• Latest
  • Trending
  • All
Answer card: Microsoft 2011 Secure Boot certificates expire in 2026, but existing Linux systems keep booting; the fix is enrolling the 2023 key with fwupd.

Secure Boot certificates expire in 2026: the Linux fix

22 June 2026
Answer card stating that Mullvad announced on 3 September 2026 that it is shutting down its public encrypted domain name system servers on 2 November 2026 and sponsoring the Quad9 Foundation instead, with 194.242.2.2 and its five sibling addresses all going away, and virtual private network customers unaffected.

Mullvad’s DNS servers go dark on 2 November, and Quad9 blocks no ads

5 September 2026
OpenAI announcement image for GPT-6 Astra, a spiral galaxy of white, blue and amber points of light curling around a bright core on a near black star field.

GPT-6 Astra lists at $10 and $50, 2.5x what GPT-5.6 Sol costs

6 September 2026
Google's official announcement image for the release, reading Introducing Gemini 3.8 Flash and 3.8 Flash Cyber in black type over a pale blue background with a blurred white chevron and the four colour Gemini spark below.

Gemini 3.8 Flash keeps the price and the 1 January cliff

3 September 2026
Answer card stating that Anthropic announced Enterprise Frontier Safeguards on 1 September 2026, that activity data used for misuse monitoring moves into cloud storage the customer controls under the customer own encryption keys, that Anthropic charges nothing for the feature while the cloud provider bills storage and egress, and that the phased rollout starts later in autumn 2026 with interim zero data retention on Fable 5 and Fable 5.1 for eligible customers.

Anthropic moves retention into your own cloud, for 30 days

3 September 2026
Official Google diagram of a client connection in three numbered steps: a DNS lookup with a query and an address, a TLS ClientHello and ServerHello, then a content exchange with a website. A callout on the DNS step reads 25% of global web traffic is now protected by encrypted DNS, and a callout beside an Android phone on the ClientHello step reads Android 17 supports ECH GREASE by default.

Android 17 hides the SNI, not your DNS or destination

3 September 2026
Still frame from the Claude Fable 5.1 launch video showing model-designed protein binders in orange docked against twelve grey target proteins, rendered as ESMFold2 structure predictions.

Claude Fable 5.1 breaks forced tool use, cuts cache 75%

1 September 2026
Answer card stating that on 31 August 2026 the European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act, the first conversational AI service classified that way, because it answers user prompts and queries including by searching the web, with OpenAI having declared roughly 159.1 million average monthly users in the European Union for ChatGPT search.

The EU now calls ChatGPT a very large search engine

3 September 2026
Answer card stating that on 31 August 2026 the Department of War added OpenAI ChatGPT Mil and Starshield AI Grok for Government to the GenAI.mil portal alongside Google Gemini, all three accredited at Impact Level 5 for Controlled Unclassified Information, with 1.7 million unique users onboarded out of roughly 3 million eligible personnel, and ChatGPT Mil currently serving GPT-5.4 Terra with GPT-5.6 Terra said to be rolling out.

ChatGPT Mil and Grok reached IL5 on GenAI.mil

3 September 2026
Answer card stating that Anthropic opened a research preview of the Model Hardware Standard on 27 August 2026, standardising the driver layer between an operating system and a laboratory instrument with read and write primitives plus discovery and safety limits, reachable through MCP as well as a command line and code files, with no public specification published.

Anthropic’s Model Hardware Standard is gated, and sits under MCP

3 September 2026
Official Cohere key art for the Parse 5 launch: the Cohere mark and the wordmark Parse with a superscript 5 in white, centred on a soft out of focus gradient of deep blue, violet and amber curves.

Cohere Parse 5 is $1.50 per 1,000 pages, on three of five dimensions

3 September 2026
Title card from the OpenAI announcement video: a man sits on a blue sofa in a loft with tall windows and potted plants, a laptop open on the coffee table in front of him, with the words WebMCP in ChatGPT in large white type across the lower left.

WebMCP in ChatGPT needs GPT-5.6 Sol or Terra

3 September 2026
The Agentic Coding section of the official Hy4 preview benchmark appendix published by Tencent, a table comparing Hy3 and Hy4 preview against DeepSeek V4 Pro 0813, Qwen 3.8 Max, GLM 5.3, Kimi K3, GPT 5.6 Sol and Claude Opus 5 across SWE-bench Multilingual, SWE-bench Pro, DeepSWE, three SWE Atlas tasks, SWE-Marathon, Terminal-Bench 2.1, NL2Repo-Bench, CyberGym, ProgramBench, PostTrainBench and Harbor-Index.

Tencent’s 770B Hy4 tops one benchmark row in 46

3 September 2026
  • About
  • Contact
  • Privacy
  • Legal
Sunday, September 6, 2026
  • Login
Packet Nebula
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About
No Result
View All Result
Packet Nebula
No Result
View All Result
Home Security

Secure Boot certificates expire in 2026: the Linux fix

by stephane
22 June 2026
in Security
0
Answer card: Microsoft 2011 Secure Boot certificates expire in 2026, but existing Linux systems keep booting; the fix is enrolling the 2023 key with fwupd.
492
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

The headlines made it sound like every Linux PC turns into a brick on 27 June 2026, the day Microsoft's 2011 Secure Boot certificate expires. It doesn't. If your machine boots today, it keeps booting after that date, dual-boot and all, because expiry stops Microsoft signing new boot components, it does not revoke the keys your firmware already trusts. So nothing detonates in June. The real problem is slower and quieter: new distro installs and future shim and kernel updates are signed with Microsoft's 2023 certificate, and your firmware will not trust those until you enroll the new key. On Linux that is one command through fwupd, when your vendor ships it. Here's what is actually expiring, what genuinely breaks, and exactly what to run.

The short answer

Microsoft’s 2011 Secure Boot certificates expire through 2026 (the Linux shim cert on 27 June). Nothing that boots today stops booting: expiry is not revocation. The catch is tomorrow. New installs and future shim updates use Microsoft’s 2023 certificate, so you enroll the new key in your firmware with fwupd. One command, one reboot.

Jun 20262011 certs start expiring
0machines bricked on the date
fwupdmgrupdate: the one-command fix
Answer card: Microsoft 2011 Secure Boot certificates expire in 2026 but existing Linux systems keep booting; enroll the 2023 key with fwupd.
The calm version. The scary headline is about signing new things, not your current boot.

Nothing bricks in June (or October)

Here is the whole panic, defused, in one paragraph. Microsoft’s 2011 Secure Boot certificates expire across 2026, but expiry is not revocation. A certificate that has already vouched for the bootloader sitting in your firmware keeps being trusted; expiry only means Microsoft can no longer sign new things with it. So the machine that boots Linux this morning boots it tomorrow, and the morning after 27 June, dual-boot and all. Anyone telling you to back up and reinstall before the date is selling fear. Fedora’s own write-up is, fittingly, titled “Don’t Panic.”

What is actually expiring

Three certificates, three jobs, three dates.

Table of the three expiring 2011 Secure Boot certificates: KEK CA 2011 (24 Jun 2026, signs db/dbx updates), UEFI CA 2011 (27 Jun 2026, signs the Linux shim), Windows PCA 2011 (19 Oct 2026, Windows bootloader).
Three certs, three roles. The middle one is the one Linux rides on.

The one Linux cares about is the Microsoft UEFI CA 2011: it signs third-party bootloaders, which in practice means the shim, the small Microsoft-signed first stage that then loads your distro’s GRUB and kernel. It lapses 27 June 2026. Next to it, the KEK CA 2011, which signs updates to the Secure Boot databases themselves, expires 24 June 2026, and the Windows Production PCA 2011, the one behind the Windows boot loader, runs out 19 October 2026. Each has a 2023 replacement that needs to be sitting in your firmware’s key database for the new signatures to be trusted.

The real problem: tomorrow’s updates, not today’s boot

This is the part that genuinely matters. New shims, and the new kernels they load, are now signed with Microsoft’s 2023 certificate. Firmware that only knows the 2011 keys will refuse to run them. So two things quietly stop working if you do nothing:

  • New installs. Boot a freshly downloaded distro on an untouched machine and its 2023-signed shim may not be trusted, so the installer never starts while Secure Boot is on.
  • Security updates. Once your distro moves to 2023-signed shims, firmware that has not enrolled the 2023 key stops accepting them, so you stop receiving boot-level security fixes. That is the “degraded security” the vendors warn about, and it is the slow-burn risk, not a dramatic June failure.

And dual-boot does not make any of this worse. Windows and Linux lean on the same Secure Boot keys in the same firmware, so the expiry hits the machine evenly or not at all. There is no special Linux curse here, whatever the headline implied.

The fix: enroll the 2023 key with fwupd

On Linux the whole thing is usually two commands, because the firmware key update ships through the Linux Vendor Firmware Service and fwupd applies it. Refresh the metadata first:

Linux
sudo fwupdmgr refresh

Then pull and apply whatever your vendor has published:

Linux
sudo fwupdmgr update
Terminal: sudo fwupdmgr refresh downloads LVFS metadata, then sudo fwupdmgr update offers a UEFI Secure Boot key update that enrolls Microsoft's 2023 CA and applies on reboot.
Two commands. The key update applies on the next reboot, and you're current.

If your vendor has pushed the update to the LVFS, fwupd offers it, schedules it, and applies it on the next reboot, adding the 2023 certificate to your firmware’s db. If fwupdmgr shows nothing for your hardware, the update simply has not been published for your board yet: check again later, or ask the OEM for a UEFI update that does the same job. On a Windows-and-Linux dual-boot machine, letting Windows Update run enrolls the new keys too, because it is the same firmware database underneath. It is the same kind of scheduled housekeeping as renewing a TLS certificate before it lapses: boring, and a non-event if you do it on time.

What not to do

Three tempting “fixes” that make things worse:

  • Do not remove the 2011 certificate. It still vouches for legacy option ROMs on graphics and network cards; pull it and those peripherals can stop initialising. Add the 2023 key, do not subtract the old one.
  • Do not hand-edit the Secure Boot db with efivar incantations from a forum unless you truly know the consequences. A botched db is a machine that will not boot, which is exactly the disaster the panic warned about, now self-inflicted.
  • Do not “solve” it by turning Secure Boot off. It works, and it throws away the boot-level tamper protection you turned it on for.

Run sudo fwupdmgr update sometime in the next few months, reboot, and you are finished: your firmware now trusts both the old and the new Microsoft keys, your current install keeps booting, and the next one will too. The 2026 expiry is a chore with a frightening headline, not an emergency.

Sources: Microsoft Support, Red Hat and Fedora Magazine. Certificate names and dates as published by Microsoft for 2026.

Frequently asked questions

Will my Linux PC stop booting on 27 June 2026?

No. A machine that boots today keeps booting after the date, dual-boot included. Certificate expiry is not revocation: the keys already trusted in your firmware stay trusted, so your installed shim and kernel keep loading. Expiry only stops Microsoft from signing new boot components with the old 2011 certificate.

What actually breaks when the Secure Boot certificate expires?

Two things, both about the future, not today. New OS installs: a freshly downloaded distro signed with the 2023 certificate may not be trusted by firmware that only knows the 2011 keys, so the installer will not start under Secure Boot. And future security updates: once your distro ships 2023-signed shims, firmware without the 2023 key stops accepting them, so you fall behind on boot-level fixes.

How do I update Secure Boot keys on Linux?

Through fwupd, when your hardware vendor has published the update to the Linux Vendor Firmware Service. Run sudo fwupdmgr refresh then sudo fwupdmgr update, and reboot to apply. That enrolls the Microsoft 2023 certificate in your firmware db. If fwupdmgr offers nothing for your board, the update is not published for it yet: check back, or ask your OEM for a UEFI update.

Does this affect Windows and Linux dual-boot?

It affects both equally, which means neither is specially cursed. Windows and Linux rely on the same Secure Boot keys in the same firmware, so the expiry hits the machine, not one OS. On a dual-boot system, letting Windows Update run also enrolls the new keys, since it is the same firmware database that Linux uses.

Should I just disable Secure Boot to avoid the hassle?

You can, and it is a real downgrade. Disabling Secure Boot removes the boot-level tamper protection entirely, which is a much bigger loss than the housekeeping you were avoiding. It is fine as a momentary diagnostic, wrong as a permanent answer. Enroll the 2023 key instead and keep the protection.

Tags: dual-bootguidelinuxsecure-bootsecurityuefi
Share197Tweet123
stephane

stephane

  • Trending
  • Comments
  • Latest
Answer card: Proton Lumo 2.0 is private by policy, not by locality. Saved history is locked so even Proton cannot read it, but the prompt is decrypted on a Proton EU server to answer it, then forgotten.

Proton Lumo 2.0 review: how private is it, really?

3 September 2026
Google's official announcement image for the release, reading Introducing Gemini 3.8 Flash and 3.8 Flash Cyber in black type over a pale blue background with a blurred white chevron and the four colour Gemini spark below.

Gemini 3.8 Flash keeps the price and the 1 January cliff

3 September 2026
Answer card stating that Anthropic announced Enterprise Frontier Safeguards on 1 September 2026, that activity data used for misuse monitoring moves into cloud storage the customer controls under the customer own encryption keys, that Anthropic charges nothing for the feature while the cloud provider bills storage and egress, and that the phased rollout starts later in autumn 2026 with interim zero data retention on Fable 5 and Fable 5.1 for eligible customers.

Anthropic moves retention into your own cloud, for 30 days

3 September 2026
Answer card: JWTs are not encrypted, anyone can read them; the signature proves who issued the token, not who may read it.

Are JWTs encrypted? No, and the difference will bite you

0
Answer card: a random 8 character password falls in under 2 hours offline, while 16 random characters hold for 1.4 trillion years at the same speed.

How long does it take to crack a password in 2026?

0
Answer card: three DNS records decide if your mail lands or bounces; SPF lists allowed senders, DKIM signs messages, DMARC sets the failure policy.

SPF, DKIM and DMARC explained: the records your email needs

0
Answer card stating that Mullvad announced on 3 September 2026 that it is shutting down its public encrypted domain name system servers on 2 November 2026 and sponsoring the Quad9 Foundation instead, with 194.242.2.2 and its five sibling addresses all going away, and virtual private network customers unaffected.

Mullvad’s DNS servers go dark on 2 November, and Quad9 blocks no ads

5 September 2026
OpenAI announcement image for GPT-6 Astra, a spiral galaxy of white, blue and amber points of light curling around a bright core on a near black star field.

GPT-6 Astra lists at $10 and $50, 2.5x what GPT-5.6 Sol costs

6 September 2026
Google's official announcement image for the release, reading Introducing Gemini 3.8 Flash and 3.8 Flash Cyber in black type over a pale blue background with a blurred white chevron and the four colour Gemini spark below.

Gemini 3.8 Flash keeps the price and the 1 January cliff

3 September 2026
  • About
  • Contact
  • Privacy
  • Legal

Copyright © 2026 Stephane Cardon.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About

Copyright © 2026 Stephane Cardon.