It's dead, Jim – the old Microsoft UEFI CA from 2011 expired yesterday
5 days ago
- #Debian
- #SecureBoot
- #UEFI
- The old Microsoft UEFI CA from 2011 expired on 26 June 2026, ending the signing for option ROMs and other software.
- Debian and other distributions have new dual-signed shim binaries with both old and new CAs, thanks to quick reviews by the shim-review team and Microsoft.
- Debian has started rolling out these shims in unstable and testing, with plans for point releases in Debian 12 and 13 to ensure Secure Boot functionality.