In November 2025 an update was released to XenServer 8.4, which would ensure newly provisioned Virtual Machines would have both the 2011 and 2023 certificates. As such any entirely new virtual machines created after this update has been applied will be unaffected by the expiry.
For virtual machines created prior to this update, Citrix has introduced a remediation workflow to allow for updating the certificates.
This workflow has been introduced to the XenServer 8.4 Early Access channel on June 11 2026, and to the Normal channel on June 24 2026.
The workflow allows customers to:
This workflow (referred to as an ‘out of band’ update) is required as for technical reasons it is not possible to perform an ‘in band’ update from within the Virtual Machine.
For details on how to use the workflow, please refer to the documentation.
XenCenter support for the workflow was included in XenCenter 2026.3.0, released June 25 2026.
Additionally, Citrix will be providing guidance on how to use these changes in typical CVAD environments.
Cause
Some UEFI virtual machines retain Microsoft’s 2011 Secure Boot certificates in their UEFI NVRAM. After certificate expiry, these VMs may fail to boot securely or trigger guest‑side recovery workflows.
XenServer builds released from November 2025 onwards include the newer 2023 Microsoft certificates. Newly provisioned VMs on those builds are not affected.
The issue applies only to VMs whose existing metadata still reflects the legacy 2011 certificate state.
Precautions
An ‘out of band’ certificate update may trigger recovery workflows inside a virtual machine. In particular, for VMs using Microsoft’s BitLocker technology, it may trigger the BitLocker recovery workflow and require the recovery key.
As such, Citrix strongly recommends that administrators:
Issue
Microsoft UEFI Secure Boot certificates issued in 2011 are scheduled to expire starting in June 2026. Replacement certificates were issued by Microsoft in 2023, and included into XenServer in 2025, however older Virtual Machines (VMs) may not have these certificates present.
See “Windows Secure Boot certificate expiration and CA updates” for more information from Microsoft.
There are two scenarios where problems may occur with XenServer virtual machines in relation to this certificate expiry:
It is important to clarify that, other than in scenario 2 above, the expiry will not automatically cause VMs to fail to boot, as the expiry date of the certificate is, by design, not checked during the normal boot process.
Microsoft have published a blog on this issue at - Act now: Secure Boot certificates expire in June 2026 - Windows IT Pro Blog