Microsoft's 2026 Secure Boot Certificate Rollout Stalls Despite Two Years of Preparation
Microsoft's Windows Production PCA 2011 certificate, embedded in the boot trust chain of nearly every PC sold over the past 15 years, is set to expire on October 19, 2026. Despite over two years of advance notice, published guidance, and automatic updates pushed since 2024, the rollout of replacement 2023 certificates has hit significant obstacles. In July 2026, Microsoft paused updates for certain hardware combinations after failures were reported on devices from HP, Dell, ASUS, MSI, and ASRock, including BitLocker recovery loops and certificates failing to apply correctly. The core problem is that some devices require a firmware update from the manufacturer before the Secure Boot update can proceed, shifting responsibility to OEM release schedules. Machines that miss the update won't stop working but will lose the ability to receive future boot-level security patches, leaving them silently unprotected against new bootkit vulnerabilities.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in