Unsolved

1 Rookie

 • 

14 Posts

 • 

37 Points

421

June 12th, 2026 04:28

Applying 2023 Secure Boot Certificates to Dell XPS 8700

I have a Dell XPS 8700 running Windows 10 64-bit. I plan on adding Windows 11 later this year. Been having an issue with File Explorer (something for a later post) and noticed the warning in Event Viewer for expiration of the Secure Boot Certificates. Looks like I have two options: (1) Download and install Microsoft KB5072033 or (2) modify registry keys.

From what I've been reading, it looks like using the wrong method can really screw things up. So,

Can anyone confirm which method will work for XPS 8700?

11 Legend

 • 

16K Posts

 • 

81.8K Points

June 12th, 2026 13:03

There are standard Windows update powershell commands that will install three out of four secure boot certificates smoothly.

We found the 4th certificate KEK is difficult due to Dell not submitting old model private key to Microsoft.

10 Wizard

 • 

17.9K Posts

 • 

71.2K Points

June 12th, 2026 19:11

I have a Dell XPS 8700 running Windows 10 64-bit.

1. I plan on adding Windows 11 later this year.

2. noticed the warning in Event Viewer for expiration of the Secure Boot Certificates. Looks like I have two options: (1) Download and install Microsoft KB5072033 or (2) modify registry keys.

3. From what I've been reading, it looks like using the wrong method can really screw things up. So,

4. Can anyone confirm which method will work for XPS 8700?

1. You are going to force-install Windows-11 onto your XPS-8700? Interesting.

2. Sounds old. Are you sure XPS-8700 is even UEFI-class? Do you run it Secure-Boot Enabled? If you run msinfo32, does it say SecureBoot State is ON?

3. You read correctly, like this:

https://www.dell.com/community/en/conversations/xps-desktops/xps-8930-bios-update-with-secure-boot/6a25f88c205c2e50bf498a3a?commentId=6a2b5afa127a263c5dcaa9b0

 

4. I've been recommended that everyone start here (so we can all see what we are dealing with)

 

https://www.dell.com/community/en/conversations/xps-desktops/xps-8930-purchased-2018-2023-secure-boot-certificates/699cdb010daada5e7a6c379f?commentId=6a1a2ebe5e24e611a5a521fc

isProTip

1 Rookie

 • 

14 Posts

 • 

37 Points

June 14th, 2026 13:49

@Tesla1856​ 

1) Yes. It will be interesting. I'm running the 'server install' successfully on an old laptop, but it appears that TPM (available on the laptop, but not on XPS 8700) could be the clincher.

2) Yes to UEFI and Secure Boot is on. But, as in #1, lack of TPM is creating havoc during updates.

3) Not sure what you are referring to in this one. That is a thread for XPS 8930; newer model that 8700, so TPM is available and some drivers still supported by Dell. So, not really relevant here. Again, really looking for someone who's done this on the 8700.

4) Again, really hoping to find someone with an 8700 who has successfully done this. You'd be surprised how many 8700's are still around being used as gaming machines. But, I'll take a look at your link and see what might apply. Maybe it will point me to a thread somewhere with an 8700.

1 Rookie

 • 

14 Posts

 • 

37 Points

June 14th, 2026 13:51

@redxps630​ 

Could you provide a link to information on using powershell commands for this? Did a search, but only found AI generated stuff, which I have learned never to use unless you have the smarts to generate it yourself.  ;-)

1 Rookie

 • 

14 Posts

 • 

37 Points

June 14th, 2026 14:22

I have been to the GitHub site and run the Check UEFI PK, KEK, DB and DBX.cmd as indicated in the post referred by Tesla1856 (and possibly the Powershell commands noted by redxps630). Here are the results, though as near as I can tell, it basically says I don't have the 2023 certificates. The post that this came from indicated that other commands should not be run unless you know what you're doing, so again, would really like to hear from XPS 8700 owner if one's out there.

HW : Dell Inc. - XPS 8700 - AMD64/X64
FW : Dell Inc. - A14 - 31 May 2019
OS : Windows 10 - 22H2 (Build 19045.7417)

Detected AMD64/X64 UEFI architecture. Ensure that this is correct for valid DBX results.

Secure Boot status: Enabled

Current UEFI PK
√ DO NOT TRUST - AMI Test PK

Default UEFI PK
WARNING: Failed to query UEFI variable PKDefault

Current UEFI KEK
√ Microsoft Corporation KEK CA 2011 (revoked: False)
X Microsoft Corporation KEK 2K CA 2023

Default UEFI KEK
WARNING: Failed to query UEFI variable 'KEKDefault' for cert 'Microsoft Corporation KEK CA 2011'
WARNING: Failed to query UEFI variable 'KEKDefault' for cert 'Microsoft Corporation KEK 2K CA 2023'
WARNING: Failed to query UEFI variable 'KEKDefault'

Current UEFI DB
√ Microsoft Windows Production PCA 2011 (revoked: False)
√ Microsoft Corporation UEFI CA 2011 (revoked: False)
√ Windows UEFI CA 2023 (revoked: False)
X Microsoft UEFI CA 2023
√ Microsoft Option ROM UEFI CA 2023 (revoked: False)

Default UEFI DB
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft Windows Production PCA 2011'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft Corporation UEFI CA 2011'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Windows UEFI CA 2023'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft UEFI CA 2023'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft Option ROM UEFI CA 2023'
WARNING: Failed to query UEFI variable 'DBDefault'

Current UEFI DBX
2026-06-09 [AMD64]          : FAIL: 154 failures, 289 successes detected
Windows BootMgr SVN         : Not applied
Windows CDBoot SVN          : Not applied
Windows WDSMgFw SVN         : Not applied
Statistics                  : 16696 Bytes, 342 SHA256 hashes, 0 X.509 certs, 0 SVNs

11 Legend

 • 

16K Posts

 • 

81.8K Points

June 14th, 2026 15:11

(edited)

1 Rookie

 • 

14 Posts

 • 

37 Points

June 14th, 2026 15:35

@redxps630​ 

Thanks for the info on the Powershell commands. I blew right past that area because it was labeled as "testing". Found it though. A couple of questions.

1) Followed one of links to what displays and noted something about TPM. As noted in previous posts, XPS 8700 has no TPM. Does this mean that the security certificates cannot be updated?

2) You noted in your initial post:

We found the 4th certificate KEK is difficult due to Dell not submitting old model private key to Microsoft.

How did you resolve this - or were you unable to update the XPS 8700 successfully?

11 Legend

 • 

16K Posts

 • 

81.8K Points

June 14th, 2026 15:49

you can have a Secure Boot update without a TPM. Secure Boot is a feature built into your motherboard's UEFI firmware that verifies the digital signatures of boot files. A TPM (Trusted Platform Module) is a separate security chip on motherboard used for encrypting data.


Secure Boot ensures your system only runs trusted software during startup, while a TPM is used to secure sensitive data (like BitLocker keys)


Secure Boot relies entirely on UEFI and the cryptographic keys embedded in your motherboard. It does not require a physical or firmware-based TPM to function.

(edited)

11 Legend

 • 

16K Posts

 • 

81.8K Points

June 14th, 2026 15:53

I was not able to use all the methods from research and help from senior experienced user like tesla to successfully deploy KEK 2023 in Dell Optiplex 7010.  I can test my 8700 when I have time 

1 Rookie

 • 

14 Posts

 • 

37 Points

June 14th, 2026 16:24

@redxps630​ 

Thanks for the info. I'll keep plugging along. I've got to fix a problem with the system freezing after every Windows Update -- pretty sure I've got that narrowed down to some sort of TPM requirement that's gumming up the works. If I find something before you do, I will post.

Again, thanks for the point to manual. That will be helpful.

10 Wizard

 • 

17.9K Posts

 • 

71.2K Points

June 14th, 2026 16:53

@lilyb88​ ,

 

I have been to the GitHub site and run the Check UEFI PK, KEK, DB and DBX.cmd as indicated in the post referred by Tesla1856

This can be the XPS-8700 thread for CA-2023 Evaluation (for you and others).

Yes, that is the proper one to run first. Be sure you are running the latest version of the script-package. Post a proper image/picture of your Report here in your XPS-8700 thread.

The instructions are here:

https://www.dell.com/community/en/conversations/xps-desktops/xps-8930-purchased-2018-2023-secure-boot-certificates/699cdb010daada5e7a6c379f?commentId=6a1a2ebe5e24e611a5a521fc

(edited)

10 Wizard

 • 

17.9K Posts

 • 

71.2K Points

June 14th, 2026 18:37

@lilyb88

@Tesla1856​ 

1) Yes. It will be interesting. I'm running the 'server install' successfully on an old laptop, but it appears that TPM (available on the laptop, but not on XPS 8700) could be the clincher.

2) Yes to UEFI and Secure Boot is on. But, as in #1, lack of TPM is creating havoc during updates.

3) Not sure what you are referring to in this one. That is a thread for XPS 8930; newer model that 8700, so TPM is available and some drivers still supported by Dell. So, not really relevant here. Again, really looking for someone who's done this on the 8700.

4) Again, really hoping to find someone with an 8700 who has successfully done this. You'd be surprised how many 8700's are still around being used as gaming machines. But, I'll take a look at your link and see what might apply. Maybe it will point me to a thread somewhere with an 8700.

Sorry, I did not see this message earlier, so I will respond now. 

 

1. Acknowledged. Yes, the "Server Install Method" is what I have been using as well. No Rufus or anything like that. Even worked on my (non UEFI) Aurora-R1. With a Intel-i7/GTX-1070/SSD it is still a viable computer.

 

2. UEFI-class but no TPM huh?  Interesting. I'm sure I have some like that but I have not done CA-2023 Evaluations on them. Between doing all my newer computers (desktops and laptops), soft-bricking our nice XPS-15 laptop with a casual firmware upgrade, and helping yall with yours ... I kinda got burnt-out and had to stop.

3. We were talking about "the wrong method can really screw things up" and that XPS-8930 owner hit the SecureBoot Security-Violation red-box.

 

4. I think you will be the first. And truthfully, it takes someone at your skill-level to figure out if it's even possible. It's very easy to get derailed along the way. 

(edited)

11 Legend

 • 

16K Posts

 • 

81.8K Points

June 15th, 2026 00:52

I report when I do the following update command in power shell command on a XPS 8700, it freezes mouse each time.  I have to hard shut down the pc.  this freeze is reproducible in 8700.

Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

on the other hand, a single power shell command of update is sufficient to inject Windows UEFI 2023 and Windows optional ROM 2023 into CMOS, notwithstanding the freeze issue.  I confirm when I reset 8700 cmos, both updates are gone.  

the Microsoft UEFI 2023 and KEK 2023 are not injected by the above command.

(edited)

3 Novice

 • 

92 Posts

 • 

420 Points

June 15th, 2026 02:43

@lilyb88​ Have you seen ‎XPS 8910 and the nightmare of June 2026 secure boot update | DELL Technologies ? Maybe you just need to disable the Secure-Boot-Update task in the Task Scheduler too?

1 Rookie

 • 

14 Posts

 • 

37 Points

June 15th, 2026 17:07

@gartaud​ 

Hey there. You are correct. In reviewing posts as far back as December of 2025, the update task has caused freezing on the XPS. In fact, my system kept freezing back then (before I knew about the certificate stuff), and I finally gave up and did a fresh install of Windows 10. That worked for a while, but it resurfaced again (not surprisingly) at the end of May. I pieced together what you just did (in a fraction of the time) and disabled the update task. That has somewhat diminished the havoc it was wreaking on the system files.

No Events found!

Top