A quiet trust-anchor rollover in Secure Boot is turning June 2026 into a hard deadline for device fleets that have not yet moved off 2011-era certificates.
A key expiration on Microsoft’s Secure Boot update chain may not stop old machines from starting, but it could strand them without future DB and DBX protections.
Microsoft’s KEK CA 2011 is set to expire on June 27, 2026, and the real question is whether that deadline could interfere with DBX updates.