UNSOLVED

beebo.dell

updated

2 months ago

BD

beebo.dell

1 Rookie

4 Posts

13 Points

0

251

July 1st, 2026 19:45

Optiplex 7020 boot certificate

hello dears

this is first post for me here, and hope i get support.

i've optiplex 7020 disktop,

how i update secure boot certificate?

windows update shows this message

Secure Boot is on, but your device does not support the automated Secure Boot certificate update due to hardware or firmware limitations. Contact your device
manufacturer for assistance. 

 what shall we do now to fix it?

also, could I buy external tpm chip as my device doesn't have one?

  thanks

  • Tesla1856

    10 Wizard

    17985 Posts

    71600 Points

    0

    0

    Posted July 1st, 2026 20:05

    Do this and post the picture of the report here in your thread:

    https://www.dell.com/community/en/conversations/xps-desktops/xps-8930-purchased-2018-2023-secure-boot-certificates/699cdb010daada5e7a6c379f?commentId=6a1a2ebe5e24e611a5a521fc

    I'll take a look at it for you and advise.

    Edit:

    Yeah, you need to running the latest published BIOS-Firmware for your computer. And I think Windows-11 as we are not really doing all this work for computers locked-back-at Windows-10. Of course, computer must be UEFI-class.

    (edited)

    Dell Rockstar

    Microsoft Windows and Apple iOS Developer (Retired)
    - Like many of you, I can appreciate a good game-engine.
    - I answer questions here, but I'm not a Dell employee.
    - Consider giving posts you like a "thumbs-up"
    - Posting models-numbers and software versions speeds trouble-shooting.
    - Click "Mark as Accepted Answer" on any post that answers your question best.

  • ejn63

    12 Elder

    31437 Posts

    155038 Points

    0

    0

    Posted July 1st, 2026 20:05

    No, there's no way to fit an external TPM -- if the system doesn't have the TPM (and if this is the 2012-vintage 7020, even if it does it's so far out of date it's essentially useless for Windows 11), that cannot be added.

    Dell won't have updates including the 2023 secure boot certificates.  You may or may not be able to add them manually -- see

    https://www.dell.com/support/kbdoc/en-us/000473343/windows-secure-boot-certificate-ca23-update-service-guidance

  • anne_droid

    5 Journeyman

    2073 Posts

    7698 Points

    0

    0

    Posted July 2nd, 2026 08:15

    Hi

    Can you please give the current operating system that is running, the current BIOS and the year of manufacture?

    Please can you confirm the Make Model and OS, along with any configuration details like touch screen, backlit keyboard, SFF or tower etc etc.

      Kind Regards  

                                         

      anne_droid

  • beebo.dell

    1 Rookie

    4 Posts

    13 Points

    0

    0

    Posted July 2nd, 2026 10:09

    hello dear

    thanks for your reply.

    would you please, which tool i should use to share needed report? and wish it could be accessible with screenreader.

    and could i just coppy info not share as image?

    system info:

    [System Summary]

    OS Name Microsoft Windows 10 Pro 
    Version 10.0.19045 Build 19045 
    System Manufacturer Dell Inc. 
    System Model OptiPlex 7020 
    System SKU 05A5 
    Processor Intel(R) Core(TM) i5-4570 CPU @ 3.20GHz, 3201 Mhz, 4 Core(s), 4 Logical Processor(s) 
    BIOS Version/Date Dell Inc. A09, 5/18/2016 
    SMBIOS Version 2.7 
    Embedded Controller Version 255.255 
    BIOS Mode UEFI 
    BaseBoard Manufacturer Dell Inc. 
    BaseBoard Product 08WKV3 
    BaseBoard Version A01 
    Secure Boot State On 
    PCR7 Configuration Binding Not Possible 

      thanks

  • beebo.dell

    1 Rookie

    4 Posts

    13 Points

    0

    0

    Posted July 2nd, 2026 10:10

    @anne_droid​ hello 

    thanks for your reply

    [System Summary]

    OS Name Microsoft Windows 10 Pro 
    Version 10.0.19045 Build 19045 
    System Manufacturer Dell Inc. 
    System Model OptiPlex 7020 
    System SKU 05A5 
    Processor Intel(R) Core(TM) i5-4570 CPU @ 3.20GHz, 3201 Mhz, 4 Core(s), 4 Logical Processor(s) 
    BIOS Version/Date Dell Inc. A09, 5/18/2016 
    SMBIOS Version 2.7 
    Embedded Controller Version 255.255 
    BIOS Mode UEFI 
    BaseBoard Manufacturer Dell Inc. 
    BaseBoard Product 08WKV3 
    BaseBoard Version A01 
    Secure Boot State On 
    PCR7 Configuration Binding Not Possible 

    let me know if you need another info.

      thanks

  • anne_droid

    5 Journeyman

    2073 Posts

    7698 Points

    0

    0

    Posted July 2nd, 2026 11:13

    Hi

    Thank for the info, more pieces in the blank jigsaw I have for a brain.

    There are newer BIOS versions....

    A18      19 Jul 2019 Latest Currently Viewing
    A17    02 Nov 2018
    A16    10 Jul 2018
    A15     27 Feb 2018
    A13     04 Jul 2017
    A12      18 May 2017
    A11    23 Mar 2017
    A10    12 Oct 2016
    A09      26 May 2016
     
    So perhaps you may want to do some updates.

    Installation instructions

    Updating the BIOS from Windows

    Note 1: Before updating the BIOS, ensure that you suspend BitLocker encryption on a BitLocker-enabled system. If BitLocker is not enabled on your system, you can ignore this step.
    Note 2: Do not turn off the power or interrupt the BIOS update process during the update.

    Download and Installation
    1. Click Download File, to download the file.
    2. Click Save to save the file to your hard drive.
    3. Browse to the location where you downloaded the file and double-click the new file.
    The system restarts automatically and updates the BIOS at the system startup screen. After the BIOS update is complete, system restarts again.

    Updating the BIOS from DOS (Non-Windows users)

    Note 1: Before updating the BIOS, ensure that you suspend BitLocker encryption on a BitLocker-enabled system. If BitLocker is not enabled on your system, you can ignore this step.
    Note 2: Do not turn off power or interrupt the BIOS update process during the update.

    Installation
    Note: You must provide a bootable USB drive. This executable file does not create the DOS system files.
    1. Copy the downloaded file to a bootable USB drive.
    2. Power on the system and then Press the F12 key.
    3. Select USB Storage Device and boot to the DOS prompt.
    4. Run the file by typing following command. For example:
    C:\ 7020A18.exe
    Where C is the drive letter of the USB device where the executable file is located and 7020A18.exe is the name of the downloaded file.
    The system restarts automatically and updates the BIOS at the system startup screen. After the BIOS update is complete, system restarts again.

    Updating the BIOS from DOS with UEFI boot mode enabled (Non-Windows users, Load Legacy Option Disabled)

    Note 1: Before updating the BIOS, ensure that you suspend BitLocker encryption on a BitLocker-enabled system. If BitLocker is not enabled on your system, you can ignore this step.
    Note 2: Do not turn off the power or interrupt the BIOS update process during the update.

    Installation
    1. Copy the downloaded file to a bootable DOS USB drive.
    2. Power on the system and then go to BIOS Setup by pressing the F2 key.
    3. Go to General > Boot Sequence > Boot > Boot List Option.
    4. Change UEFI to Legacy of Boot List Option.
    5. Go to Exit > Save Changes and reboot system.
    6. Press F12 and then select USB Storage Device and boot to the DOS prompt.
    7. Run the file by typing the file name.
    The system restarts automatically and updates the BIOS at the system startup screen. After the BIOS update is complete, the system restarts again.
    8. Go to BIOS Setup by pressing the F2 key and go to General > Boot Sequence > Boot > Boot List Option.
    9. Change Legacy to UEFI Boot Option.
    10. Go to Exit > Save Changes and reboot the system.

      Kind Regards  

                                         

      anne_droid

  • anne_droid

    5 Journeyman

    2073 Posts

    7698 Points

    0

    0

    Posted July 2nd, 2026 11:20

    Hi

    Hopefully if you run some updates of the BIOS then maybe there will be MS updates that will install your certificates.

    If in doubt please ask.

    For a Dell OptiPlex 7020 Tower, you generally do not manually “install Microsoft Windows 10 2023 certs” in Windows itself; Dell says the right path is to keep the BIOS updated so the platform receives the new Secure Boot certificates in firmware/default Secure Boot databases, while Microsoft is also rolling updates out through Windows Update in phases.

    What to do

    1. Update Windows 10 fully through Windows Update. Microsoft’s rollout is staged, so supported systems may receive the Secure Boot certificate update automatically.

    2. Update the OptiPlex 7020 Tower BIOS from Dell Support. Dell specifically recommends keeping BIOS current so the 2023 Secure Boot certificate is present in the default Secure Boot database.

    3. After the BIOS update, check Secure Boot status in Windows and verify whether the newer trust configuration is present. Dell and Microsoft both indicate that firmware level matters for this transition.Important note

    A “manual certificate install” is not the normal end-user method for this issue on a home or small-business PC; the supported approach is Windows Update plus Dell firmware/BIOS updates.

    Dell-specific path

    • Go to the Dell support page for the OptiPlex Tower 7020 and install the latest BIOS.         dell

    • Read the BIOS release notes carefully for wording like “This BIOS contains the new 2023 Secure Boot Certificates.” Dell says that phrase may appear in driver details for affected updates.               

    •  dell

    • If the machine is BitLocker-protected, suspend BitLocker before the BIOS update, then re-enable it afterward. This is standard practice for firmware changes, though Dell’s Secure Boot articles emphasize keeping firmware current rather than manually editing certificates.  

    • dell

      Kind Regards  

                                         

      anne_droid

  • beebo.dell

    1 Rookie

    4 Posts

    13 Points

    0

    0

    Posted July 6th, 2026 12:29

    @anne_droid​ hello dear

    thanks for your reply.

    now i should download latest bios update or update all of them from older to newer?

    also, when using dell command update doesn't suggest to update bios, why?

    another question, Once I try to scan hardware from support assist  hearing high sound of fans is it normal? 

    is dell service tag unique one  or the same for many devices.

      thanks very much

  • anne_droid

    5 Journeyman

    2073 Posts

    7698 Points

    0

    0

    Posted July 6th, 2026 13:14

    Hi

    The service tag is unique to your device.

    I suggest an interim BIOS update if practicable.  Perhaps A15, then A18.

    Unfortunately noisy fans are becoming a way of life, but if you feel it is excessive then ask a local repairer for an opinion.

      Kind Regards  

                                         

      anne_droid