Secure boot is on but device is using an older boot trust configuration that should be updated. There is not enough information for automatic update

Ludo 0 Reputation points
2026-06-15T10:51:51.07+00:00

Nearly new Dell machine running windows 11 pro and after setting up including applying bios and windows updates get the message in the subject above.

Dell say this is a Microsoft issue. I’ve checked updates and there is nothing to apply.

I’ve also used the PowerShell commands to check if the certificates are in place.

The uefi ca 2023 comes back as true but kek 2k ca 2023 is false.

I believe this expires on 24 June so concerned that this may impact the security of a new machine going forward if not resolved especially as the next windows update will typically be after this expiry.

Any assistance would be much appreciated

Windows for home | Windows 11 | Windows update
0 comments No comments

2 answers

Sort by: Most helpful
  1. DaveM121 905.8K Reputation points Independent Advisor
    2026-06-15T11:29:32.1333333+00:00

    You cannot manually update the Secure Boot Certificates yourself, if you have ensured your BIOS and firmware is fully up to date that is all you need to do, the new Secure Boot Certificates will be applied by Windows udpates automatically, Microsoft have only started releasing the updates in the May and June updates, they indicate they will continue to release the certificate updates over the next few months.

    This is the information they provide.

    Secure Boot Certs

    Was this answer helpful?

    2 people found this answer helpful.

  2. AI answer

    2026-06-15T10:52:11.18+00:00

    The message indicates that Secure Boot is enabled, but the device is still using the older 2011 Secure Boot certificates and is missing at least the Microsoft Corporation KEK 2K CA 2023 entry. This does not stop the PC from working or receiving normal Windows updates, but it does mean it cannot get future boot‑level security protections until the KEK is updated.

    Key points from current behavior:

    • The Windows UEFI CA 2023 certificate is present (UEFI CA 2023 = True), so the boot loader can be validated with the new 2023 Windows certificate.
    • The KEK 2K CA 2023 certificate is missing (False). KEK signs updates to the Secure Boot DB/DBX, so without it the platform trust anchors are not fully updated.
    • When the older 2011 certificates start expiring in June 2026, devices that do not have the 2023 certificates will:
      • Continue to boot and operate normally.
      • Continue to receive standard Windows updates.
      • Not be able to receive new Secure Boot / Boot Manager protections, revocation list updates, or mitigations for new boot‑level vulnerabilities.

    For a nearly new OEM device, the expected path is:

    1. OEM firmware (BIOS/UEFI) update
      • The KEK and DB certificates are stored in firmware. For many systems, the OEM must ship a firmware update that adds Microsoft Corporation KEK 2K CA 2023 and the other 2023 CAs.
      • Ensure the latest Dell UEFI/BIOS is installed. If already on the latest version and KEK 2K CA 2023 is still missing, this is typically an OEM firmware gap that Dell must address.
    2. Windows‑side Secure Boot updates
      • Once the firmware contains the 2023 CAs, Windows can apply boot‑manager and Secure Boot DB/DBX updates that rely on those new certificates.
      • Microsoft is rolling these updates to supported Windows 10/11 versions; devices that share diagnostic data and are “managed by Microsoft” are updated automatically where possible.
    3. Impact if KEK is not updated by the 2011 expiry
      • The device will still start and run apps normally.
      • Windows Update will still work, except for new boot‑related security components that require the updated KEK.
      • Over time, the device becomes less protected against new boot‑level threats, and scenarios that depend on Secure Boot trust (BitLocker hardening, boot‑level code integrity, some third‑party bootloaders/option ROMs) may be affected.

    Recommended actions in this situation:

    1. Confirm that:
      • Windows 11 is fully updated (Settings → Windows Update → Check for updates).
      • The latest Dell BIOS/UEFI is installed.
    2. If KEK 2K CA 2023 remains missing after all updates:
      • Treat this as a firmware issue that Dell must resolve with a new BIOS/UEFI release that includes Microsoft Corporation KEK 2K CA 2023 in the KEK store.
      • Reference Microsoft’s public guidance on Secure Boot certificate expiration when working with Dell support so they understand this is about updating the platform trust anchors, not a Windows configuration problem.
    3. Do not disable Secure Boot as a workaround. Disabling Secure Boot reduces protection and is explicitly not recommended as a response to certificate expiration.

    Until Dell provides firmware that includes KEK 2K CA 2023, the device will continue to function but will not be able to consume future Secure Boot/boot‑manager security updates that depend on the new KEK.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.