-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
- HP Community
- Desktops
- Desktop Boot and Lockup
- Re: HP ProDesk 600 G4 SFF BIOS Update for 2023 Secure Boot C...

Create an account on the HP Community to personalize your profile and ask a question
03-20-2026
08:19 PM
- last edited on
03-24-2026
04:00 AM
by
Raj_05
PC is a HP ProDesk 600 G4 SFF, Product: 2VG42AV, Serial: Edited
I applied the registry key to force the Secure Boot Certificate update
"reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x40 /f"
The Event log shows the error "The Secure Boot update Windows UEFI CA 2023 (DB) was blocked due to a known firmware issue on the device. Check with your device vendor for a firmware update that addresses the issue."
This support page says that "HP PCs released between 2018 to 2021 received a BIOS update on or around December 31, 2025." for the new Windows Secure Boot certificates
https://support.hp.com/us-en/document/ish_13070353-13070429-16
As the HP ProDesk 600 G4 SFF was released in 2018, there should be a Bios update available
My PC has Bios HP Q07 v02.30.00 30/12/2024 installed
HP Support shows Bios v02.21.00 Rev.A Nov 08 2022 (i.e. older) for download
Does anyone know if an updated Bios has been released and if so where I might get it?
Thanks
Solved! Go to Solution.
Accepted Solutions
03-22-2026 09:48 AM
No one here can tell you when a new BIOS update will be released, so I recommend checking for updates using the following application
03-21-2026 12:49 PM
Hi @nige0090
You already have the latest version of the BIOS installed.
https://ftp.hp.com/pub/softpaq/sp156501-157000/sp156641.html
https://ftp.hp.com/pub/softpaq/sp156501-157000/sp156641.exe
If your BIOS is compatible with the certificate, you should receive an update via Windows Update. The file name is as follows: : Secure Boot Allowed Key Exchange Key (KEK) Update
Without that update, you won't be able to use the new Windows certificate.
03-21-2026 07:40 PM
Hi @Resistencia,
Thanks for the reply.
My event log has the two items...
1801 Updated Secure Boot certificates are available on this device but have not yet been applied to the firmware.
1802 The Secure Boot update Windows UEFI CA 2023 (DB) was blocked due to a known firmware issue on the device.
So the new certificates are available but are "blocked due to a known firmware issue on the device."
HP have said that a Bios update should be available on or around December 31, 2025, for the new certificates.
When will a Bios update be released to fix this blocking firmware issue?
Thanks
03-22-2026 09:48 AM
No one here can tell you when a new BIOS update will be released, so I recommend checking for updates using the following application