Skip to main content
Question

Microsoft certificates for Secure Boot expire in June 2026

  • December 24, 2025
  • 3 replies
  • 394 views

HI!
Microsoft certificates for Secure Boot expire in June 2026

Will AHV, CVM, and VM legacy boot continue to function properly after the certificate expires?
Secure Boot expiration will only affect guest VMs using UEFI?


 

3 replies

Forum|alt.badge.img
  • Voyager
  • January 7, 2026

HI!
Microsoft certificates for Secure Boot expire in June 2026

Will AHV, CVM, and VM legacy boot continue to function properly after the certificate expires?
Secure Boot expiration will only affect guest VMs using UEFI?


 

Already updated in AHV 10.3.1. You can find more info at:

http://portal.nutanix.com/kb/20522


HI!
Microsoft certificates for Secure Boot expire in June 2026

Will AHV, CVM, and VM legacy boot continue to function properly after the certificate expires?
Secure Boot expiration will only affect guest VMs using UEFI?


 

Already updated in AHV 10.3.1. You can find more info at:

http://portal.nutanix.com/kb/20522

There is no answer to my question in the KB. It only specifies what needs to be done for VMs with Uefi deployed on AHV.


The question is how this will affect AHV and CVM? Do they need to be updated separately?
If I remember correctly, AHV and CVM don't use UEFI. Therefore, there's no need to do anything with them or the host.

 


Forum|alt.badge.img+6
  • Adventurer
  • February 10, 2026

Stop using legacy BIOS.  

 

 

What worries me is this statement in the KB--->

 

Note: As of today, you cannot apply the Microsoft KEK 2K CA to AHV VMs with UEFI running Windows guests utilizing Windows Update.  Nutanix Engineering is working on a solution for this matter.