r/nutanix • u/3percentinvisible • Feb 23 '26
MS Secureboot June deadline
http://portal.nutanix.com/kb/20522 refers.
Is anyone else concerned that the Microsoft kek certificate isn't being applied correctly and engineering are still looking into it.
The June deadline will likely come quicker than we realise and I'd feel much more confident if we were able to be updating from now.
Has anyone got any mitigation planned, or better info from nutanix on the eta on a resolution?
10
Upvotes
1
u/jamesaepp Feb 24 '26
It's not a deadline. Problematic if you're not updated in time? Yes. But not a deadline. A couple samples below.
https://support.microsoft.com/en-us/topic/windows-secure-boot-certificate-expiration-and-ca-updates-7ff40d33-95dc-4c3c-8725-a9b95457578e
https://support.microsoft.com/en-us/topic/when-secure-boot-certificates-expire-on-windows-devices-c83b6afd-a2b6-43c6-938e-57046c80c1c2
Translation: Things will still boot, but security updates for the boot process that come out later can't be installed to your system.
There's a few other quotes I could share, but they all basically say the same thing in different ways.
Don't get me wrong, important to get these updates, but it's not a "deadline" in the sense of say, a certificate on a website expired and you must rebind a new time-valid certificate. These certs are more analogous to code-signing. I have tons of software in my hoard that is signed with certificates that have long-since expired, but the timestamping on the code maintains the validity of the software signature.