Published
21 May 2026Form Number
LP2441PDF size
26 pages, 968 KBAbstract
This document provides guidance for Lenovo customers to transition Windows Server and Azure Local environments from Microsoft Secure Boot Certificate Authority (CA) 2011 to CA 2023 to maintain system security and boot integrity as CA 2011 certificates approach expiration in June 2026.
Procedures are outlined for validating the presence and activation of CA 2023 certificates within system firmware and operating system components, including minimum Lenovo UEFI firmware levels and required servicing updates.
Deployment-specific guidance spans existing environments, new installations, and Azure Local solutions, with additional coverage of recovery procedures for common failure conditions such as Secure Boot violations, recovery media incompatibility, and loss of custom Secure Boot keys.
Table of Contents
Introduction
Check Which Certificates Are Installed
Via PowerShell
Via UEFI Settings
Certificate expiration vs revocation
Update Windows Server to Secure Boot CA 2023
Before You Start
Scenario: Windows Server environment is already deployed
Scenario: Windows Server environment is not yet deployed
Scenario: Azure Local solution running Azure Stack HCI
Recovery Scenarios
Scenario: Firmware was updated but CA 2023 keys are not present in db
Scenario: System fails to boot after June 2026 with a Secure Boot violation
Scenario: BitLocker recovery key prompt appears after Secure Boot key update
Scenario: Recovery or deployment media fails to boot
Scenario: Custom Secure Boot keys lost after Restore Factory Keys
Scenario: Azure Local cluster node fails to rejoin cluster after CA 2023 update
References
Document history
Authors
Configure and Buy
Full Change History
Course Detail
Employees Only Content
The content in this document with a is only visible to employees who are logged in. Logon using your Lenovo ITcode and password via Lenovo single-signon (SSO).
The author of the document has determined that this content is classified as Lenovo Internal and should not be normally be made available to people who are not employees or contractors. This includes partners, customers, and competitors. The reasons may vary and you should reach out to the authors of the document for clarification, if needed. Be cautious about sharing this content with others as it may contain sensitive information.
Any visitor to the Lenovo Press web site who is not logged on will not be able to see this employee-only content. This content is excluded from search engine indexes and will not appear in any search results.
For all users, including logged-in employees, this employee-only content does not appear in the PDF version of this document.
This functionality is cookie based. The web site will normally remember your login state between browser sessions, however, if you clear cookies at the end of a session or work in an Incognito/Private browser window, then you will need to log in each time.
If you have any questions about this feature of the Lenovo Press web, please email David Watts at dwatts@lenovo.com.
