According to a recent update thread on the Secure Boot Objects GitHub, MS deliberately rotates through a series of one-year "leaf" certs to sign the boot manager. And this particular one will be the last in that series, since they can't generate another past the Oct 2026 deadline.I noticed Microsoft has updated the expire date to 10/17/2026
@hughsie that looks to be intended. Our leaf certificates recently rotated for this CA - they both chain to the Microsoft Corporation KEK CA 2011.
20250902 - signed by certificate thumbprint 2c181a475fb7e3d83a742d69b543d14ba0ac38ae
20260402 - signed by certificate thumbprint b514f92b4ba43b894f8c1aca9fe6a3ed4007bba8 (valid 3/12/2026 - 6/23/2026) <-- this will be the last leaf certificate for the KEK CA 2011
After that, presumably they'll switch a new round of one-year certs after October.
My Computer
System One
-
- OS
- Windows 7





