Do you want to switch the language?

Microsoft Secure Boot certificates

Windows Secure Boot certificates

Secure Boot is a security feature in UEFI-based firmware (Unified Extensible Firmware Interface) that ensures only trusted software is executed during a device’s boot sequence. Since Windows introduced support for Secure Boot, all Windows-based devices have had the same set of Microsoft certificates in the KEK and the database. These original certificates are due to expire in June 2026. To continue running Windows and receive regular updates for your Secure Boot configuration, you must update these certificates.

Next steps:

Inventory and identification of the affected systems.

Checking UEFI/BIOS/firmware compatibility and the availability of any necessary OEM updates.

Pilot testing / validation on representative systems.

Patching / certificate update, including the necessary reboot.

Success check (checking whether the 2023 certificates are present in KEK/DB).

We bring about positive change

Inventory

Physical and virtual machines (VMs) running supported versions of:

  • Windows 10
  • Windows 11
  • Windows Server 2012
  • Windows Server 2012 R2
  • Windows Server 2016
  • Windows Server 2019
  • Windows Server 2022
  • Windows Server 2025

This affects all systems released since 2012, including the Long-Term Servicing Channel (LTSC).

⚠️ Note: Windows 8 is also affected, but is no longer supported.

Note:
Affected third-party operating systems also include macOS. However, these fall outside the scope of Microsoft support.
On Linux systems in a dual-boot configuration with Windows, Windows updates the certificates on which Linux relies.

Source: https://techcommunity.microsoft.com/blog/windows-itpro-blog/act-now-secure-boot-certificates-expire-in-june-2026/4426856

We bring about positive change

Patching

Updating the Secure Boot certificates depends on the support provided by the respective manufacturer’s UEFI/BIOS/firmware. In certain cases, a Windows update alone is not sufficient. In addition, a recent OEM firmware/BIOS update may be required to ensure that the new 2023 Secure Boot certificates (in particular KEK and DB) can be successfully installed:

You might also be interested in:

Discontinuation of Microsoft SMS & Voice Authentication

Read more

How may I help you?
CANCOM Austria AG processes your personal data exclusively in the context of your inquiry. Processing is carried out in accordance with Art. 6(1)(b) GDPR for the performance of a contract or a request. For storage and hosting, we use IT service providers who may access your data in the process. Providing your data is voluntary; however, without it, your inquiry cannot be processed. For questions, you can reach us at info@cancom.com.

Under this link you will find our privacy policy with further information.