Secure Boot Security Certificates

Leon E S 20 Reputation points
2026-04-09T22:41:37.8933333+00:00

Secure Boot Security Certificates

User's image

what to do for my hp z640 and hp 440 PCs?

Windows for business | Windows Client for IT Pros | Devices and deployment | Install Windows updates, features, or roles
0 comments No comments

Answer accepted by question author
Domic Vo 30,200 Reputation points Independent Advisor
2026-04-10T00:32:48.1533333+00:00

Hello Leon E S,

For your HP Z640 workstation and HP 440 series PC, the Secure Boot certificate update is handled entirely through HP’s BIOS/firmware packages. The PowerShell check you ran shows that the “Windows UEFI CA 2023” certificate is not present in the current Secure Boot db. That’s expected if the firmware hasn’t yet been updated to include Microsoft’s 2023 Secure Boot certificate authority.

The correct action is to update the BIOS on both systems from HP’s official support site. For the Z640, look under “BIOS” or “Firmware” in the drivers section for your exact product SKU. For the HP 440, do the same by entering the serial number or product ID on HP’s support portal. Once the latest BIOS update is installed, reboot into firmware setup (F10 on HP), confirm Secure Boot is enabled, and re‑run your PowerShell command. If HP has included the updated db in that BIOS release, the command will return True for the Windows UEFI CA 2023 string.

If no BIOS update is available yet for your models, there is no supported way to manually inject the certificate. Microsoft’s documentation makes clear that OEMs are responsible for distributing updated Secure Boot databases. In that case, the best practice is to keep Secure Boot enabled, apply all Windows updates, and monitor HP advisories for when the updated BIOS becomes available.

I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!

Domic Vo.

Was this answer helpful?

0 comments No comments

1 additional answer

Sort by: Most helpful
  1. AI answer

    2026-04-09T22:41:56.1233333+00:00

    For HP business PCs such as the Z640 workstation and ProBook/EliteBook 440, the Secure Boot certificate update is delivered through HP firmware/BIOS updates that add the new 2023 Microsoft Secure Boot certificates before the 2011 certificates expire in 2026.

    For these devices the required actions are:

    1. Follow HP’s specific guidance for Secure Boot certificate readiness
      • HP provides model‑specific instructions and BIOS/firmware versions that contain the updated Secure Boot certificates.
      • Use HP’s support article “HP PCs - Prepare for new Windows Secure Boot certificates” to look up the exact steps and required BIOS versions for HP Z‑series workstations and HP 4xx series PCs.
    2. Update system BIOS/firmware on each HP PC
      • From HP’s Secure Boot support page, locate the entries for HP Z640 and HP 440 (or their platform families) and install the recommended BIOS/UEFI firmware update packages.
      • Apply the BIOS update using HP’s recommended method (HP Support Assistant, HP Image Assistant, or manual BIOS flash) and reboot as instructed so the firmware updates the Secure Boot databases (KEK/DB/DBX) with the 2023 Microsoft certificates.
    3. Verify Secure Boot and certificates after the HP update
      • Ensure Secure Boot is enabled in the HP BIOS after the firmware update.
      • Then use the Windows tools (such as the WinCS API/CLI and PowerShell cmdlets referenced in the Secure Boot certificate update guidance) to confirm that the new 2023 Microsoft certificates are present in the KEK and DB and that the 2011 certificates are no longer solely relied upon.

    If any HP device does not yet have an HP‑provided BIOS that includes the 2023 certificates, monitor HP’s Secure Boot support page for that model and plan to deploy the HP firmware update as soon as it becomes available so that the device remains compliant when the 2011 certificates start expiring in June 2026.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.