Microsoft's 2011 Secure Boot signing certificate expires June 26, 2026, but existing RHEL systems will continue to boot normally. The expiration only affects signing new boot components, not booting with already trusted ones. Red Hat is releasing updated shims signed with the 2023 certificate for supported releases starting with RHEL 9.7. Administrators should assess Secure Boot settings, verify enrolled certificates, monitor security advisories, and avoid manual DB updates until vendors provide guidance. For virtual environments, update the edk2-ovmf package on hypervisors to ensure new VMs inherit the 2023 certificates.

Table of contents
What is UEFI Secure Boot and how does it work?What does the 2026 certificate expiration mean for RHEL?What are the recommended actions for Red Hat environments?How can I determine whether Secure Boot is enabled on my systems?How can I determine which Secure Boot certificates are enrolled?How do I update my firmware using LVFS?Can I update the UEFI Secure Boot DB directly and without a full firmware update?Should I install the 2023 UEFI db update now?How does this apply to virtual machines using OVMF?Summary165 Impressions