Hello Leon E S,
For your HP Z640 workstation and HP 440 series PC, the Secure Boot certificate update is handled entirely through HP’s BIOS/firmware packages. The PowerShell check you ran shows that the “Windows UEFI CA 2023” certificate is not present in the current Secure Boot db. That’s expected if the firmware hasn’t yet been updated to include Microsoft’s 2023 Secure Boot certificate authority.
The correct action is to update the BIOS on both systems from HP’s official support site. For the Z640, look under “BIOS” or “Firmware” in the drivers section for your exact product SKU. For the HP 440, do the same by entering the serial number or product ID on HP’s support portal. Once the latest BIOS update is installed, reboot into firmware setup (F10 on HP), confirm Secure Boot is enabled, and re‑run your PowerShell command. If HP has included the updated db in that BIOS release, the command will return True for the Windows UEFI CA 2023 string.
If no BIOS update is available yet for your models, there is no supported way to manually inject the certificate. Microsoft’s documentation makes clear that OEMs are responsible for distributing updated Secure Boot databases. In that case, the best practice is to keep Secure Boot enabled, apply all Windows updates, and monitor HP advisories for when the updated BIOS becomes available.
I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!
Domic Vo.