• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
Check out our WINDOWS 11 Support Center info about: OPTIMIZATION, KNOWN ISSUES, FAQs, VIDEOS AND MORE.
HP Recommended

I have updated to the latest bios from HP for the HP Z2 G5 Workstation (01.04.20 from around September) and I have used the bios option to 'Reset Secure Boot keys to factory defaults' but the new Microsoft Secure Boot certificates from 2023 have not been put in place yet.  I have also seen the Windows can install the certificates with registry keys if the BIOS supports the new 'SBKPFV3' string.  I am running a Linux OS though so that will not help (RHEL 10 ).

I see mentions of using RHEL's fwupdmgr but it appears that HP does not publish their updates to that.

How can we get the new certificates added manually or is there yet a newer BIOS update that will have the new certificates so that when we reset the secure boot certificates, they will be updated?

Olde certificates are still in place...

root@desktop1:/root# mokutil --db --short
f6071c13ca HP UEFI Secure Boot DB 2017
580a6f4cc4 Microsoft Windows Production PCA 2011
46def63b5c Microsoft Corporation UEFI CA 2011

BIOS version...
root@desktop1:/root# dmidecode|grep '01.04.20'
Version: S50 Ver. 01.04.20




† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.