Certificati Secure Boot in scadenza: Linux rischia il blocco a settembre

Certificati Secure Boot in scadenza: Linux rischia il blocco a settembre

Giu 23, 2026 linux secure boot uefi firmware updates system administration open source fwupd lvfs certificate expiration devops

Linux Secure Boot: The Deadline Is Real

Got Secure Boot enabled on your Linux machine? Plenty of you do, even if you didn't consciously turn it on. Well, mark September 11 on your calendar. That's when an old Microsoft signing key—dating back to 2011—stops being valid for the shim bootloader.

For those not in the know, the shim is that little piece of code that makes Linux boot properly on systems with Secure Boot active. It's signed by Microsoft so your UEFI doesn't throw a fit during startup. The problem? The key signing this thing is about to retire, and millions of machines don't have the replacement installed yet.

Here's the real kicker: hardware vendors control whether your firmware gets the new certificate. If they've moved on to newer products, your aging workstation might never see an update.

Will Your System Even Notice?

Honestly? Probably not. If you've got Linux running right now and it boots fine, you're likely in good shape. Your distribution's bootloader carries its own signatures, and those won't suddenly stop working.

The trouble starts when you try to:

  • Install Linux fresh on a Secure Boot machine
  • Boot from USB or DVD on older systems
  • Deal with hardware that vendor updates skipped entirely

Richard Hughes from LVFS put it nicely: rollout success sits around 98-99%. Sounds great until you realize that percentage still leaves millions of machines potentially affected. Not a catastrophe, but definitely not nothing.

Why Does This Even Happen?

It's not about keys breaking. It's about storage. Older UEFI firmwares have tiny amounts of space for certificates. Sometimes you need to "defragment" that space by resetting BIOS to factory defaults before the new key can fit. The older your hardware, the more likely you hit this wall.

For the unlucky few percent dealing with failed updates, the workaround is straightforward: reboot, reset BIOS to defaults, try again.

The Cavalry Is Coming

Good news from the open-source world. LVFS and fwupd—tools that push firmware updates from within Linux—have been updated to handle this transition smoothly. The major distributions will ship shim binaries signed with the fresh Microsoft key, so new installations should work without drama.

Vendors are rolling out KEK updates through fwupd, which safely adds the new certificate to your system's firmware database. For hardware where vendors have gone dark? Disabling Secure Boot might be your only option.

Your Action Plan

Running Linux with Secure Boot? Here's what to do before September:

  1. Check your current setup now
  2. Update your firmware if updates exist
  3. Keep alternative boot options ready
  4. For new installs after September, make sure your installation media has the updated shim

The open-source ecosystem has dealt with certificate rollovers before. This one should mostly pass without drama. But if you're managing multiple machines or planning a fresh install soon, spend a few minutes verifying your firmware is current.

A little prep now beats frantic debugging later.

Stay secure out there—preferably with valid keys.

Read in other languages:

RU BG EL CS UZ TR SV FI RO PT PL NB NL HU FR ES DE DA ZH-HANS EN