You may have seen news that the Microsoft UEFI Secure Boot certificates from 2011 have expired. The short version for AlmaLinux users: everything is covered, and your systems will not stop booting. There is nothing you have to do right now, but a quick check will make sure you are ready for future shim updates. Here is what happened and what we recommend.
What happened?
The Microsoft certificates that have anchored UEFI Secure Boot since 2011 have reached the end of their lifecycle. The Microsoft Corporation KEK CA 2011 expired on June 24, 2026, and the Microsoft Corporation UEFI CA 2011 — the certificate used to sign Linux shim bootloaders — expired on June 27, 2026.
SOCIAL SHARE CARD GENERATOR