10 September 2026 as a 552 billion parameter mixture of experts model with a new causal encoder decoder architecture that activates 8 billion parameters on input and 16 billion on output, with native vision, a one million token context and MIT licensed weights, that the API model name is now deepseek-flash at 0.15 dollars per million input tokens and 0.60 dollars per million output tokens off peak, and that DeepSeek announced V4 Pro would be routed to V4.1-Flash from 14 September and reversed that on 11 September.

DeepSeek V4.1-Flash arrived, and the V4 Pro retirement lasted a day

12 September 2026
Answer card stating that Cognition released SWE-2 on 10 September 2026, a coding model post-trained from Kimi K3, scoring 50.0 percent on FrontierCode 1.1 Main against 50.9 percent for Claude Fable 5.1 and 27.3 percent on Terminal-Bench 4 against 55.8 percent, available only inside Devin.

SWE-2 trails Fable 5.1 by one point, and by 28 on Terminal-Bench 4

11 September 2026
Answer card for Meta Muse, free to 100 million tokens a week then $20 a month, launched 8 September 2026 for United States adults only, running in a dedicated per user virtual machine.

Does Meta Muse do enough to earn your inbox and a card on file?

9 September 2026
Answer card stating that the public download pages for the VMware Virtual Disk Development Kit on developer.broadcom.com began returning 404 errors on 25 August 2026 with no announcement or deprecation notice, that Broadcom support tells customers the kit is no longer available for use or download, and that release lines 7.0.3.1, 8.x and 9.x are all affected.

Broadcom pulled VDDK 8.0 and 9.0, and the 404 is the only notice

8 September 2026
  • About
  • Contact
  • Privacy
  • Legal
Monday, September 21, 2026
  • Login
Packet Nebula
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About
No Result
View All Result
Packet Nebula
No Result
View All Result
Home Security

Secure Boot certificates expire in 2026: the Linux fix

by stephane
22 June 2026
in Security
0
Answer card: Microsoft 2011 Secure Boot certificates expire in 2026, but existing Linux systems keep booting; the fix is enrolling the 2023 key with fwupd.
495
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

The headlines made it sound like every Linux PC turns into a brick on 27 June 2026, the day Microsoft's 2011 Secure Boot certificate expires. It doesn't. If your machine boots today, it keeps booting after that date, dual-boot and all, because expiry stops Microsoft signing new boot components, it does not revoke the keys your firmware already trusts. So nothing detonates in June. The real problem is slower and quieter: new distro installs and future shim and kernel updates are signed with Microsoft's 2023 certificate, and your firmware will not trust those until you enroll the new key. On Linux that is one command through fwupd, when your vendor ships it. Here's what is actually expiring, what genuinely breaks, and exactly what to run.

The short answer

Microsoft’s 2011 Secure Boot certificates expire through 2026 (the Linux shim cert on 27 June). Nothing that boots today stops booting: expiry is not revocation. The catch is tomorrow. New installs and future shim updates use Microsoft’s 2023 certificate, so you enroll the new key in your firmware with fwupd. One command, one reboot.

Jun 20262011 certs start expiring
0machines bricked on the date
fwupdmgrupdate: the one-command fix
Answer card: Microsoft 2011 Secure Boot certificates expire in 2026 but existing Linux systems keep booting; enroll the 2023 key with fwupd.
The calm version. The scary headline is about signing new things, not your current boot.

Nothing bricks in June (or October)

Here is the whole panic, defused, in one paragraph. Microsoft’s 2011 Secure Boot certificates expire across 2026, but expiry is not revocation. A certificate that has already vouched for the bootloader sitting in your firmware keeps being trusted; expiry only means Microsoft can no longer sign new things with it. So the machine that boots Linux this morning boots it tomorrow, and the morning after 27 June, dual-boot and all. Anyone telling you to back up and reinstall before the date is selling fear. Fedora’s own write-up is, fittingly, titled “Don’t Panic.”

What is actually expiring

Three certificates, three jobs, three dates.

Table of the three expiring 2011 Secure Boot certificates: KEK CA 2011 (24 Jun 2026, signs db/dbx updates), UEFI CA 2011 (27 Jun 2026, signs the Linux shim), Windows PCA 2011 (19 Oct 2026, Windows bootloader).
Three certs, three roles. The middle one is the one Linux rides on.

The one Linux cares about is the Microsoft UEFI CA 2011: it signs third-party bootloaders, which in practice means the shim, the small Microsoft-signed first stage that then loads your distro’s GRUB and kernel. It lapses 27 June 2026. Next to it, the KEK CA 2011, which signs updates to the Secure Boot databases themselves, expires 24 June 2026, and the Windows Production PCA 2011, the one behind the Windows boot loader, runs out 19 October 2026. Each has a 2023 replacement that needs to be sitting in your firmware’s key database for the new signatures to be trusted.

The real problem: tomorrow’s updates, not today’s boot

This is the part that genuinely matters. New shims, and the new kernels they load, are now signed with Microsoft’s 2023 certificate. Firmware that only knows the 2011 keys will refuse to run them. So two things quietly stop working if you do nothing:

  • New installs. Boot a freshly downloaded distro on an untouched machine and its 2023-signed shim may not be trusted, so the installer never starts while Secure Boot is on.
  • Security updates. Once your distro moves to 2023-signed shims, firmware that has not enrolled the 2023 key stops accepting them, so you stop receiving boot-level security fixes. That is the “degraded security” the vendors warn about, and it is the slow-burn risk, not a dramatic June failure.

And dual-boot does not make any of this worse. Windows and Linux lean on the same Secure Boot keys in the same firmware, so the expiry hits the machine evenly or not at all. There is no special Linux curse here, whatever the headline implied.

The fix: enroll the 2023 key with fwupd

On Linux the whole thing is usually two commands, because the firmware key update ships through the Linux Vendor Firmware Service and fwupd applies it. Refresh the metadata first:

Linux
sudo fwupdmgr refresh

Then pull and apply whatever your vendor has published:

Linux
sudo fwupdmgr update
Terminal: sudo fwupdmgr refresh downloads LVFS metadata, then sudo fwupdmgr update offers a UEFI Secure Boot key update that enrolls Microsoft's 2023 CA and applies on reboot.
Two commands. The key update applies on the next reboot, and you're current.

If your vendor has pushed the update to the LVFS, fwupd offers it, schedules it, and applies it on the next reboot, adding the 2023 certificate to your firmware’s db. If fwupdmgr shows nothing for your hardware, the update simply has not been published for your board yet: check again later, or ask the OEM for a UEFI update that does the same job. On a Windows-and-Linux dual-boot machine, letting Windows Update run enrolls the new keys too, because it is the same firmware database underneath. It is the same kind of scheduled housekeeping as renewing a TLS certificate before it lapses: boring, and a non-event if you do it on time.

What not to do

Three tempting “fixes” that make things worse:

  • Do not remove the 2011 certificate. It still vouches for legacy option ROMs on graphics and network cards; pull it and those peripherals can stop initialising. Add the 2023 key, do not subtract the old one.
  • Do not hand-edit the Secure Boot db with efivar incantations from a forum unless you truly know the consequences. A botched db is a machine that will not boot, which is exactly the disaster the panic warned about, now self-inflicted.
  • Do not “solve” it by turning Secure Boot off. It works, and it throws away the boot-level tamper protection you turned it on for.

Run sudo fwupdmgr update sometime in the next few months, reboot, and you are finished: your firmware now trusts both the old and the new Microsoft keys, your current install keeps booting, and the next one will too. The 2026 expiry is a chore with a frightening headline, not an emergency.

Sources: Microsoft Support, Red Hat and Fedora Magazine. Certificate names and dates as published by Microsoft for 2026.

Frequently asked questions

Will my Linux PC stop booting on 27 June 2026?

No. A machine that boots today keeps booting after the date, dual-boot included. Certificate expiry is not revocation: the keys already trusted in your firmware stay trusted, so your installed shim and kernel keep loading. Expiry only stops Microsoft from signing new boot components with the old 2011 certificate.

What actually breaks when the Secure Boot certificate expires?

Two things, both about the future, not today. New OS installs: a freshly downloaded distro signed with the 2023 certificate may not be trusted by firmware that only knows the 2011 keys, so the installer will not start under Secure Boot. And future security updates: once your distro ships 2023-signed shims, firmware without the 2023 key stops accepting them, so you fall behind on boot-level fixes.

How do I update Secure Boot keys on Linux?

Through fwupd, when your hardware vendor has published the update to the Linux Vendor Firmware Service. Run sudo fwupdmgr refresh then sudo fwupdmgr update, and reboot to apply. That enrolls the Microsoft 2023 certificate in your firmware db. If fwupdmgr offers nothing for your board, the update is not published for it yet: check back, or ask your OEM for a UEFI update.

Does this affect Windows and Linux dual-boot?

It affects both equally, which means neither is specially cursed. Windows and Linux rely on the same Secure Boot keys in the same firmware, so the expiry hits the machine, not one OS. On a dual-boot system, letting Windows Update run also enrolls the new keys, since it is the same firmware database that Linux uses.

Should I just disable Secure Boot to avoid the hassle?

You can, and it is a real downgrade. Disabling Secure Boot removes the boot-level tamper protection entirely, which is a much bigger loss than the housekeeping you were avoiding. It is fine as a momentary diagnostic, wrong as a permanent answer. Enroll the 2023 key instead and keep the protection.

Tags: dual-bootguidelinuxsecure-bootsecurityuefi
Share198Tweet124
stephane

stephane

  • Trending
  • Comments
  • Latest
Answer card: Proton Lumo 2.0 is private by policy, not by locality. Saved history is locked so even Proton cannot read it, but the prompt is decrypted on a Proton EU server to answer it, then forgotten.

Proton Lumo 2.0 review: how private is it, really?

3 September 2026
The Agentic Coding section of the official Hy4 preview benchmark appendix published by Tencent, a table comparing Hy3 and Hy4 preview against DeepSeek V4 Pro 0813, Qwen 3.8 Max, GLM 5.3, Kimi K3, GPT 5.6 Sol and Claude Opus 5 across SWE-bench Multilingual, SWE-bench Pro, DeepSWE, three SWE Atlas tasks, SWE-Marathon, Terminal-Bench 2.1, NL2Repo-Bench, CyberGym, ProgramBench, PostTrainBench and Harbor-Index.

Tencent’s 770B Hy4 tops one benchmark row in 46

3 September 2026
Answer card: Qwen 3.7 Max is API-only and cannot run locally yet; the open Qwen models (Qwen 3.6 27B, qwen3:8b to 32b) run offline via Ollama.

Qwen 3.7 local: what you can actually run offline

22 June 2026
Answer card: JWTs are not encrypted, anyone can read them; the signature proves who issued the token, not who may read it.

Are JWTs encrypted? No, and the difference will bite you

0
Answer card: a random 8 character password falls in under 2 hours offline, while 16 random characters hold for 1.4 trillion years at the same speed.

How long does it take to crack a password in 2026?

0
Answer card: three DNS records decide if your mail lands or bounces; SPF lists allowed senders, DKIM signs messages, DMARC sets the failure policy.

SPF, DKIM and DMARC explained: the records your email needs

0
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
Answer card stating that Jev 1.13 from TypeSafe AI is a decision model in early access since 15 September 2026 that returns typed probabilities instead of text, priced at 42 dollars per billion input tokens with output tokens free, answering in 70 to 500 milliseconds, with a 64K token request budget, text input only, and a documented list of things it does badly, including counting and dates.

Jev 1.13 bills $42 a billion tokens, and it can’t count

19 September 2026
Answer card stating that Qwen3.8-Omni-Flash launched on 17 September 2026 as an API only model on Alibaba Cloud Model Studio, taking text, images, audio and video in a 1M token context and returning text only, priced at 0.15 dollars per million input tokens for every modality and 0.47 dollars per million output tokens in the international regions, with no open weights published and the Qwen-Live Harness GitHub repository returning 404.

Qwen3.8-Omni-Flash bills audio at $0.15 and ships no weights

18 September 2026
  • About
  • Contact
  • Privacy
  • Legal

Copyright © 2026 Stephane Cardon.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About

Copyright © 2026 Stephane Cardon.