Skip to content
Discussion options

You must be logged in to vote

The certificates signing the Microsoft binaries are different from the ones used for shim and wimboot, and if I remember correctly, Hyper-V will only ever allow one of them at a time, not both? (Have they released the 2023 update yet?)

I believe this is correct. https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/generation-2-virtual-machine-security-features#secure-boot documents the selection, and the fact that it's a single drop-down in the UI suggests that Hyper-V is not capable of being configured to simultaneously trust both the Windows root and the UEFI CA root.

@skyblaster Everything in iPXE and wimboot is working correctly here. The problem is in Hyper-V. As…

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@mcb30
Comment options

mcb30 Jun 3, 2026
Maintainer

Answer selected by skyblaster
@skyblaster
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants