Do you want to switch the language?

Microsoft Secure Boot Certificates

Windows Secure Boot Certificates

Secure Boot is a security feature in the UEFI-based firmware (Unified Extensible Firmware Interface) that ensures that only trusted software is executed during a device's boot sequence. Since Windows introduced support for Secure Boot, all Windows-based devices have the same set of Microsoft certificates in the CEC and database. These original certificates are approaching their expiry date of June 2026, so in order to continue running Windows and receive regular updates to your Secure Boot configuration, you will need to update these certificates.

Next Steps:

Inventory & identification of the affected systems.

Checking UEFI/BIOS/firmware compatibility or availability of required OEM updates.

Piloting / validation on representative systems.

Patching / certificate update incl. required reboot.

Success control (check whether the 2023 certificates are available in KEK/DB).

we transform for the better

Inventory

Physical and virtual machines (VMs) with supported versions of:

  • Windows 10
  • Windows 11
  • Windows Server 2012
  • Windows Server 2012 R2
  • Windows Server 2016
  • Windows Server 2019
  • Windows Server 2022
  • Windows Server 2025

This affects all systems released since 2012, including Long-Term Servicing Channel (LTSC).

⚠️ Note: Windows 8 is also affected, but is no longer supported.

Note:
Affected third-party operating systems also include macOS. However, these are outside the scope of Microsoft support.
For Linux systems dual-booting with Windows, Windows updates the certificates that Linux relies on.

Source: https://techcommunity.microsoft.com/blog/windows-itpro-blog/act-now-secure-boot-certificates-expire-in-june-2026/4426856

we transform for the better

Patching

How may I help you?
CANCOM Austria AG processes your personal data exclusively in the context of your inquiry. Processing is carried out in accordance with Art. 6(1)(b) GDPR for the performance of a contract or a request. For storage and hosting, we use IT service providers who may access your data in the process. Providing your data is voluntary; however, without it, your inquiry cannot be processed. For questions, you can reach us at info@cancom.com.

Under this link you will find our privacy policy with further information.