Message CenterMajor changeAdmin impact

MC1185931 — Secure Boot playbook for certificates expiring in 2026

MC1185931WindowsstayInformedUpdated: 18 November 2025

Secure Boot helps ensure that only trusted software runs during the boot sequence. It uses cryptographic keys, known as certificate authorities (CAs), to validate that firmware modules come from a trusted source. After 15 years, the Secure Boot certificates that are part of many Windows systems will start expiring in June 2026. These certificates were originally issued in 2011. Many Windows PCs manufactured since 2024 already have updated (2023) certificates. For the remaining devices, we recomm...

Applies to: Windows
Source: mc.merill.net — data via Merill Fernando's open archive (MIT).