Linux Secure Boot Shim Signing Keys Expired in June — How to Audit Yours
Microsoft's shim loader signing keys used to validate Linux boot components expired in June 2026, affecting systems with Secure Boot enabled. The expiry does not immediately break anything, as firmware validates signatures without checking expiration dates. However, administrators should audit their Secure Boot state using the 'mokutil --sb-state' command and review enrolled keys with 'mokutil --db'. Fedora and RHEL-based users can pull updated keys via 'fwupdmgr update', while Ubuntu users should verify their shim-signed package is up to date. The issue is considered routine maintenance rather than an emergency, but is especially worth addressing for those managing fleets of Linux workstations or servers.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in