• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended

So based on this  https://support.hp.com/us-en/document/ish_13070353-13070429-16 am I correct in thinking that the only HP ProDesk 400 G5 DM has gotten a firmware update with a SBKPFV3 key for the new boot certificates and all other form factors are out of luck. 

I applied this firmware   https://support.hp.com/gb-en/drivers/hp-prodesk-400-g5-small-form-factor-pc/model/21351198?sku=6JZ89...  and yet the SBKPFV3 is missing. 

6 REPLIES 6
HP Recommended

The only suggestion I can offer would be to first check this:

 

Go to Settings>Privacy & Security>Windows Security>Device Security>Secure Boot

 

It provides messaging regarding the new secure boot certificate updates.

 

I have two HP PC's that didn't get the updates, even after trying the method in the link I posted below.

 

I checked the messaging in this new section on my two PC's that did not get the new certificates, and this is what it indicates:

 

Secure boot is on, but your device is affected by a known issue. To reduce risk, Secure Boot certificate updates are temporarily paused while Microsoft and partners work toward a supported resolution. The update will resume automatically once resolved.

 

See if your PC is presenting the same message.

 

If it doesn't show that message, try updating the certificates using the procedure described at the link below.

 

Your Windows Secure Boot Certificates are Expiring Soon: Here's How to Update to the Latest - Make T...

 

It worked for me on 3 different PC's.

HP Recommended

Yes it has that message under secure boot.  When I researched the bios update as far as I remember the G5 SFF was on the supported list and is now missing. 

HP Recommended

We're probably going to have to wait until Microsoft, HP and Intel sort this out.

 

It is not out of the realm of possibility that HP will release a BIOS update to fix whatever is causing the problem because I have a thin client t630 PC that hadn't gotten a BIOS update since May of 2024.

 

Just last month, and I found out earlier this month, HP released a BIOS update in March that installs the 2023 secure boot certificates.

 

 I assumed the PC would never get another BIOS update since it doesn't even meet Microsoft's minimum W11 hardware requirements, processor-wise.

 

HP t630 Thin Client Software and Driver Details

 

- Updates the Microsoft Windows Certificate Authority (CA) for Secure Boot.

HP Recommended

Aren't the registry key edit and the task schedule assuming the boot certificates are present? I ran the Powershell commands to check t if they where present and they  all returned false. 

HP Recommended

The issue is they doing this on the regular patch  Tuesday  so they only have one maybe two shots to sort this out.  I checked again today and there have been no new updates beyond the one from Jan 2026 they have already installed.

HP Recommended

Regarding the registry keys, I don't believe so.

 

I ran those two Powershell commands on 3 different Dell desktop PCs.

 

Two with Intel 4th gen core processors from 2014 and one with an Intel 7th gen core processor from 2017 and the 2023 certificates were installed .

 

The other thing is, not having those certificates installed does not mean the end of the world for many home PC users.

 

When Secure Boot certificates expire on Windows devices - Microsoft Support

 

The key points are:

 

What continues to work:

 

- The device continues to start normally.

 

- Windows updates continue to install, except for boot‑related security components that require the updated certificates.

 

- Everyday app use, networking, browsing, and most OS features remain unchanged.

 

What no longer works

 

- New Secure Boot and Boot Manager protections cannot be applied.

 

- Vulnerability fixes for the early boot environment - such as BitLocker bypass mitigations or Secure Boot revocations - will not be available.

 

- Some third‑party components that rely on Microsoft Secure Boot trust may fail to update if they require newer certificate entries.

 

None of those downsides would seem to have any effect on what I use my PCs for.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->