I've read quite a bit about the UEFI cert expiration, and I still don't know exactly what my way forward is.
Only one of my clusters is running PVE 9.x. Until earlier today, that was 9.1.6.
Now its running 9.2 and giving me some very helpful advice.
WARN: EFI disk without 'ms-cert=2023k' option, suggesting that not all UEFI 2023 certificates from Microsoft are enrolled yet.
The UEFI 2011 certificates expire in June 2026! The new certificates are required for secure boot update for Windows and common Linux distributions.
Use 'Disk Action > Enroll Updated Certificates' in the UI or, while the VM is
shut down, run 'qm enroll-efi-keys 1009' to enroll the new certificates.
The Disk Action mentioned there was not present before 9.2.

The long and confusing threads I've reviewed had a LOT of info, much of it contradictory or debated.
I read there's stuff you have to do inside of windows, possibly in conjunction with multiple reboots.
The MS article didn't help much.
I take it the first thing I need to do is update all of my clusters to 9.2.
I'm sorry if this sounds dumb with all of the info out there, but I don't see a clear set of directions.
After I "Use 'Disk Action > Enroll Updated Certificates' in the UI", what happens next?
Do I need to do stuff inside windows too? Is there a KB or help doc somewhere?
And then ... I know support on 8.4 expires in August.
I did not expect a dealbreaker like this, and I've put it off. (Gimme a break, my boss hates patching.)
Ok, I need to upgrade all my hosts. Now.
But, its unlikely I'll be able to do that in time.
I'm still going to be running 8.x hosts when "UEFI 2011 certificates expire in June 2026!"
What can I expect to happen to guests of these remaining unpatched 8.x systems?
Will they still boot? (I think that answer is yes. They just won't do "secure boot update", whatever that means.)
If I cannot manage to clear and patch these remaining 8.x hosts, is there an alternate path?
Some workaround?
Ya, I screwed myself here, but now I'm screwed, and I need some answers.
Thanks.
- t
Only one of my clusters is running PVE 9.x. Until earlier today, that was 9.1.6.
Now its running 9.2 and giving me some very helpful advice.
WARN: EFI disk without 'ms-cert=2023k' option, suggesting that not all UEFI 2023 certificates from Microsoft are enrolled yet.
The UEFI 2011 certificates expire in June 2026! The new certificates are required for secure boot update for Windows and common Linux distributions.
Use 'Disk Action > Enroll Updated Certificates' in the UI or, while the VM is
shut down, run 'qm enroll-efi-keys 1009' to enroll the new certificates.
The Disk Action mentioned there was not present before 9.2.

The long and confusing threads I've reviewed had a LOT of info, much of it contradictory or debated.
I read there's stuff you have to do inside of windows, possibly in conjunction with multiple reboots.
The MS article didn't help much.
I take it the first thing I need to do is update all of my clusters to 9.2.
I'm sorry if this sounds dumb with all of the info out there, but I don't see a clear set of directions.
After I "Use 'Disk Action > Enroll Updated Certificates' in the UI", what happens next?
Do I need to do stuff inside windows too? Is there a KB or help doc somewhere?
And then ... I know support on 8.4 expires in August.
I did not expect a dealbreaker like this, and I've put it off. (Gimme a break, my boss hates patching.)
Ok, I need to upgrade all my hosts. Now.
But, its unlikely I'll be able to do that in time.
I'm still going to be running 8.x hosts when "UEFI 2011 certificates expire in June 2026!"
What can I expect to happen to guests of these remaining unpatched 8.x systems?
Will they still boot? (I think that answer is yes. They just won't do "secure boot update", whatever that means.)
If I cannot manage to clear and patch these remaining 8.x hosts, is there an alternate path?
Some workaround?
Ya, I screwed myself here, but now I'm screwed, and I need some answers.
Thanks.
- t
Last edited: