Secure Boot Certificate Expirations in VMware Virtual Machines


VMware ESXi 8.0 Update 3j (P09) is worth applying, especially if you run Secure Boot-enabled VMs. This patch, released on 27 May 2026 as ISO Build 25429389, includes a key fix that enables automated remediation of the Platform Key (PK) during Virtual Machine reboot for vTPM-disabled VMs.

That’s important because Microsoft’s 2011 Secure Boot certificates expire in June 2026, and older VMs can see Secure Boot-related certificate updates fail. With ESXi 8.0 U3j, vTPM-disabled VMs can now have their PK updated automatically during reboot, which simplifies remediation.

For vTPM-enabled Virtual Machines (both Windows and Linux), there are no automated remediation methods available at this time. Broadcom Engineering is working with Microsoft on an automated solution for vTPM-enabled Windows VMs in a future release, aligned with Microsoft’s Secure Boot certificate guidance (MS KB 5062713). Until that’s available, Broadcom’s recommendation for Windows VMs with vTPM enabled is to wait for the automated solution instead of performing manual PK updates.

In practice, this means:

  • vTPM-disabled VMs: ESXi 8.0 U3j gives you automated PK remediation during VM reboot.
  • vTPM-enabled VMs: Manual PK updates are not yet recommended for Windows; wait for the upcoming automated solution.
  • ESX hosts: There is no immediate impact on Secure Boot-enabled ESX hosts from the certificate expiration itself.

If you manage vSphere environments, I recommend adding ESXi 8.0 Update 3j to your next maintenance window, especially if you have older Secure Boot-enabled VMs without vTPM. It’s a practical step toward keeping your VMs bootable and updatable as the Secure Boot certificate transition progresses.

Useful links:

Secure Boot Certificate Expirations and Update Failures in VMware Virtual Machines

VMware ESXi 8.0 Update 3j Release Notes

Leave a Reply