Windows Secure Boot certificates
Secure Boot is a security feature in UEFI-based firmware (Unified Extensible Firmware Interface) that ensures only trusted software is executed during a device’s boot sequence. Since Windows introduced support for Secure Boot, all Windows-based devices have had the same set of Microsoft certificates in the KEK and the database. These original certificates are due to expire in June 2026. To continue running Windows and receive regular updates for your Secure Boot configuration, you must update these certificates.

