{"id":182058,"date":"2026-06-14T14:48:26","date_gmt":"2026-06-14T12:48:27","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/istekaet-vremya-zhizni-sertifikata-kotorym-zaveren-zagruzchik-dlya-uefi-secure-boot-v-distributivah-linux"},"modified":"2026-06-14T14:48:26","modified_gmt":"2026-06-14T12:48:27","slug":"istekaet-vremya-zhizni-sertifikata-kotorym-zaveren-zagruzchik-dlya-uefi-secure-boot-v-distributivah-linux","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/istekaet-vremya-zhizni-sertifikata-kotorym-zaveren-zagruzchik-dlya-uefi-secure-boot-v-distributivah-linux","title":{"rendered":"The lifespan of the certificate that certifies the bootloader for UEFI Secure Boot in Linux distributions is expiring.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Fedora Linux developers clarified the situation regarding the expiration of the Microsoft certificate used for signing the Shim layer, which is used for verified boot of Linux distributions in UEFI Secure Boot mode, set to expire at the end of June. The transition to the new certificate is expected to be seamless for users, as the actual expiration will only prevent its use for generating new signatures. During the UEFI Secure Boot process, the validity of the certificate is not checked and is only relevant in terms of revocation of compromised certificates. <\/p>\n<p>Existing systems without the shim update will continue to boot until the public key of the certificate is removed from the firmware or placed on the UEFI revoked certificates list (DBX). Only the boot shim layer is certified by Microsoft, which includes the public key of the distribution used to certify boot components such as the GRUB2 bootloader, Linux kernel, kernel modules, and boot processes like fwupd. This approach allows Microsoft to certify only changes to the shim layer while independently ensuring the verification of the distribution's boot process.<\/p>\n<p>The Microsoft certificate for signing third-party firmware for UEFI Secure Boot has been in effect since 2011. In 2023, a new certificate was generated to replace it, which will be used for signing starting October 2025. The updated shim, signed with multiple keys for maximum hardware compatibility, has already been added to the Fedora Rawhide repository, which forms the basis of the Fedora 45 release (it can be used on both old firmware without the public key of the new certificate and on firmware without the public key of the old certificate).<\/p>\n<p>Although the expiration of a Microsoft certificate should not affect the functionality of the boot process, Fedora developers recommend that users update the database with keys for Secure Boot when new firmware versions for their hardware are released. To determine if the system is booting in UEFI Secure Boot mode, you can use the command 'mokutil --sb-state', and to display the list of open keys available in the firmware, use 'mokutil --db --short'. To view the keys used to sign the shim layer, you can run the command 'sudo pesign -S -i \/boot\/efi\/EFI\/fedora\/shimx64.efi', after installing the pesign package. To check for firmware updates and install them, use the command 'sudo fwupdmgr update'. <\/p>\n<p>The next version of the shim layer will be signed only with the new Microsoft certificate, and a firmware update is necessary to prepare your systems for this change. The shim update will be released if vulnerabilities or serious bugs are identified, which could happen in a month or a year. During the existence of shim in the project, critical vulnerabilities have been found, and the last report on security issues in shim was released just a few days ago. <\/p>\n<p>The report noted two recently discovered vulnerabilities CVE-2026-8863 and<br \/>\nCVE-2026-10797, which allow achieving code execution at an early stage of the boot process before control is transferred to the operating system, bypassing UEFI Secure Boot protection, and enabling the loading of unsigned kernel components. These problems affect shim versions up to and including release 0.9, created before 2016. Very old systems such as<br \/>\n RedHat Enterprise Linux 7.2, CentOS 7.2, Oracle Linux 7.2, ROSA Linux R10\/R9, and openSUSE with shim 0.9 are vulnerable to attack. Shim layers up to and including version 0.9 have been added to the revoked signature database DBX (UEFI Forbidden Signature Database), and if the DBX is updated, they will be unable to boot in UEFI Secure Boot mode.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65683\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 Fedora Linux \u043f\u0440\u043e\u044f\u0441\u043d\u0438\u043b\u0438 \u0441\u0438\u0442\u0443\u0430\u0446\u0438\u044e, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u0443\u044e \u0441 \u0438\u0441\u0442\u0435\u0447\u0435\u043d\u0438\u0435\u043c \u0432 \u043a\u043e\u043d\u0446\u0435 \u0438\u044e\u043d\u044f \u0441\u0440\u043e\u043a\u0430 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430 Microsoft, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u0433\u043e \u0434\u043b\u044f \u0437\u0430\u0432\u0435\u0440\u0435\u043d\u0438\u044f \u0446\u0438\u0444\u0440\u043e\u0432\u043e\u0439 \u043f\u043e\u0434\u043f\u0438\u0441\u044c\u044e \u043f\u0440\u043e\u0441\u043b\u043e\u0439\u043a\u0438 Shim, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u0432\u0435\u0440\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u043e\u0432 Linux \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 UEFI Secure Boot. \u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043d\u0430 \u043d\u043e\u0432\u044b\u0439 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u0434\u043e\u043b\u0436\u0435\u043d \u043f\u0440\u043e\u0439\u0442\u0438 \u043d\u0435\u0437\u0430\u043c\u0435\u0442\u043d\u043e \u0434\u043b\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0442\u0430\u043a \u043a\u0430\u043a \u0444\u0430\u043a\u0442\u0438\u0447\u0435\u0441\u043a\u0438 \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u0435 \u0432\u0440\u0435\u043c\u0435\u043d\u0438 \u0436\u0438\u0437\u043d\u0438 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430 \u043f\u0440\u0438\u0432\u0435\u0434\u0451\u0442 \u043b\u0438\u0448\u044c \u043a \u043d\u0435\u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0438 \u0435\u0433\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-182058","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 Fedora Linux \u043f\u0440\u043e\u044f\u0441\u043d\u0438\u043b\u0438 \u0441\u0438\u0442\u0443\u0430\u0446\u0438\u044e, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u0443\u044e \u0441 \u0438\u0441\u0442\u0435\u0447\u0435\u043d\u0438\u0435\u043c \u0432 \u043a\u043e\u043d\u0446\u0435 \u0438\u044e\u043d\u044f \u0441\u0440\u043e\u043a\u0430 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430 Microsoft, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u0433\u043e \u0434\u043b\u044f \u0437\u0430\u0432\u0435\u0440\u0435\u043d\u0438\u044f \u0446\u0438\u0444\u0440\u043e\u0432\u043e\u0439 \u043f\u043e\u0434\u043f\u0438\u0441\u044c\u044e \u043f\u0440\u043e\u0441\u043b\u043e\u0439\u043a\u0438 Shim, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u0432\u0435\u0440\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/istekaet-vremya-zhizni-sertifikata-kotorym-zaveren-zagruzchik-dlya-uefi-secure-boot-v-distributivah-linux\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0418\u0441\u0442\u0435\u043a\u0430\u0435\u0442 \u0432\u0440\u0435\u043c\u044f \u0436\u0438\u0437\u043d\u0438 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u043c \u0437\u0430\u0432\u0435\u0440\u0435\u043d \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a \u0434\u043b\u044f UEFI Secure Boot \u0432 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 Linux | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 Fedora Linux \u043f\u0440\u043e\u044f\u0441\u043d\u0438\u043b\u0438 \u0441\u0438\u0442\u0443\u0430\u0446\u0438\u044e, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u0443\u044e \u0441 \u0438\u0441\u0442\u0435\u0447\u0435\u043d\u0438\u0435\u043c \u0432 \u043a\u043e\u043d\u0446\u0435 \u0438\u044e\u043d\u044f \u0441\u0440\u043e\u043a\u0430 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430 Microsoft, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u0433\u043e \u0434\u043b\u044f \u0437\u0430\u0432\u0435\u0440\u0435\u043d\u0438\u044f \u0446\u0438\u0444\u0440\u043e\u0432\u043e\u0439 \u043f\u043e\u0434\u043f\u0438\u0441\u044c\u044e \u043f\u0440\u043e\u0441\u043b\u043e\u0439\u043a\u0438 Shim, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u0432\u0435\u0440\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/istekaet-vremya-zhizni-sertifikata-kotorym-zaveren-zagruzchik-dlya-uefi-secure-boot-v-distributivah-linux\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-06-14T12:48:27+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-06-14T12:48:27+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47The certificate used to sign the bootloader for UEFI Secure Boot in Linux distributions has expired | ProHoster","description":"Fedora Linux developers clarified the situation regarding the expiration at the end of June of the Microsoft certificate used to sign the shim layer for verification.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/istekaet-vremya-zhizni-sertifikata-kotorym-zaveren-zagruzchik-dlya-uefi-secure-boot-v-distributivah-linux","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0418\u0441\u0442\u0435\u043a\u0430\u0435\u0442 \u0432\u0440\u0435\u043c\u044f \u0436\u0438\u0437\u043d\u0438 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u043c \u0437\u0430\u0432\u0435\u0440\u0435\u043d \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a \u0434\u043b\u044f UEFI Secure Boot \u0432 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 Linux | ProHoster","og:description":"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 Fedora Linux \u043f\u0440\u043e\u044f\u0441\u043d\u0438\u043b\u0438 \u0441\u0438\u0442\u0443\u0430\u0446\u0438\u044e, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u0443\u044e \u0441 \u0438\u0441\u0442\u0435\u0447\u0435\u043d\u0438\u0435\u043c \u0432 \u043a\u043e\u043d\u0446\u0435 \u0438\u044e\u043d\u044f \u0441\u0440\u043e\u043a\u0430 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430 Microsoft, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u0433\u043e \u0434\u043b\u044f \u0437\u0430\u0432\u0435\u0440\u0435\u043d\u0438\u044f \u0446\u0438\u0444\u0440\u043e\u0432\u043e\u0439 \u043f\u043e\u0434\u043f\u0438\u0441\u044c\u044e \u043f\u0440\u043e\u0441\u043b\u043e\u0439\u043a\u0438 Shim, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u0432\u0435\u0440\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/istekaet-vremya-zhizni-sertifikata-kotorym-zaveren-zagruzchik-dlya-uefi-secure-boot-v-distributivah-linux","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-06-14T12:48:27+00:00","article:modified_time":"2026-06-14T12:48:27+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"182058","title":null,"description":null,"keywords":null,"keyphrases":{"focus":[],"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-08-05 12:22:23","updated":"2026-08-05 12:22:23","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/182058","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=182058"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/182058\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=182058"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=182058"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=182058"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}