UNSOLVED

Ed3585

updated

2 days ago

E

Ed3585

1 Rookie

2 Posts

7 Points

0

56

August 26th, 2026 07:27

Inspiron 3585 secure boot failed

Since August 24th, my inspiron 3585 (windows 10) says 'secure boot failed'. I tried all the options including BIOS clock, restore, boot from usb and repair, update to latest BIOS level (which was already 1.15.0). Am I right in thinking this is due the need for a firmware update to handle KEK 2K CA 2023? If so, will there be an update? For now I switched secure boot off - is that safe?

  • anne_droid

    5 Journeyman

    2063 Posts

    7665 Points

    0

    0

    Posted August 26th, 2026 09:02

    Hi

    Reset Secure Boot keys in BIOS (most common fix)

    This is the standard fix Microsoft and OEMs recommend for “Secure Boot failed” after updates. learn.microsoft+2

    1. Shut down the laptop completely.

    2. Power on and immediately tap F2 repeatedly to enter BIOS/UEFI.

      • On some Dell laptops you may need Fn + F2.

    3. In BIOS, go to the Boot or Security section (wording varies by BIOS version).

    4. Look for one of these options:

      • Secure BootSecure Boot Mode → change to Deployed Mode or Standard (if available), or

      • Secure BootReset to Setup Mode / Clear Secure Boot Keys, then

      • Secure BootRestore Factory Keys / Load Factory Default Keys / Install Default Secure Boot Keys.

    5. Do this sequence if both exist:

      • First: Clear/Reset Secure Boot Keys (or “Reset to Setup Mode”).

      • Then: Restore/Load Factory Keys (or “Install Default Secure Boot Keys”).

    6. Ensure:

      • Boot Mode is UEFI (not Legacy/CSM).

      • Windows Boot Manager is the first boot option.

    7. Save and exit (usually F10 → Yes).

    If Windows now boots normally and the message is gone, you’re done. If it still says “Secure Boot failed”, continue.


    2) Temporarily disable Secure Boot to get into Windows

    If the machine won’t boot with Secure Boot enabled:

    1. Enter BIOS again (F2 at power-on).

    2. Under Boot or Security:

      • Set Secure Boot to Disabled.

    3. Save and exit.

    If Windows now boots, you can repair the Secure Boot environment from inside Windows.

    If in doubt please ask.


      Kind Regards  

                                         

      anne_droid

  • Ed3585

    1 Rookie

    2 Posts

    7 Points

    2

    0

    Posted August 26th, 2026 15:15

    @anne_droid​ Thanks for the response.

    I did all that and still get the error. I also booted without secure boot (as I cant boot with it on)  and ran the windows scheduler to update the boot info, but it just ran and the certificate is still not there.  Claude tells me that my realistic options are keeping secure boot off, or buying a new laptop. Unless you know of other options, I think I will stop there.

  • anne_droid

    5 Journeyman

    2063 Posts

    7665 Points

    1

    0

    Posted August 26th, 2026 22:23

    As Clint Eastwood (Dirty Harry Callaghan) may say

    A man's gotta know his limitations.

    A good man always knows his limitations.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

      Kind Regards  

                                         

      anne_droid

  • anne_droid

    5 Journeyman

    2063 Posts

    7665 Points

    0

    0

    Posted August 26th, 2026 22:30

    Hi

    Maybe Dell will issue a newer BIOS than 1.15.0,if so, then I am sure all will be well.

     If your BIOS supports manual key import

    Some OEMs (ASUS, some others) document importing the microsoft uefi ca 2023.crt file from a USB stick into the Authorized Signatures (db) and/or KEK.

    • Check your 3585 BIOS under Security → Secure Boot → Key Management for options like Update / Append for db or KEK.

    • If present, you can:

      • Download the official certificate from Microsoft:
        https://go.microsoft.com/fwlink/?linkid=2239872

      • Put it on a FAT32 USB stick and import it as described in your BIOS UI.

    Not all Dell consumer BIOSes expose this, but it’s worth checking.

    Will there be an update?

    • Microsoft has stated that devices without the 2023 certificates will continue to boot and receive updates; the rollout is ongoing and may take months for some hardware.

    • For Dell specifically, new BIOSes with the 2023 keys are being released across many models in 2026, but older/low‑end platforms sometimes lag or may not get an update at all.

    • Practically:

      • If the 3585 is still actively supported, a BIOS with KEK 2K CA 2023 is plausible but not guaranteed.

      • If Dell decides the model is end‑of‑life for firmware, the workaround is to keep Secure Boot disabled or rely on key reset + Windows updates, accepting that some future Secure Boot–dependent features may be limited.

    Recommended next steps for your 3585

    1. In BIOS, do a full Secure Boot key reset to factory defaults as described above, then re‑enable Secure Boot and test.

    2. Boot into Windows, run the two PowerShell checks for KEK 2K CA 2023 and Windows UEFI CA 2023.

    3. If either check fails:

      • Ensure Windows Update is fully current and reboot a couple of times.

      • Re‑check the Dell support page for any newer BIOS than 1.15.0 with Secure Boot/2023 notes.

    4. If no newer BIOS appears and the keys remain missing, your options are:

      • Leave Secure Boot disabled (system will still boot, but some security features are reduced), or

      • Manually import the 2023 certificate if your BIOS allows it.

      Kind Regards  

                                         

      anne_droid