Windows 10 ESU: Manual Enrollment of UEFI Secure Boot 2023 Certificates on EOL Hardware (HP ProDesk 400 G2 MT)

Don 0 Reputation points
2026-08-23T00:45:04.9966667+00:00

Hello,

I am writing to inquire about the deployment roadmap and manual installation procedures for the new Windows Secure Boot 2023 certificates (UEFICA2023 / Windows UEFI CA 2023) within the UEFI NVRAM environment on older, enterprise-enrolled hardware.

My system is currently running Windows 10 Pro, running natively in UEFI boot mode, and I am an active subscriber to the Extended Security Updates (ESU) program.

Here are my official and detailed system specifications:

- System Manufacturer: Hewlett-Packard (HP)

- System Model: HP ProDesk 400 G2 MT

- OS Version: 10.0.19045 Build 19045 (Version 22H2, OS Build 19045.7663)

- BIOS Version/Date: Hewlett-Packard L02 v02.56, 24/04/2019

The Problem:

The OEM (HP) has officially ceased UEFI firmware support for this specific platform, with the final firmware release dating back to April 2019. Consequently, HP has not included the 2023 Secure Boot keys (Db/Kek) in the default factory NVRAM configurations. The certificate updates have not been pushed to my device via Windows Update, which I suspect is due to a safeguard hold implemented by Microsoft on legacy OEM hardware to prevent catastrophic boot failures.

As an ESU subscriber running on native UEFI, I need to ensure my device remains fully secure during startup.

My specific technical questions are:

1. Since the OEM will not provide a native UEFI firmware update containing the 2023 certificates, when or how will Microsoft deploy the standalone DB/KEK updates to Windows 10 ESU devices with legacy UEFI environments?

2. Is there an officially supported deployment script, PowerShell configuration, or specific registry key override (such as forcing the MicrosoftUpdateManagedOptIn key) that I can safely execute to write the updated 2023 certificates directly into the UEFI NVRAM variables from within Windows?

3. If Windows Update cannot enforce this due to UEFI hardware age, what is the official manual remediation path for standalone enterprise desktops to avoid security compromise when the remaining 2011 certificates fully expire later this year?

Thank you for your technical guidance.

pc11

pc111

Windows for business | Windows Client for IT Pros | Devices and deployment | Install Windows updates, features, or roles
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.