how do i get a new secure boot certificate

Dennis Wilkinson 0 Reputation points
2026-06-12T17:26:20.3466667+00:00

Hello

I need a new secure boot certificate for Windows 10

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
0 comments No comments

2 answers

Sort by: Most helpful
  1. Scott Nguyen 1,965 Reputation points Independent Advisor
    2026-06-12T19:42:14.4033333+00:00

    Hello, I want to make sure I understand right that you are looking to update the expiring 2011 Microsoft Secure Boot certificates to the new 2023 versions, or are you trying to generate a custom certificate for your own development use?

    Assuming you are dealing with the broad 2026 certificate expiration cycle affecting Windows 10 devices, the easiest path is to just let Windows Update handle it.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-06-12T17:26:41.4566667+00:00

    Secure Boot certificates for Windows 10 are not obtained manually like a typical PKI certificate; they are delivered and updated through Windows and firmware updates.

    For Windows 10 devices, there are two primary paths:

    1. Microsoft-managed devices (typical personal or small-business PCs)
      • Secure Boot certificates are updated automatically via Windows Update.
      • No separate request or manual certificate enrollment is required.
    2. Organization/IT-managed devices
      • IT administrators are responsible for deploying the updated Secure Boot certificates following Microsoft’s guidance in the Secure Boot update documentation.
      • The process typically involves:
        • Ensuring the device is on a supported Windows version listed in the Secure Boot guidance.
        • Applying the cumulative updates that include the new Secure Boot certificates.
        • Applying any required OEM firmware updates so the firmware can accept and store the new certificates.
      • The guidance is provided in the “Windows Secure Boot certificate expiration and CA updates” and “Secure Boot Certificate updates: Guidance for IT professionals and organizations” documentation referenced in the context.

    If the device is already running Windows and can install updates, the new Secure Boot certificates are written into firmware as part of those updates, even if older certificates are expired. For virtualized environments, either the virtualization platform provides updated virtual firmware with the new certificates, or Windows applies them if the virtual firmware supports Secure Boot updates.

    To remain protected:

    • Keep Windows 10 fully updated with the latest cumulative updates.
    • For IT-managed fleets, follow the Secure Boot certificate update guidance and coordinate with the OEM for any necessary firmware updates.

    There is no separate “download a certificate file” step; the supported method is to consume the Microsoft-provided updates that carry and install the new Secure Boot certificates.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.