Secure Boot Allowed Key Exchange Key (KEK) Update


MitchInHome

Well-known member
Member
VIP
Local time
7:43 AM
Posts
90
OS
Win 11 Pro 25H2 26200 8457
Got this after boot this AM - supposed to be a gradual roll out I hope its the last for awhile, all seems to be ok for now after install..... My system spec's are up to date
Any one else ?
 
Last edited:

My Computer

System One

  • OS
    Win 11 Pro 25H2 26200 8457
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Omen45L
    CPU
    Intel Core I9 12900K
    Motherboard
    HP 8917
    Memory
    32 GB
    Graphics Card(s)
    Nvidia GeForce RTX 3060 24GB
    Sound Card
    HP
    Monitor(s) Displays
    2 HP 27 & 23
    Screen Resolution
    3840x2160
    Hard Drives
    2 TB Samsung 990 EVO 2 TB Samsung 1 TB SATA ST1000
    PSU
    HP 800 Watt
    Case
    HP
    Cooling
    Water
    Keyboard
    Logo Tech G 213
    Mouse
    Logi Tech 502
    Browser
    FireFox
    Antivirus
    MS Defender / Malwarebytes Prem.
    Other Info
    Omen 45SL purchased from HP 12 2022 - Brother Printer MFC-L2700DW APC 500 Back UPS Macrium Reflect Home 8.1 25H2 Oct 2025 KEK CA 2023 cert April 2026
This update is expected if your PC doesn't have a recent BIOS version which added the Secure Boot CA 2023 certs by itself. Your PC's vendor provided MS a copy of the signed KEK CA 2023 cert, which was successfully installed to your system.

The rest of the Secure Boot update process will happen (this year), without any user intervention on your part.
 

My Computer

System One

  • OS
    Windows 7
  • Like
Reactions: x_1
OK and thanks kind sir - guess I'll just wait now :rolleyes:
 

My Computer

System One

  • OS
    Win 11 Pro 25H2 26200 8457
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Omen45L
    CPU
    Intel Core I9 12900K
    Motherboard
    HP 8917
    Memory
    32 GB
    Graphics Card(s)
    Nvidia GeForce RTX 3060 24GB
    Sound Card
    HP
    Monitor(s) Displays
    2 HP 27 & 23
    Screen Resolution
    3840x2160
    Hard Drives
    2 TB Samsung 990 EVO 2 TB Samsung 1 TB SATA ST1000
    PSU
    HP 800 Watt
    Case
    HP
    Cooling
    Water
    Keyboard
    Logo Tech G 213
    Mouse
    Logi Tech 502
    Browser
    FireFox
    Antivirus
    MS Defender / Malwarebytes Prem.
    Other Info
    Omen 45SL purchased from HP 12 2022 - Brother Printer MFC-L2700DW APC 500 Back UPS Macrium Reflect Home 8.1 25H2 Oct 2025 KEK CA 2023 cert April 2026
We have received this update on some of the laptops in the house, but not all. Has been received in order on two HP spectre x360 13 (2019), an HP Envy 15 (2021), 2 x HP spectre x360 14x (2023), a Lenovo Yoga 9i (2024). It has yest to be received on the Gigabyte p37x (2015 - still going strong on Win 10 but chip too old for Windows 11), a Dell XPS 17 9700 (2020 I think), my HP Zbook 15V (2017) and a Gigabyte Aero 16 XE5 (2023). The Gigabyte Aero has not had a BIOS update since 6mths after I bought, the one & only BIOS update it has had, so not expecting Gigabyte to be speedy in releasing this to MS.

Not sure if one will be released for my 11 year old Win 10 Gigabyte P37x. It's still well used so I hope so.
 

My Computer

System One

  • OS
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    HP Zbook 15v
    CPU
    i7-8850H
    Memory
    16GB
    Graphics Card(s)
    Intel UHD 530 + Quadro P600
    Monitor(s) Displays
    When used as a desktop - Dell P2415Q (4K)
    Screen Resolution
    4K
    Hard Drives
    1 x SSD
    Keyboard
    Logitech MX Keys
    Mouse
    Logitech MX Anywhere 3
    Internet Speed
    4G Wireless Broadband. Speeds vary from 260/50 to 70/20 (Mb) depending on day/time.
    Browser
    Edge, Chrome. Firefox
    Antivirus
    Windows Defender. MBAM Pro
    Other Info
    No battery - spicy pillow removed. Laptop is permanently plugged in.
Not sure if one will be released for my 11 year old Win 10 Gigabyte P37x. It's still well used so I hope so.
Doubt it. Most vendors will only go as far back as 3-4 years to provide signed KEK's to MS. Since MS can't update it without the vendor's help, they'll just nag you that your PC is insecure.
 

My Computer

System One

  • OS
    Windows 7
I have now got an update for every computer in the house other than the 2nd to newest laptop - a 12th gen Gigabyte Aero XE5. Even my 8th gen HP Zbook 15v (2017) & 3 x 10th gen HP laptops (2019) have received the Secure boot KEK updates.

Gigabyte are notoriously bad in my experience for providing driver support to consumer laptops. I've had only 1 BIOS update for the Aero XE5 since new, & that was within a few months of owning it. I will be very annoyed if they do not provide an update, as it's my highest specced machine & heavily used.
 

My Computer

System One

  • OS
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    HP Zbook 15v
    CPU
    i7-8850H
    Memory
    16GB
    Graphics Card(s)
    Intel UHD 530 + Quadro P600
    Monitor(s) Displays
    When used as a desktop - Dell P2415Q (4K)
    Screen Resolution
    4K
    Hard Drives
    1 x SSD
    Keyboard
    Logitech MX Keys
    Mouse
    Logitech MX Anywhere 3
    Internet Speed
    4G Wireless Broadband. Speeds vary from 260/50 to 70/20 (Mb) depending on day/time.
    Browser
    Edge, Chrome. Firefox
    Antivirus
    Windows Defender. MBAM Pro
    Other Info
    No battery - spicy pillow removed. Laptop is permanently plugged in.

Latest Support Threads

Back
Top Bottom