Hello, it seems Dell has not provided a PK-signed KEK to Microsoft for the Dell Precision Tower 3620. As such, updating the Secure Boot certificates to the new 2023 ones fails with Event 1803: Firmware_MissingKEKInPackage. Are there any plans from Dell to provide Microsoft with updated KEKs for this, as well as other devices? This desktop is still a very capable machine. Thank you.
So, I'm going to say the answer is NO, unfortunately it will not.
(edited)
Dell Rockstar
Microsoft Windows and Apple iOS Developer (Retired) - Like many of you, I can appreciate a good game-engine. - I answer questions here, but I'm not a Dell employee. - Consider giving posts you like a "thumbs-up" - Posting models-numbers and software versions speeds trouble-shooting. - Click "Mark as Accepted Answer" on any post that answers your question best.
@Tesla1856 The second article states "nor does it mean that these systems cannot get certificate updates from Windows Update". So pretty please?
I understand Dell doesn't want to release BIOS updates for older models, but they can sign new KEKs and I reckon that's way easier.
To add more info, the PC has accepted the db certs successfully and updated to the 2023 bootloader, but there is no KEK to replace the old one, so the PC won't be able to receive updates to the dbx.
If so, we can work here quietly in your thread. If your skill level is high, I might be able to guide you the rest of the way. For starters, I would have to see the report.
(edited)
Dell Rockstar
Microsoft Windows and Apple iOS Developer (Retired) - Like many of you, I can appreciate a good game-engine. - I answer questions here, but I'm not a Dell employee. - Consider giving posts you like a "thumbs-up" - Posting models-numbers and software versions speeds trouble-shooting. - Click "Mark as Accepted Answer" on any post that answers your question best.
@Tesla1856 Thank you for this, though I probably won't go as hard as signing my own Secure Boot keys. I hope Dell provides Microsoft with an updated KEK.
Tesla1856
10 Wizard
•
17979 Posts
•
71574 Points
0
1
Posted May 15th, 2026 20:28
It is NOT on this list:
https://www.dell.com/support/kbdoc/en-us/000347876/microsoft-2011-secure-boot-certificate-expiration#Precision
But IS on this list:
https://www.dell.com/support/kbdoc/en-us/000378734/microsoft-2011-secure-boot-certificates-expiration-for-out-of-scope-platforms-for-bios-updates#Precision
So, I'm going to say the answer is NO, unfortunately it will not.
(edited)
Dell Rockstar
Microsoft Windows and Apple iOS Developer (Retired)
- Like many of you, I can appreciate a good game-engine.
- I answer questions here, but I'm not a Dell employee.
- Consider giving posts you like a "thumbs-up"
- Posting models-numbers and software versions speeds trouble-shooting.
- Click "Mark as Accepted Answer" on any post that answers your question best.