If you cannot update your PC to MS UEFI CA 2023 certificates, this may be a solution to you.


suatcini54

Well-known member
Power User
VIP
Local time
3:33 AM
Posts
750
OS
Windows 11 Pro build 26200.8524
@garlin Your advice needed !!!

I have been reading here in this reputable forum that some HP PC owners whose PCs are out of service life cannot update their HP PCs to UEFI CA 2023 certificates using your scripts or other methods.

On the other hand, I have updated my HP EliteBook 840 G5 notebook PC, which is also out of service life, without a hitch (in as short as 15 minutes or so) and I cannot understand why other HP owners with the same model PCs cannot update their systems.

I know you have done too much work in trying to help Windows users update their systems to UEFI CA 2023 certificates by introducing wonderful scripts and constantly improving them, which have led many people to update their PCs like pulling a hair out of butter without any effort.

That's great work and I consider this forum and its members or non-member readers very lucky having your scripts, your comments and your individual advises on very many special cases and occasions.

Therefore, for those people without success, I developed (in my humble opinion. I may be wrong) a method to check if they can update their HP PCs (or any make and model PC for that matter) to Microsoft UEFI CA 2023 certificates. This may be their last resort.

If you can take a quick look and advise on the applicability of the method, it will be very helpful to those not able to update their systems. This method is universal. The example is for HP PC only.

REPLACE MS CA2023 CERTIFICATES IN HP NOTEBOOKS (out of their service life such as EliteBook 840 G5 with HP Sure Start Technology)

PROCEDURE:

Make sure you have the latest BIOS update. The latest BIOS for HP EliteBook 840 G5 version is: Q78 01.31.00 dated March.10, 2025

This version is important because it has PK (Platform Key) with signed Microsoft KEK 2K CA 2023 certificate.

Open PowerShell.

Give the command "Get-SecureBootUEFI -name PK -Decoded" without quotes.

Please write down "Serial Number" of PK in your PC or take a screenshot of the PowerShell command result.

Go to Microsoft github website "secureboot_objects/PostSignedObjects at main · microsoft/secureboot_objects"

Expand "PostSignedObjects"

Download "KEK_update_map.json" file.

Open "KEK_update_map.json" file with notepad. You will see a long list of manufacturers signed UEFI KEK CA 2023 certificates list.

Jason_HP.webp

Browse down the file until you see HP/KEK file information such as above.

Here you will see HP/KEK file names and their serial numbers. One of the serial numbers must match your PK serial number.

If there is no match, you may actually be out of luck. Serial number of HP/KEKUpdate_HP_PK1.bin file matched my PK serial number.

HP/KEKUpdate_HP_PK(x) where (x) should match your serial number. Download this HP/KEKUpdate_HP_PK(x) file.

Put this file and the .json file in a folder, such as C:\CERT

Now you will prepare your PC for installing this KEK file (for HP PCs with HP Sure Start Technology). If your PC does not have HP Sure Start, you will skip some steps.

1. Disable BitLocker if it is enabled. You can re-enable BitLocker after everything is done and all certificates are installed.

2. Disable "Sure Start Secure Boot Keys Protection" in BIOS. Save the settings, Reboot into BIOS again and check if this setting has remained disabled.

3. Disable Secure Boot through selecting "Legacy Support Disable and Secure Boot Disable" setting. Save the settings, reboot into BIOS again.

5. Enable/check "Clear SecureBoot keys" in BIOS. This puts Secure Boot into Setup Mode. Save the settings, Reboot directly into WINDOWS.

6. Open Powershell with elevated rights and leave PowerShell open.

7. Check that the UEFI is in fact in Setup Mode with PowerShell command (PowerShell opened in Administrator mode)

Get-SecureBootUEFI -Name SetupMode

If the answer is SetupMode {1}, then Setup Mode is on. If it is {0}, then you need to revisit BIOS and check the Clear SecureBoot setting again.

8. Run the following PowerShell command (change time setting if necessary. It should not be months away):

Set-SecureBootUEFI -Name KEK -ContentFilePath C:\certs\KEKUpdate_HP_PK(x).bin -Time 2026-09-01T00:00:00Z

Note: (x) should be replaced with your KEK file number, such as KEKUpdate_HP_PK1.bin

Reboot your PC and enter BIOS.

9. Unselect Clear Secureboot Keys, if it is not automatically unselected. Save the settings, Reboot and enter BIOS again.

10. Enable Secure Boot through "Legacy Support Disable and Secure Boot Enable". Save the settings and Reboot into WINDOWS.

11. Open Registry Editor and navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot key. Change the AvailableUpdates value to 0x5944 (hex).

12. Open Scheduled Tasks and run \Microsoft\Windows\PI\Secure-Boot-Update task.

13. Restart your PC and Reboot into WINDOWS.

14. Open Command Prompt with administrator rights and give the following command:

powershell -nop -ep bypass -f C:\Windows\SecureBoot\ExampleRolloutScripts\Detect-SecureBootCertUpdateStatus.ps1

You will get a report, confirming whether the certificate updates are completed or not.

Report.webp

You can later revoke Windows UEFI PCA 2011 certificate and put it in DBX section of the UEFI firmware.

You can also later activate SVN of the firmware. There are commands to do all this very easily.

If your PC runs well, then you can re-enable "Sure Start SecureBoot Keys Protection" in BIOS to protect the new UEFI CA 2023 certificates.

Hope this post is useful to some.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro build 26200.8524Intel i7-4790Teams DDR3-1600 4x4 GBMSI Nvidia GeForce GTX 1050Ti
    OS
    Windows 11 Pro build 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Built
    CPU
    Intel i7-4790
    Motherboard
    Asus H97 Pro Gamer with add-on TPM1.2 module
    Memory
    Teams DDR3-1600 4x4 GB
    Graphics Card(s)
    MSI Nvidia GeForce GTX 1050Ti
    Sound Card
    Realtek ALC1150
    Monitor(s) Displays
    Dell P2425D
    Screen Resolution
    2560 by 1440 pixels
    Hard Drives
    Corsair NVMe M.2 Core XT 1000 GB (Windows 11 v.25H2); Samsung SATA Evo 870 500 GB (Windows 11 v.25H2);
    PSU
    Corsair HX850
    Case
    Gigabyte Solo 210
    Cooling
    Zalman CNPS7X Tower
    Keyboard
    Microsoft AIO Wireless (includes touchpad)
    Mouse
    HP S1000 Plus Wireless
    Internet Speed
    500 Mb fiber optic
    Browser
    Chrome; MS Edge
    Antivirus
    Windows Defender
  • At a glance

    MacOS 12 MontereyIntel Core i58 GBIntel integrated
    Operating System
    MacOS 12 Monterey
    Computer type
    Laptop
    Manufacturer/Model
    Apple Macbook Air
    CPU
    Intel Core i5
    Memory
    8 GB
    Graphics card(s)
    Intel integrated
    Screen Resolution
    1440 by 900 pixels
    Hard Drives
    128 GB
    Keyboard
    Built-in
    Mouse
    Microsoft Wireless
    Internet Speed
    802.11 ac
    Browser
    Chrome; Safari
    Antivirus
    N/A
You've done a lot of work, but HP support finally provides a script for updating "End of Service Life" commercial (or business) PC's. For PC models that aren't supported by the update script, you may need other methods.
eosl-products-package-v5

Just run the PS script. What HP provides are two different KEK CA 2023 files for these PC's, instead of a BIOS update.

If HP has created signed KEK files, why not submit them to MS's GitHub repo and have the Secure Boot update task work? For reasons I don't know why, HP has two different PK's (2013 & 2017), but in their infinite lack of wisdom both KEK's ended up with the same thumbprint.

With the same thumbprint, MS cannot add both of them to the GitHub's master list of KEK certs or KEKUpdateCombined.bin. Additional logic (like a simple script) is required to figure which KEK matches your unsupported PC. The Secure Boot task doesn't have support for this logic, since it appears to be a HP-specific decision on their part.

For HP Elitebook * G5 owners, the script is available from the posted link. The next version of my scripts will alert you to use HP's own criteria and instruct you to use them.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Forgot to add there's no point doing this thumbprint matching on your own. That's exactly what the Secure Boot task does. The difference is Windows combines all of the GitHub's KEK files into one local file in the SecureBootUpdates folder. The correct matching KEK is extracted and installed.

To this day, OEM's are still adding a few KEK's. You can see the activity on the GitHub's commits and pending updates. Those KEK's will end up in an upcoming Monthly Update.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Thanks for your prompt response.

I updated my eosl notebook PC to UEFI CA 2023 keys in April 2026. I used another method that had me download all certificates from github.

edk.webp

I mentioned this several times in this forum. This time I found out reading several articles that by matching serial numbers the update can also be done. I may be wrong, though.

This is my updated HP notebook PC with your secureboot check script output.

SB.webp

This is my HP PK serial number and it has a match in .json's file in my first post.

Serial-No-PK-Cert.webp

That is which I do not understand why people with the same make and model PC cannot update to CA 2023 certs and this is why I tried to find a way, which is the whole point I came up with this post of mine.

Thanks again for your valuable comment.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro build 26200.8524Intel i7-4790Teams DDR3-1600 4x4 GBMSI Nvidia GeForce GTX 1050Ti
    OS
    Windows 11 Pro build 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Built
    CPU
    Intel i7-4790
    Motherboard
    Asus H97 Pro Gamer with add-on TPM1.2 module
    Memory
    Teams DDR3-1600 4x4 GB
    Graphics Card(s)
    MSI Nvidia GeForce GTX 1050Ti
    Sound Card
    Realtek ALC1150
    Monitor(s) Displays
    Dell P2425D
    Screen Resolution
    2560 by 1440 pixels
    Hard Drives
    Corsair NVMe M.2 Core XT 1000 GB (Windows 11 v.25H2); Samsung SATA Evo 870 500 GB (Windows 11 v.25H2);
    PSU
    Corsair HX850
    Case
    Gigabyte Solo 210
    Cooling
    Zalman CNPS7X Tower
    Keyboard
    Microsoft AIO Wireless (includes touchpad)
    Mouse
    HP S1000 Plus Wireless
    Internet Speed
    500 Mb fiber optic
    Browser
    Chrome; MS Edge
    Antivirus
    Windows Defender
  • At a glance

    MacOS 12 MontereyIntel Core i58 GBIntel integrated
    Operating System
    MacOS 12 Monterey
    Computer type
    Laptop
    Manufacturer/Model
    Apple Macbook Air
    CPU
    Intel Core i5
    Memory
    8 GB
    Graphics card(s)
    Intel integrated
    Screen Resolution
    1440 by 900 pixels
    Hard Drives
    128 GB
    Keyboard
    Built-in
    Mouse
    Microsoft Wireless
    Internet Speed
    802.11 ac
    Browser
    Chrome; Safari
    Antivirus
    N/A
I wrote a script to do all these exact steps so normal users don't have to follow all those instructions.

1. Check if PK has matching KEK in the MS GitHub. Download and install it.
2. If no matching KEK, try to copy the KEK pre-signed cert to the EFI. Ask user to manually install it. If that worked, continue with normal updates.
3. If user decides to delete all keys and is in Setup Mode, download the EDK2 zip. Install all certs.

You're free to document the whole process. But we have a working and (mostly debugged) script that works for most PC's. Except the ones which get "bricked" because they have weird firmware issues. For most non-technical users, it's just easier to try running the scripts.

What's unexpected is HP kinda messed up, and so they ended having to write their own update script. It works exactly like my script and pushes a KEK bin file, except they have extra logic to figure out if you have a 2013 or 2017 PK.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
I wrote a script to do all these exact steps so normal users don't have to follow all those instructions.

1. Check if PK has matching KEK in the MS GitHub. Download and install it.
2. If no matching KEK, try to copy the KEK pre-signed cert to the EFI. Ask user to manually install it. If that worked, continue with normal updates.
3. If user decides to delete all keys and is in Setup Mode, download the EDK2 zip. Install all certs.

You're free to document the whole process. But we have a working and (mostly debugged) script that works for most PC's. Except the ones which get "bricked" because they have weird firmware issues. For most non-technical users, it's just easier to try running the scripts.

What's unexpected is HP kinda goofed, and so they ended having to write their own update script. It works exactly like my script and pushes a KEK bin file, except they have extra logic to figure out if you have a 2013 or 2017 PK.
I am sorry if I am misunderstood. I know and I tried to say your scripts helped thousands, if not millions, of people. My point was, people who could not update systems may see if they can update or not by just checking a simple file and a serial number.

My starting point was HP EliteBook 840 G5 owners, my HP notebook, who could not update. Maybe they can now see what they must do, hopefully.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro build 26200.8524Intel i7-4790Teams DDR3-1600 4x4 GBMSI Nvidia GeForce GTX 1050Ti
    OS
    Windows 11 Pro build 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Built
    CPU
    Intel i7-4790
    Motherboard
    Asus H97 Pro Gamer with add-on TPM1.2 module
    Memory
    Teams DDR3-1600 4x4 GB
    Graphics Card(s)
    MSI Nvidia GeForce GTX 1050Ti
    Sound Card
    Realtek ALC1150
    Monitor(s) Displays
    Dell P2425D
    Screen Resolution
    2560 by 1440 pixels
    Hard Drives
    Corsair NVMe M.2 Core XT 1000 GB (Windows 11 v.25H2); Samsung SATA Evo 870 500 GB (Windows 11 v.25H2);
    PSU
    Corsair HX850
    Case
    Gigabyte Solo 210
    Cooling
    Zalman CNPS7X Tower
    Keyboard
    Microsoft AIO Wireless (includes touchpad)
    Mouse
    HP S1000 Plus Wireless
    Internet Speed
    500 Mb fiber optic
    Browser
    Chrome; MS Edge
    Antivirus
    Windows Defender
  • At a glance

    MacOS 12 MontereyIntel Core i58 GBIntel integrated
    Operating System
    MacOS 12 Monterey
    Computer type
    Laptop
    Manufacturer/Model
    Apple Macbook Air
    CPU
    Intel Core i5
    Memory
    8 GB
    Graphics card(s)
    Intel integrated
    Screen Resolution
    1440 by 900 pixels
    Hard Drives
    128 GB
    Keyboard
    Built-in
    Mouse
    Microsoft Wireless
    Internet Speed
    802.11 ac
    Browser
    Chrome; Safari
    Antivirus
    N/A
Two HP reps promised in an earlier Secure Boot AMA that HP would provide a fix for G5 PC's, and it took them a while before support finally got a solution which they're providing to their users. There are threads in the HP forums where users are already asking about the tools.

But the tool is only for "commercial" or business PC's. Not for unsupported personal PC's.

When you run my update scripts, all the steps you covered are processed. For an unsupported PC, the user is asked to first try manual KEK enrollment since it's the least intrusive fix, and if that doesn't work, then the user is suggested to go into Setup Mode and re-run the script. This covers all the PC's that can be updated.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
I think people with older hardware that cant update, can always skip using secure boot
Secure boot is more of a theoretical protection mostly proven in hack/security conventions as a proof of concept then it is a real world threat to most people.

So people that feel they have to run and buy new hardware as they cant use secure boot should not worry to much.

If you can update, Great, do it and use it.. if you cant, the risk of that being exploited is less then winning the lottery.


Edit:
the chain of failure.
The user have to do something stupid to first get a malware.
Of all malwares out there, the Malware has to be specificity design for attacking what secure boot protect against.
The AV has to fail to detect the malware so it can run and do its thing.
It is a bigger chance to actually win the lottery
 

My Computers My Computers

  • At a glance

    Linux: Debian, Kali-linux, Alma, Win:7,10IoT,...i3, i5 and i7 From 2gen to 9th gen... Server ...
    OS
    Linux: Debian, Kali-linux, Alma, Win:7,10IoT,2012R
    Manufacturer/Model
    HP Elitebook 840, AsusX53, Aspire E1-572. AsusUX32A, HP Pro3130mt+3010mt, HP Proliant ML150, 3xCustom-PC, i3, i5, i7
    CPU
    i3, i5 and i7 From 2gen to 9th gen... Server dual Xenon
    Hard Drives
    Sata, M.2, SAS
  • At a glance

    Retro: 2003server.XPpro, Win2000, Win98SE, Wi...Oldest intel 8088 up to P4 dual core
    Operating System
    Retro: 2003server.XPpro, Win2000, Win98SE, Win95, Win3.11, MS-DOS, IBM-DOS
    Manufacturer/Model
    Commodore, AST, Fujitsu, Compaq, etc etc. etc Around 15 desktops and 20 laptops in the collection
    CPU
    Oldest intel 8088 up to P4 dual core
    Hard Drives
    MFM, IDE, SCSI

Latest Support Threads

Back
Top Bottom