2 Intern
•
196 Posts
•
56 Points
0
160
July 11th, 2026 19:13
How to handle the Secure Boot certificate expiration issue on OptiPlexes running Linux?
I run the latest Debian Stable on an OptiPlex 390 SFF. The Debian 13.6 release announcement advises:
The 2013 UEFI Secure Boot CA installed by default on most PCs and used to sign bootloaders has now expired. Future updates to shim-signed could therefore lead to systems being unable to boot with Secure Boot enabled.
Users are strongly advised to apply CA, KEK and DBX updates from their system OEM in line with the following guidance: https://wiki.debian.org/SecureBoot/CAChanges#What_should_I_do.3F
Does anyone have any guidance beyond the documentation above? Just looking before I leap so I my 390 doesn't wind up being unable to boot.
No Events found!


jdrch
2 Intern
•
196 Posts
•
56 Points
0
July 11th, 2026 19:44
Update: Solution. The TL,DR is the OptiPlex 390 doesn't support Secure Boot because it supports an early version of UEFI that doesn't fully implement Secure Boot. Thus even OSes that UEFI boot on it doesn't use Secure Boot in doing so. Which means there's nothing to do as a result of the Debian announcement.
Tesla1856
10 Wizard
•
18K Posts
•
71.5K Points
1
July 11th, 2026 21:06
@jdrch ,
Yeah, I've run-into that before (on other computers). There are a lot of old computers out there :)
I've always called it EFI (not full-blown UEFI).
(edited)