Secure Boot Cert Rotation

Triage and fix the Microsoft Secure Boot 2011→2023 UEFI certificate rotation across Dell PowerEdge / iDRAC9 bare metal, Ubuntu/Linux servers, and Harvester HCI / KubeVirt guest VMs. Two 2011 CAs expired June 2026 and Windows Production PCA 2011 expires 2026-10-19 — but UEFI firmware ignores certificate expiry, so nothing stopped booting; the real risks are forward-compat once a 2023-only-signed shim arrives (already true on aarch64) plus a dbx/revocation freeze. Routes to the per-platform fix: iDRAC BIOS-staged keys applied on reboot (Dell), fwupd-free manual `db` append self-authenticating via the existing 2011 KEK (Linux), and the Harvester virt-launcher OVMF floor (v1.6.0) with ephemeral-vs-persistent NVRAM triage (VMs). Covers the PK→KEK→db trust chain, the missing generic 2023 KEK payload, backup/rollback, and audit via mokutil / efi-readvar / racadm bioscert / Redfish.

air-gapped 0ec9056 9 files · 70.4 KB Updated

File contents

air-gapped/skills/tree/main/.claude/skills/secure-boot-cert-rotation commit 0ec9056ef8

Frequently asked questions

npx skillmds@latest add air-gapped/secure-boot-cert-rotation