That doesn't make sense. The overall byte length of the PK is really determined by how many characters it takes to encode the Issuer's (cert owner) name. Even the longest shouldn't be larger than roughly 1 KB.
If the byte sizes don't match, it means a different PK was used. Generally an OEM won't replace the PK from the one that was originally provided in the very first BIOS version. They stick to the same PK over the system's lifetime. The one exception will be for any BIOS'es that issued a "DO NOT SHIP" PK by accident. Those would be replaced by a proper issuer's name instead of "DO NOT SHIP".
On updated systems, they probably rewrote parts of the BIOS and by coincidence they switched the PK. But the PK itself does nothing to determine whether adding too many DBX entries will mess up the cert validations.
If the byte sizes don't match, it means a different PK was used. Generally an OEM won't replace the PK from the one that was originally provided in the very first BIOS version. They stick to the same PK over the system's lifetime. The one exception will be for any BIOS'es that issued a "DO NOT SHIP" PK by accident. Those would be replaced by a proper issuer's name instead of "DO NOT SHIP".
On updated systems, they probably rewrote parts of the BIOS and by coincidence they switched the PK. But the PK itself does nothing to determine whether adding too many DBX entries will mess up the cert validations.
My Computer
At a glance
Windows 7
- OS
- Windows 7











