Linux Secure Boot faces disruption as Microsoft signing key nears September expiration
By
By Jake EdgeJuly 16, 2025
Summary
Linux users with Secure Boot enabled rely on a Microsoft key for booting that expires in September. Microsoft will stop using this key to sign the shim UEFI bootloader used by Linux distributions. A replacement key has been available since 2023 but may not be installed on many systems, potentially causing boot issues for Linux users after the expiration date.
Source
Key quotes
· 3 pulledLinux users who have Secure Boot enabled on their systems knowingly or unknowingly rely on a key from Microsoft that is set to expire in September.
After that point, Microsoft will no longer use that key to sign the shim first-stage UEFI bootloader that is used by Linux distributions to boot the kernel with Secure Boot.
But the replacement key, which has been available since 2023, may not be installed on many systems; worse
You might also wanna read
Secure Boot Certificates to Expire June 24: Windows and Linux Users Must Update Keys
Windows and Linux users face a critical June 24 deadline when three Microsoft-signed certificates used for Secure Boot will expire. These ce
Secure Boot Certificates to Expire June 24: Windows and Linux Users Must Update Cryptographic Keys
Windows and Linux users face a critical June 24 deadline when three Microsoft-signed certificates used for Secure Boot will expire. These ce
Secure Boot certificates expiring June 24: Windows and Linux users must update keys
Windows and Linux users face a June 24 deadline to update Secure Boot cryptographic keys, as three Microsoft-signed certificates that verify
arstechnica.com·6d agoSecure Boot certificates expiring June 24: Windows and Linux users must update keys
Windows and Linux users face a June 24 deadline to update Secure Boot cryptographic keys, as three Microsoft-signed certificates that verify
arstechnica.com·6d agoThree Microsoft Secure Boot Certificates Set to Expire on June 24, Posing Security Risk
Three Microsoft-signed certificates that underpin Secure Boot's chain of trust for verifying boot-time firmware and software will expire on
Microsoft Secure Boot certificates expire June 27—here's what that means for your old PC
Windows Secure Boot certificates must be updated by June 24th deadline
Windows users face a June 24th deadline to install updated Secure Boot certificates on all systems using the Secure Boot feature. First warn
Comments
Sign in to join the conversation.
No comments yet. Be the first.
