---
title: "Secure Boot certificate changes in 2026: Guidance for RHEL environments"
url: https://daily.dev/posts/secure-boot-certificate-changes-in-2026-guidance-for-rhel-environments-q2yiojqcb
source_url: https://developers.redhat.com/articles/2026/02/04/secure-boot-certificate-changes-2026-guidance-rhel-environments
type: article
source: "Red Hat Developer"
published: 2026-02-04T03:18:13.913Z
updated: 2026-02-04T03:18:55.053Z
tags: ["security", "linux", "infrastructure"]
reading_time: 6
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Secure Boot certificate changes in 2026: Guidance for RHEL environments

**[Red Hat Developer](https://daily.dev/sources/rhdev)** · 6 min read · 0 upvotes · 0 comments

## Summary

Microsoft's 2011 Secure Boot signing certificate expires June 26, 2026, but existing RHEL systems will continue to boot normally. The expiration only affects signing new boot components, not booting with already trusted ones. Red Hat is releasing updated shims signed with the 2023 certificate for supported releases starting with RHEL 9.7. Administrators should assess Secure Boot settings, verify enrolled certificates, monitor security advisories, and avoid manual DB updates until vendors provide guidance. For virtual environments, update the edk2-ovmf package on hypervisors to ensure new VMs inherit the 2023 certificates.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://developers.redhat.com/articles/2026/02/04/secure-boot-certificate-changes-2026-guidance-rhel-environments>

## Similar posts on daily.dev

- [What you need to know about the Microsoft Secure Boot certificate expiration: Don’t Panic\!](https://daily.dev/posts/what-you-need-to-know-about-the-microsoft-secure-boot-certificate-expiration-don-t-panic--fm8qejjsl) · Fedora Magazine · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#linux](https://daily.dev/tags/linux), [#infrastructure](https://daily.dev/tags/infrastructure)

[View this post on daily.dev](https://daily.dev/posts/secure-boot-certificate-changes-in-2026-guidance-for-rhel-environments-q2yiojqcb)
