Expiration of Secure Boot signing certificates in 2026

If you will ever be thinking of (unlikely for many, I know, anyways) having SecureBoot enabled and use a distribution which supports it (or enable it in Arch etc.) in a future, you might want to have a read:

https://www.redhat.com/en/blog/expiration-secure-boot-signing-certificates-2026

Sharing is CARING!

YOU (yes you :index_pointing_at_the_viewer:) are WelCome!

And AS always the PLEASURE was all om MY SIDE.

THANKs for your ATTENTION!

@cactux , the REAL one; The ONE and ONLY :check_box_with_check:

:kiss_mark:

FWIW I ran fwupd some time ago and that appeared to update the certificates for both my systems

Same here, on two systems. I’ve got one more to go. I’ll be looking into it this evening.

Devices that have been updated successfully:
 • UEFI CA (2011 → 2023)
 • UEFI dbx (20241101 → 20250902)

Just did the “fwupdmgr update” on my Thinkpad T14 Gen2 AMD, but Secure Boot is bios disabled.

You can keep secure boot disabled and boot up your current system normally.

However this would effect those who use signed bootloaders (distributions like Debian, Ubuntu, Fedora, openSUSE, etc.) when their next iteration of their bootloaders need to be signed only by the 2023 key for them to be able to boot with Secure Boot enabled.