What you need to know about the Microsoft Secure Boot certificate expiration: Don’t Panic!
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Microsoft's UEFI Secure Boot signing certificate from 2011 expires in June 2026, but this does not mean systems will stop booting. Existing public keys remain valid in firmware databases unless explicitly removed or revoked. Since October 2025, Microsoft has been dual-signing with a new 2023 key. Fedora Rawhide (F45) already ships a dual-signed shim for forward compatibility. Users are advised to update their firmware database via fwupd when available, check which keys are enrolled using mokutil, and avoid manually removing or revoking the 2011 key since it was also used to sign option ROMs. Practical commands are provided to check UEFI vs BIOS mode, Secure Boot status, enrolled keys, and shim signing details.