Hasty Briefsbeta

Bilingual

It's dead, Jim – the old Microsoft UEFI CA from 2011 expired yesterday

5 days ago
  • #Debian
  • #SecureBoot
  • #UEFI
  • The old Microsoft UEFI CA from 2011 expired on 26 June 2026, ending the signing for option ROMs and other software.
  • Debian and other distributions have new dual-signed shim binaries with both old and new CAs, thanks to quick reviews by the shim-review team and Microsoft.
  • Debian has started rolling out these shims in unstable and testing, with plans for point releases in Debian 12 and 13 to ensure Secure Boot functionality.