# Preserve HGS signing and encryption keys through certificate renewal

> What certificate-renewal constraint must be preserved for Host Guardian Service?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-121-preserve-hgs-signing-and-encryption-keys-through-certificate-renewal/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:15:10+00:00
- Modified: 2026-09-08T18:23:27+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

What certificate-renewal constraint must be preserved for Host Guardian Service?

## Potentially affected

Administrators obtaining or renewing HGS signing and encryption certificates.

## DSE recommendation

Prepare a renewal plan that explicitly preserves the required keys and identifies the authorized custodian.

## Article

## Source facts

HGS uses signing and encryption certificates to protect the information needed to start shielded VMs. VM owners use the public certificate material to authorize the guarded environment. Microsoft recommends certificates from a trusted certification authority. The documentation also permits self-signed certificates for a lab environment. The HGS certificate requirements specify renewal with the same key. Microsoft warns that renewing with different keys prevents shielded VMs from starting. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-obtain-certs).

## Applicability

Identify the certificate roles, current keys, issuing authority, expiration dates, and all HGS nodes. Review the source’s complete cryptographic requirements and the key-storage provider before ordering replacements.

## DSE recommendation

Prepare a renewal plan that explicitly preserves the required keys and identifies the authorized custodian. Have the guarded-fabric owner review how renewal differs from an intentional key-change project. Schedule a representative startup test and retain the approved recovery material before replacing certificates.

## Verification

Inspect the renewed certificates and confirm the intended key relationship and deployment on the required nodes. Start a representative shielded VM through the approved guarded-host path and record HGS results. Treat an unexplained key change or startup failure as unresolved before completing the renewal.

## Official references

[Microsoft Learn: Obtain certificates for HGS](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-obtain-certs). Source reviewed September 8, 2026.

## Primary reference

- Name: Obtain certificates for HGS
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-obtain-certs
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Preserve HGS signing and encryption keys through certificate renewal,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-121-preserve-hgs-signing-and-encryption-keys-through-certificate-renewal/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
