2 Intern

 • 

196 Posts

 • 

56 Points

160

July 11th, 2026 19:13

How to handle the Secure Boot certificate expiration issue on OptiPlexes running Linux?

I run the latest Debian Stable on an OptiPlex 390 SFF. The Debian 13.6 release announcement advises:

The 2013 UEFI Secure Boot CA installed by default on most PCs and used to sign bootloaders has now expired. Future updates to shim-signed could therefore lead to systems being unable to boot with Secure Boot enabled.

Users are strongly advised to apply CA, KEK and DBX updates from their system OEM in line with the following guidance:  https://wiki.debian.org/SecureBoot/CAChanges#What_should_I_do.3F

Does anyone have any guidance beyond the documentation above? Just looking before I leap so I my 390 doesn't wind up being unable to boot. 

2 Intern

 • 

196 Posts

 • 

56 Points

July 11th, 2026 19:44

Update: Solution. The TL,DR is the OptiPlex 390 doesn't support Secure Boot because it supports an early version of UEFI that doesn't fully implement Secure Boot. Thus even OSes that UEFI boot on it doesn't use Secure Boot in doing so. Which means there's nothing to do as a result of the Debian announcement.

10 Wizard

 • 

18K Posts

 • 

71.5K Points

July 11th, 2026 21:06

@jdrch​ ,

 

Update: Solution. The TL,DR is the OptiPlex 390 doesn't support Secure Boot because it supports an early version of UEFI that doesn't fully implement Secure Boot. Thus even OSes that UEFI boot on it doesn't use Secure Boot in doing so. Which means there's nothing to do as a result of the Debian announcement.

Yeah, I've run-into that before (on other computers). There are a lot of old computers out there :)

I've always called it EFI (not full-blown UEFI).

(edited)

No Events found!

Top