Tendvane

← All articles

Windows updatesJuly 22, 2026

Windows is quietly swapping its Secure Boot certificates - and older PCs are hitting snags

Buried in this summer's Windows updates is a change most people will never notice - and a small number will notice the hard way. The security certificates that make Secure Boot work were issued back in 2011, and they've started to expire. Microsoft's KEK certificate lapsed on June 24, 2026, with others following through October. Windows is swapping in fresh 2023 certificates that are valid until 2038.

For most home PCs this is a non-event. If Windows Update is switched on and Secure Boot is enabled - the default on any reasonably modern machine - the new certificates install quietly in the background and you carry on. Do nothing, and it just works.

Older hardware is where it gets messy. At a meeting with PC makers on July 15, Microsoft admitted that it and the manufacturers can't fix every case. Some machines from 2018 and earlier don't have enough firmware storage for the new certificates; on certain models the update sets off a BitLocker recovery prompt at reboot, asking for a 48-digit key many people have never laid eyes on. A PC that never gets the new certificates keeps starting and running fine, but it stops receiving protection for the earliest, most sensitive part of startup.

The one thing worth doing now is making sure you can find your BitLocker recovery key before an update ever asks for it - it's stored in your Microsoft account at account.microsoft.com/devices. Tendvane's security-posture check flags whether BitLocker is on and nudges you to back that key up, and its check-for-updates confirms Windows is current so the certificate swap actually reaches your PC.

Sources

Download Tendvane