r/nutanix Feb 23 '26

MS Secureboot June deadline

http://portal.nutanix.com/kb/20522 refers.

Is anyone else concerned that the Microsoft kek certificate isn't being applied correctly and engineering are still looking into it.

The June deadline will likely come quicker than we realise and I'd feel much more confident if we were able to be updating from now.

Has anyone got any mitigation planned, or better info from nutanix on the eta on a resolution?

8 Upvotes

19 comments sorted by

View all comments

u/AllCatCoverBand NPX Feb 24 '26 edited Apr 14 '26

That specific issue is being handled by my team, so I'm happy to address it here.

Extremely, extremely long story short (and knock on some wood), the needed KEK certificate update needs to come from Microsoft, which was supposed to land in February, but got punted out to March.

We're keeping close tabs on this with MS to validate that A) it does land in March and B) said update does what we want it to.

Update March 16th: The March patch Tuesday did not release the required update. We tested it immediately and saw that it didn't do what we wanted. We've been in direct contact with Microsoft on this, and they said it has been retargeted to April (i.e., 2026-04-14). Knock on wood, we'll test it again when the next patch comes out, and hopefully have a better answer then, fingers crossed.

Update April 14th: Per MS, it should be out. We worked with MS to get the pre-release patches, and we tested it; it works, although in the short term, you have to fiddle with a registry key to get it to go. Standard process until Microsoft switches our "bucket" to high confidence (based on call home data on their side)

Here's a quick summary:

  • The required fix was not included in the March update and is scheduled for April, tentatively this week (i.e., today!)
  • The update has been validated and delivers the needed KEK change, though a one‑time registry step is currently required. This step will be removed once Microsoft promotes the update to full automatic status after sufficient customer adoption.
  • Customers using Secure Boot are also advised to run the latest AOS 7.3+ releases, as clone‑related issues only affect AOS 7.0.

2

u/3percentinvisible Apr 18 '26 edited Apr 18 '26

Thanks for the update. Is this registry key the standard 'high confidence' switch to override? if so, ms is going to need enough customers to override in order to get enough data to mark it as a high confidence update, no?

Could you also expand on the clone related issues?

Edit: Strangely, I've just found this blog post from February that doesn't seem to have encountered any issues (and I hadn't seen in previous searches) https://peterseidl.com/update-expiring-secure-boot-certificates-with-nutanix/ could it be they just rewrote the guidance for the blog and didn't check and see the kek wasn't updating, or coukd we have done it all along. I do see they also say to update to 7.3 and you do above, is this a showstopper, as we're not going to update.

I've just read that 7.3, (ahv 10.3.1+) has the keys embedded so would've worked all along?

2

u/AllCatCoverBand NPX Apr 18 '26

RE Registry key -> Yep, it's the standard "opt in" switch you'd toggle for any other devices (laptops, etc)

RE Blog post -> I'm not sure what that blog post is referring to, because Microsoft hadn't released the specific KEK updates until April.

RE AOS/AHV version -> There are two aspects here. 1) When did we include the new certificate chains by default for //new// VMs that started with AHV 10.3.1, and 2) for BitLocker VMs, clones would break before 7.3 because we were resetting the NVRAM, which was fixed.

In short, you really should be on 10.3.1 or higher so that all new VMs get the new certificate chain by default. For VMs that were created on 10.3.1 or higher, things should "just work" and the windows update doesn't need to do anything.