Unsolved
1 Rookie
•
14 Posts
2
390
July 30th, 2025 15:44
XPS 8950, Secure Boot Certificate update
I have a Dell XPS 8950 just updated to BIOS 1.26 (dated may 2025). I need to know if the Dell BIOS will get the updates Secure Boot Certificates installed or if Windows has to install it through Windows Updates? I know the BIOS is made AMI. The current certificates are set to expire next summer. Please advise how this will work. Thank you
No Events found!



RichardWrightGeorgeOrwellJohnSteinbeck
1 Rookie
•
1 Message
0
August 14th, 2025 23:22
I have this same issue but I am on an XPS 8940.
I see that there is a feature in the UEFI to load these secure boot keys myself. If I can fix this security issue myself, I want to do it manually and not wait for the UEFI update.
Is this possible to do myself?
I have followed the official instructions to check the BIOS updates for the key phrase "This BIOS contains the new 2023 Secure Boot Certificates" in the Important Information section of these updates. None of the "BIOS" (UEFI) updates for my device indicate that they include these certificates so far.
https://www.dell.com/support/kbdoc/en-us/000347876/microsoft-2011-secure-boot-certificate-expiration
I've already followed Microsoft's official instructions to update the db key via a registry edit, the restarting of a service, and two reboots as listed here: https://techcommunity.microsoft.com/blog/windows-itpro-blog/updating-microsoft-secure-boot-keys/4055324
Upon completion the command "[System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match ‘Windows UEFI CA 2023’" returns "True" indicating that the db key was successfully updated.
(edited)
Charlie84
1 Rookie
•
5 Posts
0
October 30th, 2025 01:00
@RichardWrightGeorgeOrwellJohnSteinbeck - If that's all you did, you only added the updated 2023 database (db) but you didn't revoke the existing database and activate the new one.
Open Windows Event Viewer and wait until Summary of Administrative Events box gets populated. It might take ~1-2 min depending on how many events have been logged.
Expand list under Errors and scroll down looking for Event ID 1801 with Source TPM-WMI. If it's there you'll see this when you open it:
Secure Boot CA/keys need to be updated...
I did exactly what you did and got true in response to the PowerShell query:
"[System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match ‘Windows UEFI CA 2023’", but still get a new event 1801 logged at every boot.
So just updating the db isn't sufficient. There are steps to do the next step for updating dbx online. Those steps require the latest BIOS for whichever PC model and it has to support manual updating. Manual updating can be risky if BIOS doesn't fully support it, and could brick the motherboard. We also don't know if Dell will release new versions with new security keys already included for models that are "end of life".
The safest thing may be just to keep waiting and see if Windows Update rolls out automatic key updates for older BIOS...
85rx7gslse
1 Rookie
•
14 Posts
0
November 14th, 2025 15:35
@Charlie84 I just checked at Dell Support and for the XPS8950 it is now BIOS 1.29.0 which says in the details that it now has the updated Secure Boot Keys .. There is also a new BIOS for the XPS8960 with updated keys (version number is different)
Charlie84
1 Rookie
•
5 Posts
0
November 29th, 2025 21:05
Unfortunately, mine is XPS 8930 and Dell hasn't released new BIOS since 2023. Probably won't release another one since it's long past its End of Life, even though Dell supports it with Win 11.
Hopefully, Windows Update will eventually release an update for the secure boot keys.
Bell98
1 Rookie
•
18 Posts
0
January 5th, 2026 11:26
I've the 2019 released Alienware Aurora R10 and it doesn't appear to be supported in the Alienware list. The Bot want me to pay £40 for a "Yes it will be supported" / "No it won't" when all these are listed for free.
Alienware
Alienware 16 Area-51 AA16250Alienware 16 Aurora AC16250Alienware 16X Aurora AC16251Alienware 18 Area-51 AA18250Alienware Area-51 AAT2250Alienware Aurora ACT1250Alienware Aurora R13Alienware Aurora R15Alienware Aurora R15 AMDAlienware Aurora R16Alienware Aurora Ryzen Edition R14Alienware m15 R6Alienware m15 R7Alienware m15 R7 AMDAlienware m15 Ryzen Edition R5Alienware m16 R1Alienware m16 R1 AMDAlienware m16 R2Alienware m17 R5 AMDAlienware m18Alienware m18 R1Alienware M18 R2Alienware x14Alienware x14 R2Alienware x15 R1Alienware x15 R2Alienware x16 R1Alienware X16 R2Alienware x17 R1Alienware x17 R2(edited)
Pirutgrrrl
1 Rookie
•
2 Posts
0
January 14th, 2026 19:37
85rx7gslse I updated to this BIOS (1.29.0) on my 8950 but I don't see that it updated the secure boot key when running checks.
Bell98
1 Rookie
•
18 Posts
0
January 15th, 2026 09:42
It looks as if the Key updates might be coming from Microsoft in a Windows update. Dell are dragging their knuckles.
Dell Tech support varies with 1 person - very kind and understanding to "JUST GIVE US YOUR MONEY TO SORT OUT DELL'S PROBLEM"
This is from Microsoft.
https://learn.microsoft.com/en-gb/windows-hardware/manufacture/desktop/windows-secure-boot-key-creation-and-management-guidance?view=windows-11#14-signature-databases-db-and-dbx
Dell not even issuing "We're working on the following machines" and I also would understand "Unfortunately these machines are too old for updating". Dell's policy is "silence is golden".
I've got a new machine personalised for me sitting in a company's basket. The support for my machine has been dreadful with Dell's dreadful software. No updates for chipset after 4 years. AMD didn't recognise their own processor it appears to be a bodge that Dell bought - AMD Ryzen 9 5900 the preferred model number is 5900X but AMD were very helpful - no charge.
Now this.
I'm lucky I can afford to buy a fresh machine.
(edited)
Bell98
1 Rookie
•
18 Posts
0
January 15th, 2026 10:22
@Bell98 P.S. For the same price as one question to Dell support on a Dell issue, I'm getting 3 years support with the new computer.