{"id":1030,"date":"2026-08-10T15:00:00","date_gmt":"2026-08-10T13:00:00","guid":{"rendered":"https:\/\/www.pvs-forge.com\/?p=1030"},"modified":"2026-08-08T16:33:57","modified_gmt":"2026-08-08T14:33:57","slug":"secure-boot-2026-why-it-hits-provisioning-environments-harder","status":"publish","type":"post","link":"https:\/\/www.pvs-forge.com\/en\/secure-boot-2026-warum-es-provisioning-umgebungen-haerter-trifft\/","title":{"rendered":"Secure Boot 2026: Why It Hits Provisioning Environments Harder"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Anyone who uses Citrix Provisioning is familiar with the division of labor: The tool creates the vDisk\u2014but the <strong>It is the customer's responsibility to ensure that the surrounding area is clean<\/strong>. And that's exactly where some pitfalls are lurking that not every administrator is aware of. The latest one is called Secure Boot, and it has an expiration date.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The 2011 Secure Boot certificates are expiring<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft will replace the entire Secure Boot certificate chain in 2026. Two of the three certificates issued in 2011 have already expired: the KEK CA on June 24 and the UEFI CA on June 27, 2026. The third, the Windows Production PCA 2011, will follow on October 19, 2026. It will be replaced by the 2023 generation, which must be installed in the UEFI firmware of each individual machine via Windows Update.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For traditional PCs, this is a rollout just like any other. For provisioning environments, however, it\u2019s a trap waiting to happen\u2014so much so that Citrix has published two separate known-issue articles on the topic (CTX696455 for VMware and XenServer, CTX696473 for Hyper-V). The crux of both: PVS targets with Secure Boot will no longer boot after Windows updates have been applied to the vDisk.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why Provisioning Is Particularly Affected<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The mechanism behind this is easy to explain\u2014and typical of PVS. The Windows Update places a boot manager signed with the 2023-CA certificate into the master image, and thus into the vDisk. This vDisk is streamed to dozens or hundreds of target VMs. Each of these VMs verifies the boot manager against the <strong>Certificates in its own UEFI firmware\u2014which is based on a template from ages ago. If it doesn't recognize the 2023 CA, it won't boot. The farm is down.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A single PC can repair itself via Windows Update. A provisioned farm cannot\u2014because the image is frozen, and the firmware for each VM is managed by the hypervisor. It is precisely this discrepancy between \u201eone image\u201c and \u201ea hundred firmware states\u201c that makes this issue so dangerous for PVS environments.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">To be honest: This isn't a PVS Forge issue<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">And here we are back to the division of labor. An imaging tool creates a clean vDisk from the master target\u2014this works flawlessly even with Secure Boot. The firmware of the target VMs, the hypervisor version, the VM templates: <strong>All of that is up to the customer and their hypervisor vendor.<\/strong> No imaging tool in the world can influence that.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But: Who, if not the tool that runs on the master before every imaging process anyway, should warn the administrator in a timely manner?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Check, warn, fix<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">That is exactly PVS Forge's approach\u2014every time imaging is started, for every master target, without any configuration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>To check means<\/strong>: Does the master even run with Secure Boot enabled? Are the 2023 certificates already in its firmware database and in the KEK? Systems without UEFI or Secure Boot are silently skipped\u2014no false alarms.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>To warn means<\/strong>: If the certificates are missing, a clear message appears with an explanation, the Citrix part numbers, and a template for manual resolution.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>And to differentiate means<\/strong>: Distinguish what the real issue is. If the 2023-CA is missing from the database, a boot failure is likely\u2014serious warning. If only the KEK is missing, future certificate updates will be blocked\u2014note. And if the firmware simply refuses the update, PVS Forge makes it clear: This is a hypervisor issue; the only solution is a hypervisor update, not guest software.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Single Checkbox Fix<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you prefer a more convenient approach, just enable a single option: \u201e<strong>Fix Secure Boot Certificates (2023 Rollout)<\/strong>\u201e. Then, before imaging, PVS Forge sets the official Microsoft opt-in on the master, triggers Windows\u2019 own update task, and restarts the master target. Windows then applies the certificates wherever the platform allows it\u2014and because the trigger is included in the vDisk, the streamed devices can also adopt the certificates into their own firmware during boot, provided the hypervisor supports this.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Important to note: The fix uses only the documented Microsoft mechanism, is repeatable, and only takes effect if something is actually missing. Even if the hypervisor firmware doesn't cooperate, it's harmless\u2014nothing bad will happen, and the message will specify the cause.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Boundaries \u2014 and Why We Should Name Them<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">PVS Forge can do a lot, but not everything, and it\u2019s more honest to say so. The hypervisor must support the 2023 chain (such as VMware vSphere 8.0 U3h or newer, XenServer 8.4, or the latest Hyper-V on Windows Server 2019 or newer). Older versions refuse to update the firmware\u2014no guest software can bypass this. Updating the VM firmware on existing targets is a hypervisor task. And Citrix Provisioning itself also requires a current version to support the new chain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A good tool provides timely warnings, fixes whatever can be fixed within the guest, and points to the right spot when the problem lies elsewhere. An imaging tool cannot\u2014and should not\u2014promise more than that.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">By the way: the same principle applies to DNS and DHCP<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Secure Boot is just the most recent example of this philosophy. Every PVS administrator is familiar with a second example, often without knowing the cause: Streamed devices carry the DNS and DHCP identity of the master target in their image\u2014and may delete the master\u2019s DNS entry or request its old DHCP lease during boot. The proper way to handle this is to clean up this registration state immediately before sealing: DNS cleanup is safe by default because Windows rebuilds the state anyway; DHCP cleanup is a deliberate option to prevent address conflicts after the rollout.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The 2026 Secure Boot transition is not just a theory<\/strong>. Two certificates have expired, the third will expire in October, and Citrix has the <strong>Boat breakdowns have already been documented<\/strong>. Provisioned environments are at a structural disadvantage because an image encounters many different firmware states.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">PVS Forge does exactly what it\u2019s supposed to do: It checks at every opportunity, provides clear warnings, resolves issues that can be fixed with a checkbox\u2014and is honest about the rest. The Secure Boot check isn\u2019t a special case here, but just one of many examples. It\u2019s all the little built-in features\u2014from cleaning up DNS\/DHCP to certificate warnings\u2014that make the administrator\u2019s life easier right out of the box.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p class=\"wp-block-paragraph\"><em>PVS Forge checks the Secure Boot certificate chain during every imaging process out-of-the-box, issues a warning via a pop-up message, and resolves the Microsoft opt-in via a checkbox where the platform allows it\u2014and clearly indicates when the issue lies with the hypervisor. Practical expertise, built right into the product.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>","protected":false},"excerpt":{"rendered":"<p>Wer Citrix Provisioning betreibt, kennt die Arbeitsteilung: Das Werkzeug erstellt die vDisk \u2014 aber die saubere Bereitstellung der Umgebung drumherum liegt beim Kunden. Und genau dort lauern gerade Fallen, die nicht jeder Administrator auf dem Zettel hat. Die aktuellste hei\u00dft Secure Boot, und sie hat ein Ablaufdatum. Die Secure-Boot-Zertifikate von 2011 laufen ab Microsoft tauscht [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":1031,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[10],"tags":[18,16,13,19,21,20,17,14,15,22],"class_list":["post-1030","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-posts","tag-bios","tag-boot","tag-citrix","tag-firmware","tag-image","tag-microsoft","tag-provisioning-certificates","tag-pvs","tag-secure","tag-vdisk"],"uagb_featured_image_src":{"full":["https:\/\/www.pvs-forge.com\/wp-content\/uploads\/2026\/08\/hero-08-secure-boot.png",1080,720,false],"thumbnail":["https:\/\/www.pvs-forge.com\/wp-content\/uploads\/2026\/08\/hero-08-secure-boot-150x150.png",150,150,true],"medium":["https:\/\/www.pvs-forge.com\/wp-content\/uploads\/2026\/08\/hero-08-secure-boot-300x200.png",300,200,true],"medium_large":["https:\/\/www.pvs-forge.com\/wp-content\/uploads\/2026\/08\/hero-08-secure-boot-768x512.png",768,512,true],"large":["https:\/\/www.pvs-forge.com\/wp-content\/uploads\/2026\/08\/hero-08-secure-boot-1024x683.png",1024,683,true],"1536x1536":["https:\/\/www.pvs-forge.com\/wp-content\/uploads\/2026\/08\/hero-08-secure-boot.png",1080,720,false],"2048x2048":["https:\/\/www.pvs-forge.com\/wp-content\/uploads\/2026\/08\/hero-08-secure-boot.png",1080,720,false],"trp-custom-language-flag":["https:\/\/www.pvs-forge.com\/wp-content\/uploads\/2026\/08\/hero-08-secure-boot-18x12.png",18,12,true]},"uagb_author_info":{"display_name":"Thomas K\u00f6tzing","author_link":"https:\/\/www.pvs-forge.com\/en\/author\/wp-admin\/"},"uagb_comment_info":0,"uagb_excerpt":"Wer Citrix Provisioning betreibt, kennt die Arbeitsteilung: Das Werkzeug erstellt die vDisk \u2014 aber die saubere Bereitstellung der Umgebung drumherum liegt beim Kunden. Und genau dort lauern gerade Fallen, die nicht jeder Administrator auf dem Zettel hat. Die aktuellste hei\u00dft Secure Boot, und sie hat ein Ablaufdatum. Die Secure-Boot-Zertifikate von 2011 laufen ab Microsoft tauscht&hellip;","_links":{"self":[{"href":"https:\/\/www.pvs-forge.com\/en\/wp-json\/wp\/v2\/posts\/1030","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.pvs-forge.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.pvs-forge.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.pvs-forge.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pvs-forge.com\/en\/wp-json\/wp\/v2\/comments?post=1030"}],"version-history":[{"count":2,"href":"https:\/\/www.pvs-forge.com\/en\/wp-json\/wp\/v2\/posts\/1030\/revisions"}],"predecessor-version":[{"id":1034,"href":"https:\/\/www.pvs-forge.com\/en\/wp-json\/wp\/v2\/posts\/1030\/revisions\/1034"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.pvs-forge.com\/en\/wp-json\/wp\/v2\/media\/1031"}],"wp:attachment":[{"href":"https:\/\/www.pvs-forge.com\/en\/wp-json\/wp\/v2\/media?parent=1030"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.pvs-forge.com\/en\/wp-json\/wp\/v2\/categories?post=1030"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.pvs-forge.com\/en\/wp-json\/wp\/v2\/tags?post=1030"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}