UEFI KEK Certs not updated.


According to AI (which is unreliable), Huawei laptops don't have any kind of method of unlocking advanced bios, other than setting a supervisor password to unlock various things. Shut down, boot into bios with F2 key, go to "Security" tab, select "Set Supervisor password" (or set Administrator password), and hit enter. Create a memorable password (and write it down), press F10 to save changes. Restart and do F2 to go into bios again and enter the password if requested, go back to the Security or Boot tab. The hidden Secure Boot key Management, Custom mode, or restore factory keys options should be visible and selectable.

Maybe? :-) Could be worth a try. I had to do that on a laptop once and it did unlock various things.

I'm also wondering if clearing the CMOS battery might reset the bios or bring up new options. It was something that was needed to clear bios passwords on older laptops - in those days you could use two points of a paperclip on a couple of contacts next to the cmos battery. Not sure how you'd do it now, other than maybe a hard reset.

There's also this for restoring default bios generally - but you probably already know this




You could just turn secure boot off, use any highly rated antivirus program plus Malwarebytes Premium which detects rootkits and bootkits. Or just use Malwarebytes premium. And occasionally run the Kaspersky offline rescue disk (to check everything is clean - it detects rootkits or bootkits before windows loads). Once you have the Kaspersky rescue disk burned to usb it's fairly simple and quick to use on occasion - except it seems to need an ethernet connection to be able to update each time.

With sensible internet use and an adblocker you'd maybe never have an issue - and don't use usb sticks that have been in another machine. And maybe encrypt your drive and use strong WPA3 passwords on router. All of which are sensible anyway. I would think phishing emails would be a risk so care to avoid clicking on links in emails (sensible anyway) and some AV's actually protect from phishing emails now and alert you also.

And set a bios password.
Thanks for all the thinking and the great security tips, I am planning to do that :-) I did alot even try flash the bios to an older version but thats blocked too, the battery could be a next step and I can also put in a bigger NVME drive at the same time when its open, I leave secure boot on, this is still working with the old 2011 certs, I also have a good virus scanner what can do a scan before Windows is loading.
 

My Computer My Computer

At a glance

Windows 11 Pro 25H2 26200.7019Intel Core i7-8700KCorsair 32GB 4x DDR4-2998 / PC4-23900 DDR4 SD...AMD RX570
OS
Windows 11 Pro 25H2 26200.7019
Computer type
PC/Desktop
Manufacturer/Model
Self built midi tower
CPU
Intel Core i7-8700K
Motherboard
Gigabyte Z390GX
Memory
Corsair 32GB 4x DDR4-2998 / PC4-23900 DDR4 SDRAM UDIMM
Graphics Card(s)
AMD RX570
Sound Card
Sound Blaster Z
Monitor(s) Displays
2x IIyama Prolite X2380HS
Screen Resolution
1920x1080
Hard Drives
Samsung SSD 970 EVO Plus NVMe 1TB
Samsung SSD 970 EVO Plus NVMe 500GB
PSU
Seasonic 550W
Cooling
Noctua fans
Keyboard
Logitech G213
Mouse
Logitech Marble Mouse
Browser
Chrome
Antivirus
Norton
Other Info
Video/Audio editting machine
Are you going to try the setting a bios password thing? It would be great if that works and you can reset the secure boot keys.
 

My Computers My Computers

  • At a glance

    Windows 11 Home 25H2Core i5-1035G132gb
    OS
    Windows 11 Home 25H2
    Computer type
    Laptop
    Manufacturer/Model
    HP Pavilion 14-ce3606sa
    CPU
    Core i5-1035G1
    Memory
    32gb
    Hard Drives
    Samsung 870 evo sata ssd
    Cooling
    Could be better
    Internet Speed
    50 mbps Starlink
    Browser
    Firefox
    Other Info
    Originally came installed with a 500gb H10 Optane ssd
  • At a glance

    Windows 11 HomeIntel Core i5-1035G116gb
    Operating System
    Windows 11 Home
    Computer type
    Laptop
    Manufacturer/Model
    HP Pavilion ce3606sa
    CPU
    Intel Core i5-1035G1
    Memory
    16gb
    Hard Drives
    Hynix Gold P31 2TB
    Internet Speed
    200mbps Starlink
    Browser
    Firefox
    Antivirus
    Defender
Are you going to try the setting a bios password thing? It would be great if that works and you can reset the secure boot keys.
Yes I am gonna try that, I want to upgrade the 500GB NVME to a 2TB one so when the laptop is open I can do the bios reset hopefully.
 

My Computer My Computer

At a glance

Windows 11 Pro 25H2 26200.7019Intel Core i7-8700KCorsair 32GB 4x DDR4-2998 / PC4-23900 DDR4 SD...AMD RX570
OS
Windows 11 Pro 25H2 26200.7019
Computer type
PC/Desktop
Manufacturer/Model
Self built midi tower
CPU
Intel Core i7-8700K
Motherboard
Gigabyte Z390GX
Memory
Corsair 32GB 4x DDR4-2998 / PC4-23900 DDR4 SDRAM UDIMM
Graphics Card(s)
AMD RX570
Sound Card
Sound Blaster Z
Monitor(s) Displays
2x IIyama Prolite X2380HS
Screen Resolution
1920x1080
Hard Drives
Samsung SSD 970 EVO Plus NVMe 1TB
Samsung SSD 970 EVO Plus NVMe 500GB
PSU
Seasonic 550W
Cooling
Noctua fans
Keyboard
Logitech G213
Mouse
Logitech Marble Mouse
Browser
Chrome
Antivirus
Norton
Other Info
Video/Audio editting machine
I reset the bios with disconnecting the battery but everything is the same after the reset, no extra advanced tabs.
 

My Computer My Computer

At a glance

Windows 11 Pro 25H2 26200.7019Intel Core i7-8700KCorsair 32GB 4x DDR4-2998 / PC4-23900 DDR4 SD...AMD RX570
OS
Windows 11 Pro 25H2 26200.7019
Computer type
PC/Desktop
Manufacturer/Model
Self built midi tower
CPU
Intel Core i7-8700K
Motherboard
Gigabyte Z390GX
Memory
Corsair 32GB 4x DDR4-2998 / PC4-23900 DDR4 SDRAM UDIMM
Graphics Card(s)
AMD RX570
Sound Card
Sound Blaster Z
Monitor(s) Displays
2x IIyama Prolite X2380HS
Screen Resolution
1920x1080
Hard Drives
Samsung SSD 970 EVO Plus NVMe 1TB
Samsung SSD 970 EVO Plus NVMe 500GB
PSU
Seasonic 550W
Cooling
Noctua fans
Keyboard
Logitech G213
Mouse
Logitech Marble Mouse
Browser
Chrome
Antivirus
Norton
Other Info
Video/Audio editting machine
according to your post #1
you have the secure boot certs 2023 installed, enabled and the system is booting using them

the only thing you require is the updated KEK keys
here is a link to the Microsoft KEK key download page

here is link to the actual KEK key download itself. this is an actual download link.
https://aka.ms/KEKUpdatePackage

you can install these keys manually
here is the link to GitHub with the details and repository

best of luck Steve ..
 

My Computers My Computers

  • At a glance

    Debian 13 KDE .. Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Debian 13 KDE .. Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
If updating KEK this way is safe, why doesn't Microsoft do it through Windows Update? Or at least release a tool and instructions for users?

I'm sure there are a significant number of PCs out there with this problem. A lot of manufacturers don't care about supporting PC firmware after a few years.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
If updating KEK this way is safe, why doesn't Microsoft do it through Windows Update? Or at least release a tool and instructions for users?

I'm sure there are a significant number of PCs out there with this problem. A lot of manufacturers don't care about supporting PC firmware after a few years.
MS do update the secure boot certs and KEK keys for system that are supported via Windows Update
and also these updates can be available from the manufactures web site.

the big 'if' is if they are supported and there lies the problem, not all systems are supported.
best of luck Steve ..
 

My Computers My Computers

  • At a glance

    Debian 13 KDE .. Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Debian 13 KDE .. Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
according to your post #1
you have the secure boot certs 2023 installed, enabled and the system is booting using them

the only thing you require is the updated KEK keys
here is a link to the Microsoft KEK key download page

here is link to the actual KEK key download itself. this is an actual download link.
https://aka.ms/KEKUpdatePackage

you can install these keys manually
here is the link to GitHub with the details and repository

best of luck Steve ..

Can you explain how the OP system could have been booting the 2023 certs when there's no 2023 KEK ? Your links to the 2023 KEK are fine, but how does the OP actually install it ?
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
It's possible to install all of the CA 2023 certs, except for the most important one in the whole set (KEK CA 2023). But none of the other certs are validated until KEK is loaded.

From reading a Hackintosh thread, some Huawei models don't appear to support manual key management at all. The posted solution was to use specialized EFI boot tools to overwrite the existing keys.

Since the other dev who has a working tool of this type is openly hostile to me, I allow @XxXxX to make his usual recommendation.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Can you explain how the OP system could have been booting the 2023 certs when there's no 2023 KEK ? Your links to the 2023 KEK are fine, but how does the OP actually install it ?

the keys can be manually updated using mosby secure boot updater
i placed the details in post #29 of this thread.

@garlin
what dev is hostile please

best of luck Steve ..
 

My Computers My Computers

  • At a glance

    Debian 13 KDE .. Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Debian 13 KDE .. Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
the keys can be manually updated using mosby secure boot updater
i placed the details in post #29 of this thread.

@garlin
what dev is hostile please

best of luck Steve ..

I've noticed that key enrolment feature in Mosby, never put 2+2 together to realize it could work in this situation. Good catch on your part.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
according to your post #1
you have the secure boot certs 2023 installed, enabled and the system is booting using them

the only thing you require is the updated KEK keys
here is a link to the Microsoft KEK key download page

here is link to the actual KEK key download itself. this is an actual download link.
https://aka.ms/KEKUpdatePackage

you can install these keys manually
here is the link to GitHub with the details and repository

best of luck Steve ..
Can I get a step-by-step plan on how to do this? It looks complicated to me.
 

My Computer My Computer

At a glance

Windows 11 Pro 25H2 26200.7019Intel Core i7-8700KCorsair 32GB 4x DDR4-2998 / PC4-23900 DDR4 SD...AMD RX570
OS
Windows 11 Pro 25H2 26200.7019
Computer type
PC/Desktop
Manufacturer/Model
Self built midi tower
CPU
Intel Core i7-8700K
Motherboard
Gigabyte Z390GX
Memory
Corsair 32GB 4x DDR4-2998 / PC4-23900 DDR4 SDRAM UDIMM
Graphics Card(s)
AMD RX570
Sound Card
Sound Blaster Z
Monitor(s) Displays
2x IIyama Prolite X2380HS
Screen Resolution
1920x1080
Hard Drives
Samsung SSD 970 EVO Plus NVMe 1TB
Samsung SSD 970 EVO Plus NVMe 500GB
PSU
Seasonic 550W
Cooling
Noctua fans
Keyboard
Logitech G213
Mouse
Logitech Marble Mouse
Browser
Chrome
Antivirus
Norton
Other Info
Video/Audio editting machine
the big 'if' is if they are supported and there lies the problem, not all systems are supported.
Well, yea. That's what this thread is about.

What I'm saying is that either:
A) Manually updating the KEK is not as easy (and risk free) as you and others suggest.
or
B) It is easy, but Microsoft is being negligent by not helping people with it.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Can I get a step-by-step plan on how to do this? It looks complicated to me.

this maybe of help

but it maybe an idea to put up a new post asking for instructions to create a bootable mosby USB
as several forum members have actually updated secure boot and KEK keys this way.

best of luck Steve ..
 

My Computers My Computers

  • At a glance

    Debian 13 KDE .. Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Debian 13 KDE .. Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
Well, yea. That's what this thread is about.

What I'm saying is that either:
A) Manually updating the KEK is not as easy (and risk free) as you and others suggest.
or
B) It is easy, but Microsoft is being negligent by not helping people with it.

and i and others are trying by all means possible to correct that
with the help, aid and assistance of many forum members.

best of luck Steve ..
 

My Computers My Computers

  • At a glance

    Debian 13 KDE .. Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Debian 13 KDE .. Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
As part of the suggested process for the OP, anyone want to guess if running the update script will download all the certs to the EFI folder named ' certs ', might be a useful and easy shortcut to get access to the KEK when attempting to enrol it.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11

Latest Support Threads

Back
Top Bottom