• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended
HP ProDesk 400 G2 MT

Hello HP Community,

 

I am inquiring about the Secure Boot State and updating its security keys/database for my legacy hardware. Some modern security requirements and software require updated Secure Boot signatures, and I want to know if there is an official update or utility to refresh the Secure Boot keys on this specific platform.

 

Please note that this device is officially enrolled in the Windows 10 ESU (Extended Security Updates) program, so ensuring long-term platform security and key compliance is critical for my environment.

 

Here are my exact system technical specifications:
- System Model: HP ProDesk 400 G2 MT (Microtower)
- Processor: Intel(R) Core(TM) i5-4590S CPU @ 3.00GHz
- BIOS Version/Date: Hewlett-Packard L02 v02.56, 24/04/2019
- OS: Windows 10 22H2 (Build 19045.7548) with ESU subscription

 

Is there any recent Secure Boot Database Update Utility or firmware revision that supports refreshing the Microsoft certificates/keys for this 4th Gen Intel motherboard under ESU lifecycle?

 

Thank you for your technical guidance.

1 REPLY 1
HP Recommended

@Unknown136,

 

Welcome to our HP Community forum!

 

The HP ProDesk 400 G2 MT is a business desktop based on Intel's 4th Generation (Haswell) platform.

 

According to the specifications you provided, you are already running the latest HP BIOS (v02.56) for this platform.

 

Unfortunately, HP has not released a standalone Secure Boot database (db/dbx/KEK/PK) update utility for the ProDesk 400 G2 series. On this generation of systems:

 

  • The Secure Boot keys are embedded in the system BIOS/UEFI firmware.
  • The only supported way to update those keys is through an HP BIOS update that contains newer firmware.
  • Since BIOS L02 v02.56 is the final BIOS released for this platform, there are no newer HP firmware packages available that would refresh the Secure Boot certificates.

 

If your BIOS provides the options, you can:

 

  • Restore Factory Secure Boot Keys
  • Clear Secure Boot Keys
  • Load HP Factory Default Keys

 

These actions simply reinstall the factory keys that shipped with the installed BIOS—they do not download newer Microsoft certificates or revocation databases.

 

Regarding your Windows 10 ESU subscription:

 

The Windows 10 Extended Security Updates (ESU) program extends operating system security updates, but it does not update the motherboard's UEFI Secure Boot keys. The firmware and Secure Boot databases remain the responsibility of the system manufacturer (HP).

 

One additional point is worth mentioning. Microsoft has recently distributed Secure Boot DBX (Forbidden Signature Database) updates through Windows Update for supported systems to block vulnerable bootloaders (for example, in response to the BlackLotus vulnerability). These updates are applied by Windows to the UEFI firmware when the platform supports the required update mechanism. However, this is separate from updating the Platform Key (PK), Key Exchange Keys (KEK), or allowed signature database (db), and it does not replace an HP BIOS update.

 

If your goal is simply to verify that Secure Boot is functioning correctly, you can check:

 

  • Secure Boot State in System Information (msinfo32).
  • Or run PowerShell: Confirm-SecureBootUEFI

     
     

    which should return True if Secure Boot is enabled and operational.

 

So, in summary, there is no newer HP Secure Boot key or firmware update available for the HP ProDesk 400 G2 MT. Your system is as up-to-date as HP officially supports with BIOS L02 v02.56, and Windows 10 ESU does not change that.

 

I hope this helps.

 

Kind Regards,

 

NonSequitur777


† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->