• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended

Secure Boot Certificate Updates

I have an HP Zbook 15 G3 running Windows 10 and enrolled in the Microsoft Extended Support Updates program.

I want to update the Secure Boot Certificates to the new 2023 versions, but have been experiencing problems.  The system is running the last version of the BIOS N81 v1.62 from SoftPaq sp151837.exe released in May 2024 which is the last version that HP released.

During this year as Microsoft has improved its status reporting in the Security App my laptop was reporting:

Microsoft Update Status

Secure boot is on, but your device is affected by a known issue. To reduce risk Secure Boot certificate updates are temporarily paused while Microsoft and partners work toward a supported resolution.  The update will resume once resolved.

I waited and waited, and this is still the status.  Now of course we have passed the 24th June 2026, so the certificates have now started to expire.  I then tried the Microsoft manual mechanism to update the certificates from https://support.microsoft.com/en-gb/topic/registry-key-updates-for-secure-boot-windows-devices-with-...,  This started the update procedure, but after the two reboots the Event Log showed:

Log Name:      System

Source:        Microsoft-Windows-TPM-WMI

Date:          25/06/2026 14:53:49

Event ID:      1801

Task Category: None

Level:         Error

Keywords:     

User:          SYSTEM

Computer:      dardron

Description:

Updated Secure Boot certificates are available on this device but have not yet been applied to the firmware. Review the published guidance to complete the update and maintain full protection. This device signature information is included here.

DeviceAttributes: FirmwareManufacturer:HP;FirmwareVersion:N81 Ver. 01.62;OEMModelBaseBoard:80D5;OEMManufacturerName:HP;OSArchitecture:amd64;

BucketId: 74d02577488b044b8c7996d5a995727216f53d0fa3626bb3b3a5a78c85cfaaa3

BucketConfidenceLevel: Temporarily Paused

UpdateType:

For more information, please see https://go.microsoft.com/fwlink/?linkid=2301018.

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-TPM-WMI" Guid="{7d5387b0-cbe0-11da-a94d-0800200c9a66}" />

    <EventID>1801</EventID>

    <Version>2</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8000000000000000</Keywords>

    <TimeCreated SystemTime="2026-06-25T13:53:49.1859697Z" />

    <EventRecordID>122843</EventRecordID>

    <Correlation />

    <Execution ProcessID="32164" ThreadID="6680" />

    <Channel>System</Channel>

    <Computer>dardron</Computer>

    <Security UserID="S-1-5-18" />

  </System>

  <EventData>

    <Data Name="DeviceAttributes">FirmwareManufacturer:HP;FirmwareVersion:N81 Ver. 01.62;OEMModelBaseBoard:80D5;OEMManufacturerName:HP;OSArchitecture:amd64;</Data>

    <Data Name="BucketId">74d02577488b044b8c7996d5a995727216f53d0fa3626bb3b3a5a78c85cfaaa3</Data>

    <Data Name="BucketConfidenceLevel">Temporarily Paused</Data>

    <Data Name="UpdateType">

    </Data>

  </EventData>

</Event>

 

Log Name:      System

Source:        Microsoft-Windows-TPM-WMI

Date:          25/06/2026 14:53:49

Event ID:      1797

Task Category: None

Level:         Error

Keywords:     

User:          SYSTEM

Computer:      dardron

Description:

The Secure Boot update failed as the Windows UEFI CA 2023 certificate is not present in Db

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-TPM-WMI" Guid="{7d5387b0-cbe0-11da-a94d-0800200c9a66}" />

    <EventID>1797</EventID>

    <Version>0</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8000000000000000</Keywords>

    <TimeCreated SystemTime="2026-06-25T13:53:49.1712539Z" />

    <EventRecordID>122842</EventRecordID>

    <Correlation />

    <Execution ProcessID="32164" ThreadID="6680" />

    <Channel>System</Channel>

    <Computer>dardron</Computer>

    <Security UserID="S-1-5-18" />

  </System>

  <EventData>

  </EventData>

</Event>

 

Log Name:      System

Source:        Microsoft-Windows-TPM-WMI

Date:          25/06/2026 14:53:49

Event ID:      1802

Task Category: None

Level:         Error

Keywords:     

User:          SYSTEM

Computer:      dardron

Description:

The Secure Boot update KEK 2023 was blocked due to a known firmware issue on the device. Check with your device vendor for a firmware update that addresses the issue. This device signature information is included here.

DeviceAttributes: FirmwareManufacturer:HP;FirmwareVersion:N81 Ver. 01.62;OEMModelBaseBoard:80D5;OEMManufacturerName:HP;OSArchitecture:amd64;

BucketId: 74d02577488b044b8c7996d5a995727216f53d0fa3626bb3b3a5a78c85cfaaa3

BucketConfidenceLevel: Temporarily Paused

SkipReason: KI_7.

For more information, please see https://go.microsoft.com/fwlink/?linkid=2339472

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-TPM-WMI" Guid="{7d5387b0-cbe0-11da-a94d-0800200c9a66}" />

    <EventID>1802</EventID>

    <Version>1</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8000000000000000</Keywords>

    <TimeCreated SystemTime="2026-06-25T13:53:49.1437286Z" />

    <EventRecordID>122841</EventRecordID>

    <Correlation />

    <Execution ProcessID="32164" ThreadID="6680" />

    <Channel>System</Channel>

    <Computer>dardron</Computer>

    <Security UserID="S-1-5-18" />

  </System>

  <EventData>

    <Data Name="UpdateType">KEK 2023</Data>

    <Data Name="DeviceAttributes">FirmwareManufacturer:HP;FirmwareVersion:N81 Ver. 01.62;OEMModelBaseBoard:80D5;OEMManufacturerName:HP;OSArchitecture:amd64;</Data>

    <Data Name="BucketId">74d02577488b044b8c7996d5a995727216f53d0fa3626bb3b3a5a78c85cfaaa3</Data>

    <Data Name="BucketConfidenceLevel">Temporarily Paused</Data>

    <Data Name="SkipReason">KI_7</Data>

  </EventData>

</Event>

 

Log Name:      System

Source:        Microsoft-Windows-TPM-WMI

Date:          25/06/2026 14:53:49

Event ID:      1802

Task Category: None

Level:         Error

Keywords:     

User:          SYSTEM

Computer:      dardron

Description:

The Secure Boot update 3P UEFI CA 2023 (DB) was blocked due to a known firmware issue on the device. Check with your device vendor for a firmware update that addresses the issue. This device signature information is included here.

DeviceAttributes: FirmwareManufacturer:HP;FirmwareVersion:N81 Ver. 01.62;OEMModelBaseBoard:80D5;OEMManufacturerName:HP;OSArchitecture:amd64;

BucketId: 74d02577488b044b8c7996d5a995727216f53d0fa3626bb3b3a5a78c85cfaaa3

BucketConfidenceLevel: Temporarily Paused

SkipReason: KI_7.

For more information, please see https://go.microsoft.com/fwlink/?linkid=2339472

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-TPM-WMI" Guid="{7d5387b0-cbe0-11da-a94d-0800200c9a66}" />

    <EventID>1802</EventID>

    <Version>1</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8000000000000000</Keywords>

    <TimeCreated SystemTime="2026-06-25T13:53:49.1138880Z" />

    <EventRecordID>122840</EventRecordID>

    <Correlation />

    <Execution ProcessID="32164" ThreadID="6680" />

    <Channel>System</Channel>

    <Computer>dardron</Computer>

    <Security UserID="S-1-5-18" />

  </System>

  <EventData>

    <Data Name="UpdateType">3P UEFI CA 2023 (DB)</Data>

    <Data Name="DeviceAttributes">FirmwareManufacturer:HP;FirmwareVersion:N81 Ver. 01.62;OEMModelBaseBoard:80D5;OEMManufacturerName:HP;OSArchitecture:amd64;</Data>

    <Data Name="BucketId">74d02577488b044b8c7996d5a995727216f53d0fa3626bb3b3a5a78c85cfaaa3</Data>

    <Data Name="BucketConfidenceLevel">Temporarily Paused</Data>

    <Data Name="SkipReason">KI_7</Data>

  </EventData>

</Event>

 

Log Name:      System

Source:        Microsoft-Windows-TPM-WMI

Date:          25/06/2026 14:53:49

Event ID:      1802

Task Category: None

Level:         Error

Keywords:     

User:          SYSTEM

Computer:      dardron

Description:

The Secure Boot update Option ROM CA 2023 (DB) was blocked due to a known firmware issue on the device. Check with your device vendor for a firmware update that addresses the issue. This device signature information is included here.

DeviceAttributes: FirmwareManufacturer:HP;FirmwareVersion:N81 Ver. 01.62;OEMModelBaseBoard:80D5;OEMManufacturerName:HP;OSArchitecture:amd64;

BucketId: 74d02577488b044b8c7996d5a995727216f53d0fa3626bb3b3a5a78c85cfaaa3

BucketConfidenceLevel: Temporarily Paused

SkipReason: KI_7.

For more information, please see https://go.microsoft.com/fwlink/?linkid=2339472

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-TPM-WMI" Guid="{7d5387b0-cbe0-11da-a94d-0800200c9a66}" />

    <EventID>1802</EventID>

    <Version>1</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8000000000000000</Keywords>

    <TimeCreated SystemTime="2026-06-25T13:53:49.0852877Z" />

    <EventRecordID>122839</EventRecordID>

    <Correlation />

    <Execution ProcessID="32164" ThreadID="6680" />

    <Channel>System</Channel>

    <Computer>dardron</Computer>

    <Security UserID="S-1-5-18" />

  </System>

  <EventData>

    <Data Name="UpdateType">Option ROM CA 2023 (DB)</Data>

    <Data Name="DeviceAttributes">FirmwareManufacturer:HP;FirmwareVersion:N81 Ver. 01.62;OEMModelBaseBoard:80D5;OEMManufacturerName:HP;OSArchitecture:amd64;</Data>

    <Data Name="BucketId">74d02577488b044b8c7996d5a995727216f53d0fa3626bb3b3a5a78c85cfaaa3</Data>

    <Data Name="BucketConfidenceLevel">Temporarily Paused</Data>

    <Data Name="SkipReason">KI_7</Data>

  </EventData>

</Event>

 

Log Name:      System

Source:        Microsoft-Windows-TPM-WMI

Date:          25/06/2026 14:53:49

Event ID:      1802

Task Category: None

Level:         Error

Keywords:     

User:          SYSTEM

Computer:      dardron

Description:

The Secure Boot update Windows UEFI CA 2023 (DB) was blocked due to a known firmware issue on the device. Check with your device vendor for a firmware update that addresses the issue. This device signature information is included here.

DeviceAttributes: FirmwareManufacturer:HP;FirmwareVersion:N81 Ver. 01.62;OEMModelBaseBoard:80D5;OEMManufacturerName:HP;OSArchitecture:amd64;

BucketId: 74d02577488b044b8c7996d5a995727216f53d0fa3626bb3b3a5a78c85cfaaa3

BucketConfidenceLevel: Temporarily Paused

SkipReason: KI_7.

For more information, please see https://go.microsoft.com/fwlink/?linkid=2339472

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-TPM-WMI" Guid="{7d5387b0-cbe0-11da-a94d-0800200c9a66}" />

    <EventID>1802</EventID>

    <Version>1</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8000000000000000</Keywords>

    <TimeCreated SystemTime="2026-06-25T13:53:49.0578695Z" />

    <EventRecordID>122838</EventRecordID>

    <Correlation />

    <Execution ProcessID="32164" ThreadID="6680" />

    <Channel>System</Channel>

    <Computer>dardron</Computer>

    <Security UserID="S-1-5-18" />

  </System>

  <EventData>

    <Data Name="UpdateType">Windows UEFI CA 2023 (DB)</Data>

    <Data Name="DeviceAttributes">FirmwareManufacturer:HP;FirmwareVersion:N81 Ver. 01.62;OEMModelBaseBoard:80D5;OEMManufacturerName:HP;OSArchitecture:amd64;</Data>

    <Data Name="BucketId">74d02577488b044b8c7996d5a995727216f53d0fa3626bb3b3a5a78c85cfaaa3</Data>

    <Data Name="BucketConfidenceLevel">Temporarily Paused</Data>

    <Data Name="SkipReason">KI_7</Data>

  </EventData>

</Event>

Since the laptop is “End of Service Life” I will not be seeing any further BIOS updates.  However, I was encouraged to find:

HP Business PCs - Prepare for new Windows Secure Boot certificates

And specifically the section:

Support for HP Commercial PCs outside of service life

Where is states:

For HP Commercial PCs that do not receive a BIOS update because they have reached their End of Service Life (EOSL) date (including select 2018 products and all HP PCs released 2017 and earlier), HP has developed a solution to allow you to update your system manually.

To be updated manually, systems meet the following requirements:

Contact HP to receive assistance with this manual process.

Note: 

Select product configurations might not be able to receive the updated certificates. In addition, the solutions/updates for EOSL products are provided as is. These updates receive limited testing and might not work as intended. Customers assume full responsibility for any issues that might occur when using this solution. HP encourages phased/ring testing for this solution before deploying it to all products.

I therefore tried to reach out to HP support to get the details of this manual process since HP were indicating that they had developed a manual solution to update EoSL systems.  This did not work out as well as I had hoped since instead of being sent the instructions, I was just referred to two generic Microsoft URLs on the Secure Boot process which I had obviously already found.

 

If anyone has any information on this supposed solution, I would be extremely interested to receive it. 

 

In October 2026 I will probably move this system to a Linux distribution, but I would still like to be running Secure Boot

5 REPLIES 5
HP Recommended

Hello,

The Event ID 1802 with SkipReason: KI_7 confirms that Microsoft has temporarily blocked the Secure Boot 2023 certificate update because of a known firmware compatibility issue. Therefore, changing the registry values or manually importing certificates may not be safe.

Since the HP ZBook 15 G3 is an End-of-Service-Life commercial device, I recommend contacting HP Business Support and specifically requesting the manual Secure Boot 2023 certificate update solution for EOSL HP Commercial PCs.

HP guidance:
https://support.hp.com/us-en/document/ish_13070353-13070429-16

Microsoft Secure Boot event guidance:
https://support.microsoft.com/en-us/topic/secure-boot-db-and-dbx-variable-update-events-37e47cf8-608...

I would not recommend using certificate files or BIOS tools from another HP model, as this could cause boot or BitLocker problems.

 

Haytham Alqolaq
HP Recommended

Hi Haytham,,

 

Thankyou for taking the time to respond. I did contact HP support to try and obtain their procedure for EoSL laptops, but they didn’t supply their procedure andjus directed me to Microft URLs which was were I had started.

HP Recommended

Did you ever find a solution? I am in the same situation, thanks.

HP Recommended

At the moment I am still stuck with this problem and will probably try to open another support case to see if I can get a more responsive support agent to provide the information I actually requested.

HP Recommended

Thx for the reply. Not sure I would waste the time on another support case. I opened 3 support cases on this issue and received zero reponses. Finding it hard to believe HP is just abandoning these devices. I have a lot of HP hardware but after this and my recent experience with one of their 'top of the line' printers, I'm taking my business elsewhere.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.