Windows Linux Boot Keys Expiring Soon
Boot security keys for Windows and Linux machines will start expiring on June 24. Systems relying on the old certificates will lose trusted boot chain validation.
The keys sign the initial bootloaders and firmware components. Once expired, loaders fail signature checks on affected hardware. No CVE or CVSS score applies since this is certificate lifecycle, not a code flaw.
Affects any device using the 2011-era Microsoft certificates for UEFI Secure Boot, including the Microsoft UEFI CA 2011 that signs the Linux shim. Includes older Windows 10/11 builds and many Linux distros with default keys.
Windows 11 24H2 already ships the replacement keys.
