惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
J
Java Code Geeks
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Last Week in AI
Last Week in AI
雷峰网
雷峰网
博客园_首页
小众软件
小众软件
美团技术团队
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
腾讯CDC
P
Proofpoint News Feed
MongoDB | Blog
MongoDB | Blog
Google DeepMind News
Google DeepMind News
MyScale Blog
MyScale Blog
U
Unit 42
The Cloudflare Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Microsoft Security Blog
Microsoft Security Blog
大猫的无限游戏
大猫的无限游戏
Engineering at Meta
Engineering at Meta
N
Netflix TechBlog - Medium
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 叶小钗

AI demand is so high, AWS customers are trying to buy out its entire capacity | Network World

Cisco: Latest news and insights 2026 network outage report and internet health check Selector targets the network visibility gap in multi-cloud infrastructure Top network and data center events of 2026 How AI is transforming network incident response (and where it still falls short) Google opens TPUs to enterprises beyond its own cloud via Blackstone JV AI, cybersecurity skills top IT pay premiums Startup Bolt Graphics promises 5x performance over Nvidia’s best GPU Wireless security is a battle of AI vs. AI NetOps teams look to AI to automate Day 2 operations Digital twins reshape network and data center management Network outages, power failures strain data center resiliency Five takeaways from Cisco's blowout quarter and what it means to customers Cisco to cut nearly 4,000 jobs despite strong growth in AI, enterprise networking Startup SPAN teams with Nvidia to put data center nodes in your backyard Hard drive shortage affecting enterprise storage needs Wi-Fi 8 is closer than you think. Here’s what you need to know Cisco open-sources agentic AI security spec HPE revamps private cloud stack for enterprises rethinking VMware Versa takes aim at fragmented enterprise security with CSPM, orchestration update, and AI agent controls Red Hat opens Ansible to AI agents, within limits Red Hat offers endless Linux support — for a fee Red Hat: Sovereignty is more than just compliance Tech job postings hit three-year high as AI demand fuels hiring rebound HPE memory server targets compute-heavy and agentic AI workloads PCI group begins work on new spec to support bandwidth-hungry apps like AI, HPC Q&A: Quantum physicist Sonia Fernández-Vidal on why classical computing isn't going anywhere OpenAI-led consortium seeks to address AI processing bottlenecks AWS hit by US-East-1 outage after data center thermal event Gluware's Titan rises to meet Mythos network vulnerability challenge
Microsoft plans significant update to Windows Secure Boot
by Andy Patrizio · 2026-05-21 · via AI demand is so high, AWS customers are trying to buy out its entire capacity | Network World

In June, Microsoft Secure Boot certificates are set to expire for the first time ever.

Microsoft is about to make a significant upgrade to its Secure Boot system, and if enterprise customers have not gotten started on the upgrade, they are already behind.

Secure Boot is a Windows subsystem that verifies that each driver is signed by a trusted certificate on startup. If something doesn’t match, it gets blocked. For enterprise networking customers, Microsoft Secure Boot enhancements are important because the system defends against firmware-level attacks, bootkits, ransomware, and protect device integrity.

Secure Boot is a part of the UEFI firmware standard, which replaced the older BIOS model for modern PCs. It was added to UEFI in 2011 so only trusted, signed code could run during startup.

Microsoft has not updated the certificates to Secure Boot since it was first introduced 15 years ago. Every PC manufactured since 2012 running Windows 10, Windows 11, or the last four versions of Windows Server (2016/2019/2022/2025) has been relying on certificates from 2011.

Starting on June 27 through October, those certificates begin expiring. When these certificates expire, desktops and servers keep working, but the computer loses the ability to receive security updates for the boot process. For example:

  • New protections for Windows Boot Manager won’t install.
  • Updates to the Secure Boot database won’t apply.
  • Revocation lists that block known malicious software won’t update.
  • The system gradually loses the ability to defend itself.

For desktops, the solution is basically a Windows Update and a new UEFI firmware upgrade. Two updates do the trick. With Windows Server, the process is far more complex.

Windows Server follows a completely different update process. Whereas Windows desktop PC upgrades are almost fully automatic, Windows Server requires manual intervention. IT administrators must validate and manually roll out the certificate updates across their server infrastructure.

Microsoft’s documentation for Windows Server administrators runs dozens of pages. It involves PowerShell commands, registry key checks, firmware validation, pilot deployments, and careful monitoring for enterprises with thousands of servers.

Some devices have fundamental limitations in their hardware or firmware that prevent them from receiving the automated certificate updates. These aren’t theoretical cases. Microsoft’s own documentation acknowledges them.

Administrators will need to inventory which Windows Server systems use Secure Boot and verify the certificates are already present. Some of the newest servers contain updated certificates, but they are very recent releases. Microsoft recommends keeping servers fully patched, then applying the certificate update path for any in-scope device that still relies on the older 2011 chain.

For managed environments, the safest approach is to validate physical servers, cluster nodes, and server VMs separately, since images and firmware update behavior can differ across platforms.

For computers that are no longer being serviced or updated, or their manufacturer has gone out of business, the problem is worse and the only possible solution is replacement. Obsolescence is a way of life and technology, after all.

Microsoft is not doing this by itself. It is getting complete cooperation and coordination with the major hardware OEMs, like HPE, Dell, Lenovo, and other major PC manufacturers. The OEMs have taken it upon themselves to release new firmware updates specifically to ensure that systems can accept the new certificates.

Here are links to resources from Microsoft regarding the certificate upgrade:

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.