Loading...
Loading...
The new Microsoft Corporation (MSFT) Windows Unified Extensible Firmware Interface (UEFI) CA 2023 certificate has been included all HPE Gen10, Gen10 Plus, Gen11, and Gen12 platforms BIOS releases from early in 2025.The Windows UEFI CA 2023 certificate strengthens the secure boot allowed signature database by ensuring only trusted bootloaders and firmware components are allowed during the boot process.To enable the Windows UEFI CA 2023 certificate, install the latest BIOS version on each platform. Reset "All Keys to Platform Defaults" is required to activate the Windows UEFI CA 2023 certificate after latest BIOS is installed.
Any HPE Gen10, Gen10 Plus, Gen11, and Gen12 platform running Microsoft Windows Server is potentially affected.
To enable the Windows Unified Extensible Firmware Interface (UEFI) CA 2023 certificate in the BIOS/Platform Configuration (RBSU), perform the following steps:Download the latest BIOS version for the specific platform.Reboot the server and press F9 to enter System Utilities.Navigate to the following path:System Configuration -> BIOS/Platform Configuration (RBSU) -> Server Security -> Secure Boot SettingsEnter to the the Advanced Secure Boot Options menu.Select "Reset All Keys to Platform Defaults".Notes:This is required to activate CA2023 after the latest BIOS is installed.The feature "Reset All Keys to Platform Defaults" will change the Secure Boot settings from "Enabled" to "Disabled"; therefore, the user will require to the enable the Secure Boot settings again.Confirm the selection by clicking "Yes".Reboot/Power Cycle the server.Notes:The information above is also documented in each BIOS Release Notes.For information about installing or reinstalling default Secure Boot keys on HPE Mission Critical x86 Servers, refer to the following URLs:HPE Compute Scale-up Server 3200 Configuration Guide - Installing or reinstalling default secure boot keysHPE Superdome Flex Server OS Installation Guide - Installing or reinstalling default Secure Boot keysRevision HistoryDocument VersionRelease DateDetails3March 4, 2026Additional information has been added to the Notes in the Resolution section.2February 10, 2026The following products were removed from the document:HPE ProLiant MicroServer Gen10HPE ProLiant DL388 Gen10 serverHPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 ServersThe following products were added to the document:HPE Synergy 480 Gen10 Compute ModuleHPE Synergy 660 Gen10 Compute ModuleHPE Synergy 480 Gen10 Plus Compute ModuleHPE Synergy 480 Gen11 Compute ModuleHPE Synergy 480 Gen12 Compute ModuleHPE ProLiant m750 Server BladeAdditional information about "Reset All Keys to Platform Defaults" has been added to the Resolution section.1January 15, 2026Original Document Release.
Operating Systems Affected:Microsoft Windows Server 2019, Microsoft Windows Server 2022, Microsoft Windows Server 2025
Click on a version to see all relevant bugs
Hewlett Packard Enterprise Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.