Elektrine lite

← Feed

@cyberwolfie@lemmy.ml

Does the SecureBoot key expiration matter if SecureBoot is disabled?

2026-06-21 10:12 UTC

I have completely forgotten about the SecureBoot key expiration that is coming on Wednesday. I don’t have SecureBoot enabled on any of my devices, but I wonder if it could cause issues down the line if I don’t ensure that the keys have been updated?

Replies (4)

  • @anamethatisnt@sopuli.xyz 2026-06-21 10:30

    Nah, but there should be a BIOS/UEFI firmware update available and those are always nice to keep up with. If Secure Boot is the security guard at the entrance then updating the BIOS/UEFI gives him the latest rulebook and will make the process simpler if you decide you want Secure Boot in the future. The update can also have other fixes that you want.

    Open ##3365470

  • @BlackEco@lemmy.blackeco.com 2026-06-21 11:25

    I you resell your computer down the line and the new owner enables Secure Boot, they won’t be able to install anything once the certificate expired and OSes are signed with the new one.

    Open ##3365667

  • @Duke_Nukem_1990@feddit.org 2026-06-21 22:17

    Huh? Haven’t heard about that. I am using Bazzite and IIRC they are supplying their own key for signing? Might be wrong tho.

    Open ##3368203

  • @IanTwenty@piefed.social 2026-06-21 22:35

    It could if you/future owner ever need to re-enable it: The trouble is not your present boot; it’s your future boot. If your older PC’s firmware never gets the 2023 keys, and the rest of the world starts assuming those keys exist, you can end up stuck in a weird limbo. While your existing Linux install will still boot, a new or updated distro won’t. Testing now will help diagnose future problems. https://www.zdnet.com/article/aspirin-for-linuxs-microsofts-secure-boot-headache/

    Open ##3368252