Happy Birthday, Secure Boot! Your Certificate Just Expired and Microsoft Needs You to Do Some Homework

The fix involves swapping the old 2011 certificate chain for shiny new 2023 certificates.

Somewhere deep inside Microsoft's Redmond campus, a calendar alert fired this morning that someone set 15 years ago: "Reminder: Secure Boot certificates expire. Action required." That someone has long since left the company. But the problem? Very much still here.

Today, June 24, 2026, the Microsoft Corporation KEK CA 2011 certificate officially expires. Its sibling, the Microsoft UEFI CA 2011, follows on June 27. These are the cryptographic roots that have silently kept your PC's boot process trustworthy since the Windows 8 era — back when Microsoft thought the ribbon interface was a great idea and the cloud was something that just rained on you.

Microsoft's Masterstroke: A Three-Year Rollout for a Certificate Change

To their credit, Microsoft didn't spring this on anyone at the last minute. They've been warning users since 2023. Three. Whole. Years. Plenty of time! Assuming, of course, that you read Microsoft's support documents for fun, follow the Windows IT Pro Blog like a podcast, and have a firmware update from your PC manufacturer — which, as we'll get to, is a big "assuming."

The fix involves swapping the old 2011 certificate chain for shiny new 2023 certificates. The relevant knowledge base article is KB5025885, a document so lengthy and carefully worded that reading it counts as light cardio. In essence: your PC needs to trust the new certificates and stop trusting the old ones. Simple! Unless your BIOS doesn't support it. Or your manufacturer won't release an update. Or you have a dual-boot setup. Or it's a Tuesday.

What Actually Happens If You Ignore This

Nothing dramatic. Your PC won't explode. It will, however, quietly become unable to receive future Secure Boot DBX updates — the blacklist of known-compromised bootloaders. The one that blocks things like the BlackLotus bootkit, a nasty piece of firmware malware that Microsoft has been fighting since 2023.

So in Microsoft's own carefully diplomatic phrasing: if you miss the deadline, "your system security will permanently degrade." Which is a very polished way of saying your boot process will remain stuck in 2023 forever, like a security amber, while the threat landscape cheerfully evolves around it.

How to Know If You're Fine (or Not)

Open Windows SecurityDevice Security → Secure Boot section. You'll see one of three badge colors:

  • 🟢 Green: You're sorted. Go have a coffee.
  • 🟡 Yellow: Update is pending. Windows is working on it. Probably.
  • 🔴 Red: There's a firmware incompatibility. Time to check if your PC manufacturer cares about you — statistically, there's a decent chance they don't.

That last scenario is where things get quietly awkward. Microsoft cannot force every PC on the planet to accept new certificates via Windows Update. The firmware has to cooperate. And manufacturers like Dell have already confirmed they won't be issuing BIOS updates for hardware with end-of-service dates before January 2026. So if you're running a 2019 laptop that has served you faithfully for seven years, congratulations — it is now a Secure Boot orphan, through no fault of its own.

The Microsoft Experience, Summarized

In fairness, none of this is technically wrong. Certificates expire. That's how cryptography works. Replacing them across a billion-plus devices is genuinely hard. But there is something quintessentially Microsoft about shipping a security feature in 2012 with certificates that expire in 2026, spending three years warning people about it in IT blogs most users will never read, and then leaving the resolution dependent on firmware vendors who may or may not bother.

At least they gave it a badge system. Green, yellow, red. Very traffic light. Very reassuring. Very "we tried."

What You Should Do Right Now

  1. Open Windows Security and check your Secure Boot status.
  2. Run Windows Update and install everything pending.
  3. If you see red — check your PC manufacturer's website for a BIOS/UEFI firmware update.
  4. If no firmware update exists, consider that your PC may be living on borrowed (boot) time.
about author