惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
Vercel News
Vercel News
博客园_首页
Y
Y Combinator Blog
美团技术团队
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
阮一峰的网络日志
阮一峰的网络日志
aimingoo的专栏
aimingoo的专栏
H
Hackread – Cybersecurity News, Data Breaches, AI and More
MyScale Blog
MyScale Blog
GbyAI
GbyAI
人人都是产品经理
人人都是产品经理
T
Tailwind CSS Blog
MongoDB | Blog
MongoDB | Blog
D
DataBreaches.Net
博客园 - Franky
Engineering at Meta
Engineering at Meta
量子位
The GitHub Blog
The GitHub Blog
F
Fortinet All Blogs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
酷 壳 – CoolShell
酷 壳 – CoolShell
N
Netflix TechBlog - Medium

Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises – Computerworld

Microsoft 365: A guide to the updates Windows 11 Insider Previews: What’s in the latest build? Windows 11: A guide to the updates Apple can't make chips fast enough, but that's only part of the story AI-led job cuts don’t always mean stronger ROI — Gartner Microsoft, Google push AI agent governance into enterprise IT mainstream Microsoft now has more than 20M paying Copilot users AI is more accurate than doctors in emergency diagnoses — study Start small, but start now: How to bring AI into your small business Apple is preparing to spend, but not necessarily on AI 10 quick productivity tips for Microsoft 365 mobile apps Relying on LLMs is nearly impossible when AI vendors keep changing things Apple breaks records, admits it can’t make Macs fast enough Spotlight report: Transforming software development with AI - Whitepaper Repository - 25 great uses for an old Android device AI chatbots need ‘deception mode’ Friendlier chatbots can be less reliable, study says Gartner sees untamed growth in agentic AI Apple reportedly abandons Vision Pro AI venture funding to shoot up this year as bubble looms Scaling up a tech startup in Europe is hard — 'EU Inc.' aims to help Apple will be behind on AI — until it isn’t EU lawmakers fail to agree on watered-down AI Act, talks pushed to May Android reminders, reinvented Who’s the better CEO, Apple’s Tim Cook or Microsoft’s Satya Nadella? AWS unveils trio of key AI strategy announcements SAS makes AI governance the centerpiece of its agent strategy Can Apple’s new CEO turn things around? Enterprises need to think beyond GPUs for agentic AI, analysts say Fleet hopes to be the MDM provider for the AI Era
FAQ: What you need to know about expiring Windows Secure ...
by Andy Patrizio · 2026-05-26 · via Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises – Computerworld

A major change is coming to Windows that neither individual users nor IT admins can ignore. Here’s how to prepare.

Microsoft is preparing to make a significant change to the Secure Boot system in Windows that will impact operations for both clients and servers.

In a nutshell: The Secure Boot certificates that Microsoft issued 15 years ago are being replaced by newer ones, with the older certificates set to expire beginning in June. To continue to receive the most up-to-date security protections for the Windows boot-up process, individual users and IT administrators alike need to make sure their Windows devices have the new Secure Boot certificates installed.

Have questions? Of course you do. Here are answers to eight key questions about the Secure Boot certificate updates.

What is Secure Boot?

Secure Boot is a security feature that verifies that all firmware-based software is signed by a trusted certificate when Windows starts up. If something doesn’t match, it gets blocked. This all happens immediately on boot, before Windows or anything else loads.

Secure Boot is a part of the UEFI firmware standard, which replaced the older BIOS model for modern PCs. It was added to UEFI in 2011 so that only trusted, signed code could run during startup.

Microsoft issued its original Secure Boot certificates in 2011 and introduced Secure Boot as an optional feature in Windows 8. It remained optional in Windows 10, since UEFI had not had much time to penetrate the market when Windows 10 was released in 2015. But Secure Boot became mandatory in Windows 11. Windows 11 came out in 2021, giving UEFI-powered systems plenty of time to saturate the marketplace.

What’s happening with Windows Secure Boot certificates?

To keep up with emerging threats, Microsoft in 2023 issued new Secure Boot certificates to replace the 2011 versions. Those began rolling out on Windows devices in 2024, and according to Microsoft, nearly all devices shipped in 2025 and later already include the 2023 certificates.

However, most older devices with Secure Boot enabled (those manufactured from 2012 to 2024) have been relying on the 2011 certificates — and those certificates begin expiring in June.

There are three Windows Secure Boot certificates expiring this year:

  • Microsoft Corp. KEK CA 2011: authorizes changes to the Secure Boot database
  • Microsoft UEFI CA 2011: signs third-party drivers to allow hardware components to load its firmware during boot
  • Microsoft Windows Production PCA 2011: signs the Windows bootloader itself, the core piece of software that loads Windows from your hard drive into memory

The first two certificates will expire on June 27; the third will expire on October 19.

For devices that didn’t ship with the 2023 certificates pre-installed, Microsoft is now rolling out those new certificates via Windows Update.

What happens to devices that don’t have the updated certificates after the old ones expire?

Lacking the new certificates, your PC keeps working and you’ll still receive regular Windows updates, but the computer loses the ability to receive security updates for the boot process. New protections for Windows Boot Manager won’t install. Updates to the Secure Boot database won’t apply. Revocation lists that block known malicious software won’t update. Your system is essentially defenseless against emerging boot-level threats.

Over time, not having the current certificates may also lead to compatibility issues with newer operating systems, firmware, hardware, or Secure Boot–dependent software.

How are Secure Boot certificates updated?

For most devices that have Windows updates managed by Microsoft (this includes consumer devices and some business and education devices), the new certificates will be installed automatically via Windows Update as part of the regular monthly update process, with no additional action required. Microsoft has been gradually rolling out the new certificates since June 2025, so your device may have them already.

Some devices may require a separate firmware update from the device manufacturer before the system can apply the new Secure Boot certificates. That’s because the new certificates need to be written into your motherboard’s UEFI databases that Secure Boot uses during the boot process. HP, Dell, Lenovo, and other major PC manufacturers have been releasing BIOS updates specifically to ensure their systems can properly accept the new certificates. (See also “What else should I know about the Secure Boot certificate updates” later in the story.)

Microsoft recommends that customers check their Original Equipment Manufacturer (OEM) support pages for any applicable firmware updates and install them where needed. Microsoft maintains a list of OEM support pages for Secure Boot update readiness.

Out-of-support Windows versions will not receive the new certificates.

As noted above, Microsoft-managed Windows client devices will have the new Secure Boot certificates delivered automatically through Windows Update. The new certificates will not be delivered automatically in IT-managed environments.

How do I know if the new Secure Boot certificates have been installed?

Individuals and business/education users with Microsoft-managed updates can check Windows Security > Device security > Secure Boot. Here you’ll find badges and status messages indicating whether your device is fully updated and if you need to take action. See Microsoft’s “Secure Boot certificate update status in the Windows Security app” support page for details.

What else should I know about the Secure Boot certificate updates?

With the April 2026 Windows security update and upcoming monthly updates, some devices may experience one additional reboot during installation. This is the one-time restart that applies the new Boot Manager after the certificates have been written to firmware — it is expected and documented.

Because Secure Boot is rooted in platform firmware, some environments may require additional steps. These can include specialized hardware configurations, certain virtualized environments where the platform provider manages firmware behavior, or devices that depend on OEM support. Microsoft says it is working closely with hardware and platform partners to ensure broad compatibility and a smooth transition.

In March, tech writer and Windows MVP Ed Tittel wrote a detailed article for Windows Latest about reported Secure Boot certificate update problems; the article includes a list of common issues for motherboards from various vendors. (Tittel also writes for Computerworld.) At help forums such as answers.microsoft.com, TenForums.com, ElevenForum.com, and TechPowerUp.com, he noted, issues reported for desktop PCs, especially custom builds, greatly outnumbered those reported for laptops.

In May, HP published an advisory saying that a faulty BIOS update it issued to users in April may cause its computers to get stuck in a BitLocker Recovery loop that prevents implementation of the 2023 Secure Boot certificates. All commercial HP laptops, desktops, and workstations running Windows 23H2, 24H2, or 25H2 are susceptible to this issue. The advisory includes a manual workaround.

What resources are available for help deploying and troubleshooting the new Secure Boot certificates?

Related reading:

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.