Linux Secure Boot tanúsítványok – szeptemberi határidő, amiről tudnod kell
September Approaches: Linux Secure Boot Faces a Key Transition
Many Linux users run with Secure Boot enabled without even knowing it. If that's you, there's something important coming down the pike that could complicate your next system installation.
Here's the deal: the shim bootloader—the essential first-stage component that lets Linux work with UEFI Secure Boot—carries a signature from Microsoft. That signing key dates back to 2011, and Microsoft is retiring it on September 11.
The new replacement key has actually been in circulation since 2023. Problem? Millions of machines out there simply don't have it yet. For some hardware, getting that update might mean waiting on a firmware patch from your vendor—something that may never materialize for older systems.
Does This Affect You?
If you've got an existing Linux installation that's already set up, you're likely in the clear. Your distribution's bootloader is signed with its own keys, and those should keep chugging along without issues.
Trouble starts brewing when you try to:
- Install a fresh Linux distribution on a Secure Boot machine
- Boot from installation media on systems running outdated firmware databases
- Deal with those pesky edge cases where vendors dropped the ball on updates
Richard Hughes, the mind behind LVFS (Linux Vendor Firmware Service), put it this way: "The KEK updates are going out at roughly 98% success, and db update sits around 99%—but even 1% multiplied by millions of users means quite a few people are going to hit snags." Not alarming, but not exactly comfort food either.
What's Actually Breaking?
Here's the twist: the keys themselves aren't malfunctioning. The real culprit is storage space. Older UEFI firmwares have cramped quarters for EFI variables. Sometimes deploying these updates means "defragmenting" that space by resetting the BIOS to factory defaults. As Hughes points out: "The older your BIOS, the more likely you are to run into this."
For that unlucky 1-2% hitting problems, the fix usually looks like this:
- Reboot
- Reset BIOS to factory defaults
- Attempt the update again
The Open-Source Cavalry
Good news: the community has been gearing up for this. LVFS and fwupd—tools that handle firmware updates directly from Linux—have been beefed up to manage these certificate rollovers. Most major distributions will ship updated shim binaries bearing the new Microsoft signature, so your next OS install should go off without a hitch.
Vendors are pushing out KEK (Key Exchange Key) updates so fwupd can safely tuck that new Microsoft certificate into your system's firmware database. For machines where vendors have gone dark, disabling Secure Boot entirely might be your only practical option.
Your Action Plan
Managing Linux systems with Secure Boot? Here's what to do before September arrives:
- Audit your current setup before the deadline hits
- Flash your firmware if your vendor has published updates
- Keep alternative boot options handy just to be safe
- For fresh installs after September, make sure your installation media includes the updated shim
The open-source world has survived certificate expirations before. This one should largely slip by without catastrophe. But if you're managing a fleet of machines or planning a clean install in the coming months, now's the time to verify your firmware status—and maybe send your hardware vendor a polite email asking if they're still supporting your system.
For developers and startups running Linux in production, add this to your maintenance checklist. A few minutes of preparation now beats frantic debugging later.
Stay secure out there—preferably with keys that haven't expired.