Secure Boot Certificate Upgrade Paused.


Mitch

Well-known member
Member
Local time
11:03 AM
Posts
455
Location
Scotland
OS
Windows 11 Home
Hello, Our last PC which hasn't had the Secure Boot Certificates updated received a notification.

Devices in this group are affected by a known issue. To reduce risk, Secure Boot certificate updates are temporarily paused while Microsoft and partners work toward a supported resolution. Contact your device manufacturer for assistance.

The laptop is a Dell Inspiron 5570 of around 2018. The last BIOS update was in 2023 (1.14.0) and Dell have confirmed that no further BIOS updates will be issued.
I'm unclear what will happen in the future regarding Certificate Updates if Dell have written this machine off and a BIOS update is needed. Will this be the status ongoing?
Any advice would be appreciated. Mitch.
 

My Computer My Computer

At a glance

Windows 11 Home
OS
Windows 11 Home
PC's with a reported Confidence Level that doesn't match "High Confidence" will not be automatically updated.

"Temporarily Paused" indicates MS put your PC on hold for a vendor-specific issue which the vendor is supposed to fix. But in several cases, this isn't true. Your vendor may never release an update for this model.

"Not Supported" indicates MS put your PC on hold for a known issue which won't be fixed. This could indicate possible cases of BIOS corruption. But only your vendor and MS actually know what the real problem with the system is.

For your PC, if Dell support has confirmed they're not releasing a new BIOS, or providing a signed KEK file to MS, you can try to see if manual KEK key enrollment is supported in your BIOS.

Check in the Secure Boot menus if there's some option for manually adding keys. If there isn't, you might be able to update this PC by deleting all keys and replacing them with a MS-provided set.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7

My Computers My Computers

  • At a glance

    Windows11 Pro 26200.9267Intel Core i9 14900F (24 -Core, 68 MB Total C...32GB DDR5RTX 4080 Super w/610.74
    OS
    Windows11 Pro 26200.9267
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Alienware Aurora R16
    CPU
    Intel Core i9 14900F (24 -Core, 68 MB Total Cache)
    Motherboard
    Dell Alienware
    Memory
    32GB DDR5
    Graphics Card(s)
    RTX 4080 Super w/610.74
    Sound Card
    Realtec
    Monitor(s) Displays
    Corsair XENEON 32QHD165
    Screen Resolution
    2560 X 1440
    Hard Drives
    1-2TB Samsung 990 Pro PCIe NVMe M2 SSD
    1-4TB Samsung 990 Pro PCIe NVMe M2 SSD
    PSU
    1000 Watt Platinum Dell
    Case
    Alienware
    Cooling
    Liquid Closed Loop
    Keyboard
    Corsair Strafe RGB
    Mouse
    Logitech MK270 Wireless
    Internet Speed
    100Gb's Down-20 Up
    Browser
    Firefox 154.0
    Antivirus
    Defender
    Other Info
    Very Quiet And Fast
    CyberPower UPS CP1500PFCLCD
  • At a glance

    PClinuxOS Mate (2025.7)13th Gen Inter(R) Core(TM) i3-1315U64 GB DDR4 @3200 MHz.Internal
    Operating System
    PClinuxOS Mate (2025.7)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel
    CPU
    13th Gen Inter(R) Core(TM) i3-1315U
    Motherboard
    Intel
    Memory
    64 GB DDR4 @3200 MHz.
    Graphics card(s)
    Internal
    Sound Card
    None
    Monitor(s) Displays
    Dell 2419HGCF
    Screen Resolution
    1920 X 1080
    Hard Drives
    SAMSUNG 980 PRO SSD 2TB, PCIe 4.0 M.2 2280
    PSU
    Chicony 30 Watt
    Case
    Small
    Keyboard
    Dell
    Mouse
    Razor
    Internet Speed
    1GB
    Browser
    Slimjet
Firmware dating back to 2020 typically don't have CA 2023 factory support.
Starting around 2022 is where vendors started including them, because of the Black Lotus rootkit.

- Firmware updates to address the Intel Security Advisory INTEL-SA-00295 (CVE-2020-0536, CVE-2020-0539, and CVE-2020-0545).
- Firmware updates to address the Intel Security Advisory INTEL-SA-00322 (CVE-2020-0528 and CVE-2020-0529).
- Firmware updates to address the Intel Security Advisory INTEL-SA-00320 (CVE-2020-0543).
- Firmware updates to address the Intel Security Advisory INTEL-SA-00329 (CVE-2020-0548 and CVE-2020-0549).
- Firmware updates to address CVE-2020-5362.
- Fixed the issue where the hard drive master password reset does not function.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Thanks very much for the replies. MS seems to be pushing this back to Dell to issue a BIOS update which isn't going to happen. They have confirmed that the installed BIOS is the latest and last one they have issued in 2023.
I wouldn't probably go down the manual install option as the PC is used infrequently.
I'm more concerned that something may be forced in the background making it unbootable. I suppose if that happened I could disable Secure Boot in BIOS which I haven't done before. Thanks again.
 

My Computer My Computer

At a glance

Windows 11 Home
OS
Windows 11 Home
With a 2023 BIOS, it's more likely like manual enrollment can be done. But be aware that after October 2026, if MS pushes a new Windows boot manager to fix a future security hole, you can no longer run in Secure Boot mode with applying the certs.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Thanks @garlin . I think I'll go with what we've got. I assume if we still have the old certificates and a new boot manager is issued we could still run with Secure Boot on?
 

My Computer My Computer

At a glance

Windows 11 Home
OS
Windows 11 Home
No, it doesn't work that way.

When your UEFI wants to boot off a device (drive or USB stick), it looks for an EFI boot file to load. If Secure Boot is enabled, it reads the EFI file's signing certificate. This certificate is compared to your existing certs, and granted permission to boot or is denied.

At the time the boot file is compiled, a secure signing cert is attached to it (for validation purposes).

Every signing cert is only valid for a limited time range (fixed begin & end dates). Until the middle of this October, the existing PCA 2011 cert can be used to sign the boot file. It's still valid because there's just a little of time left on the calendar.

When the date runs past mid-October, PCA 2011 can no longer be used to sign a new version of the boot file. If your BIOS compares the signing date, it rejects this file as untrusted. That's how the security mechanism works. MS has no choice but the sign the boot file with a cert that covers the current date, which would be the CA 2023 cert.

But since your BIOS doesn't support CA 2023, then it cannot accept this new version of the boot file. Therefore it's not trusted when Secure Boot is enabled.

There is no exact timeline when the first Windows boot manager that is only signed by CA 2023 comes out, that can only be determined by whatever security fixes are applied. I imagine we'll see a flood of panicked users on a random Patch Tuesday when that day arrives. For users who don't want to try updating their certs, they'll be forced to either block Windows Updates or turn off Secure Boot.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Thanks very much @garlin for explaining that. I wonder if when a new boot manager is issued and if a PC has the old certificates MS will provide an alternative? I imagine there will be thousands of non tech people (like me) who can't boot their pc's. Perhaps they won't offer the updated boot manager to these people?
 

My Computer My Computer

At a glance

Windows 11 Home
OS
Windows 11 Home
In my opinion, here's what MS is likely to do:

1. Windows will aggressively nag you on-screen that don't have a supported PC with CA 2023.

2. WU will not knowingly brick your PC by deploying a post-October 2026 boot manager. You will keep whatever previous boot manager you have in place. They will probably nag you again about it. The old boot manager is still a valid program, but it cannot protect you against newer threats which may be exploited some point in the future.

3. If you disable Secure Boot, they won't nag you because the whole point is moot. Some Windows clients have a legitimate reason for not running in Secure Boot, because they have legacy drivers that cannot run in Secure Boot. But typically it's a legacy system with some super important app that absolutely cannot be disturbed or migrated to a new PC.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Thanks @garlin . I think I'll leave well alone with this PC. The notification says that MS and Dell will be working on a solution which probably isn't going to happen. The PC works well so I'll go with that. Thanks again and I appreciate your advice. Mitch.
 

My Computer My Computer

At a glance

Windows 11 Home
OS
Windows 11 Home
@garlin

Please could you explain the downsides of turning off Secure Boot on a personal computer? Is it there to protect from booting from a dodgy USB SSD, HDD ot flash memory stick? And if we only ever use devices we own, are we safe? TIA.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.9168AMD Ryzen 7 5825U with Radeon Graphics16GB
    OS
    Windows 11 Pro 25H2 26200.9168
    Computer type
    Laptop
    Manufacturer/Model
    Acemagic LX15PRO
    CPU
    AMD Ryzen 7 5825U with Radeon Graphics
    Motherboard
    BIOS CT_BI_AMI_LX15PRO_AB8139_A-004
    Memory
    16GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD 2TB
    Internet Speed
    30 Mbps
    Browser
    Brave
    Antivirus
    Webroot SecureAnywhere Complete beta
  • At a glance

    Windows 11 Pro 23H2 22631.2506Atom N450 1.66GHz2GB
    Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
    Browser
    Brave
    Antivirus
    Webroot
  • Acer Swift SF114-34 laptop
    OS Windows 11 Pro 26200.8894
    CPU Pentium Silver N6000
    RAM 4GB
    BIOS v1.17
    SSD Samsung 970 EVO Plus SSD 2TB (an upgrade)
Is it there to protect from booting from a dodgy USB SSD, HDD ot flash memory stick?
No, it's a tool to protect you from attacks very early in the boot process thereby giving an attacker extendend possibilities to disable OS protection mechanisms and protect itself from detection.
How often do you check your EFI system partition for being "dodgy" / having changed files and thereby excluding that some software (excuted with admin rights) changed your boot loader / boot manager?

And if we only ever use devices we own, are we safe? TIA.
If you can make a 100% sure you'll never install / start software with admin rights which could contain malware.

Secure Boot isn't a perfect solution and it protects one or two (very important) steps in the early OS boot- process, but it might give you a hint that something might be wrong if your system suddenly gets a secure boot violation when booting...

Black Lotus rootkit:
Guidance for investigating attacks using CVE-2022-21894: The BlackLotus campaign
The second abstract beginning with "It is critical to note that a threat actor’s use of this bootkit is primarily a persistence and defense evasion mechanism." explains the rootkit.
 

My Computer My Computer

At a glance

W10
OS
W10

Latest Support Threads

Back
Top Bottom