• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended

My Z440 Workstation is in UEFI mode and secure boot is on. The BIOs is M60 v02.61 03/23/2023. The OS is Windows 10 with recent Windows updates.

 

The following command returned "False" : [System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match 'Windows UEFI CA 2023'

 

The following commands continue to return "InProgress" after 24 hours: reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x5944 /f Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

Device security displays the message "Secure boot certificate updates are temporarily paused while Microsoft and partners work towards a supported resolution. Contact your device manufacturer."

 

Please advise on HP's progress as a partner working toward a supported resolution. Please provide instructions on how to proceed with enabling the 2023 secure boot certificates on this Z440.

1 ACCEPTED SOLUTION

Accepted Solutions
HP Recommended

@rickmurphy,

 

Your system appears to be affected by the temporary Microsoft/OEM hold on the Secure Boot 2023 certificate rollout rather than by a configuration problem on your workstation.

 

The Windows Security message, quote: "Secure boot certificate updates are temporarily paused while Microsoft and partners work toward a supported resolution."

 

-is generated by Microsoft when a device falls into a group for which the certificate update has been intentionally paused while firmware compatibility issues are being addressed. Microsoft states that the update will resume automatically once a supported solution is available.

 

I would recommend the following:

 

  1. Firstly, update the workstation BIOS from M60 v02.61 to the current v02.62 (SP151054), as Microsoft recommends installing the latest OEM firmware before attempting the Secure Boot certificate update. Firmware updates may include the changes needed to support the new Secure Boot trust configuration.
  2. Install all available Windows updates.
  3. Reboot the workstation several times after the BIOS update.
  4. Re-run your PowerShell command to verify whether Windows UEFI CA 2023 is present.

 

If the Device Security page still reports that the certificate update is temporarily paused after updating to BIOS v02.62, then there is likely nothing further you can do at this time. The rollout is controlled jointly by Microsoft and the OEM, and Microsoft indicates that affected devices will receive the update automatically once the compatibility issue has been resolved.

 

Kind Regards,

 

NonSequitur777


View solution in original post

5 REPLIES 5
HP Recommended

@rickmurphy,

 

Your system appears to be affected by the temporary Microsoft/OEM hold on the Secure Boot 2023 certificate rollout rather than by a configuration problem on your workstation.

 

The Windows Security message, quote: "Secure boot certificate updates are temporarily paused while Microsoft and partners work toward a supported resolution."

 

-is generated by Microsoft when a device falls into a group for which the certificate update has been intentionally paused while firmware compatibility issues are being addressed. Microsoft states that the update will resume automatically once a supported solution is available.

 

I would recommend the following:

 

  1. Firstly, update the workstation BIOS from M60 v02.61 to the current v02.62 (SP151054), as Microsoft recommends installing the latest OEM firmware before attempting the Secure Boot certificate update. Firmware updates may include the changes needed to support the new Secure Boot trust configuration.
  2. Install all available Windows updates.
  3. Reboot the workstation several times after the BIOS update.
  4. Re-run your PowerShell command to verify whether Windows UEFI CA 2023 is present.

 

If the Device Security page still reports that the certificate update is temporarily paused after updating to BIOS v02.62, then there is likely nothing further you can do at this time. The rollout is controlled jointly by Microsoft and the OEM, and Microsoft indicates that affected devices will receive the update automatically once the compatibility issue has been resolved.

 

Kind Regards,

 

NonSequitur777


HP Recommended

Thanks much NonSequitur777. BIOS now updated to v02.62.  I will watch for Windows updates over the next few days and execute the secure boot commands again. I will check back with HP. Thanks for your expert help. 

HP Recommended

@rickmurphy,

 

You are most welcome -glad to be of assistance!

 

Yes, the HP Z440 Workstation remains one of my most favorite legacy upgrade projects, for sure.

 

Btw, have you upgraded your Z440's TPM 1.2 to TPM 2.0 yet?

 

Kind Regards,

 

NonSequitur777


HP Recommended

Thank you for asking about the upgrade to TPM 2.0. 

 

I am currently studying the issue and would appreciate your opinion.

 

I use the Z440 exclusively to record music in my music studio. A few years ago I decided to retain my Protools perpetual license which locks me into Protools 12.x. Avid offered users a choice : 1) retain your perpetual license without the opportunity to upgrade, or 2) surrender the perpetual license and pay periodically under their new subscription scheme.

 

Protools 12.x is certified compatible with Windows 10.  I need to preserve that configuration for the forseeable future. I may never install Windows 11 on the Z440. The Z440 rarely connects to the Internet. 

 

Given this scenario I'm trying to understand the risk of not upgrading TPM 2.0.

 

Are you aware of any risk that if I were to avoid the upgrade that I would loose access to the Z440 and be prevented from booting the machine? 

 

Thanks in advance.

 

--

rick

 

 

 

 

HP Recommended

@rickmurphy,

 

There is no risk not updating TPM 1.2 to TPM 2.0.

 

Truth be told, I did it because that upgrade was available -nothing more, nothing less.  Because I used the clever Windows Server W11 bypass method -which doesn't require TPM 2.0, the TPM upgrade didn't make any difference whatsoever.

 

Chances are overwhelming that you don't need TPM 2.0, so you could leave things as they are!

 

Kind Regards,

 

NonSequitur777


† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->