Is the secure boot update necessary?
Is the secure boot update necessary?
I have two AM5 boards with Gigabyte MB motherboards. Recently I exchanged the CPU between the two, which forced a BIOS reset and required adjusting the fan curve again. I left the W11 installation unchanged. Could this be the reason behind the issue? Both systems display an error in EventViewer: Secure Boot certificates have been updated but aren’t yet applied to the firmware. Please check the official guidance to finish the update and maintain full protection. The device signature details are provided here. Key details:
DeviceAttributes – Manufacturer: Gigabyte Technology Co., Ltd.; Firmware: American Megatrends International, LLC., Version F6; Model: B850M DS3H; System: B850 MB; Signature info included.
OS architecture: amd64.
For more info, see the link about 2026 changes. The Gigabyte site doesn’t have clear answers. I understand this might be a generic problem and there’s guidance available. How can I confirm if an update is necessary for my setup? What steps should I follow?
I believe this resolved the issue. I turned off secure boot, logged into Windows, and didn’t notice the warning. After that, I reverted to BIOS settings and turned secure boot back on, but the error persisted. It seems the BIOS might have needed to adapt to the new CPU. While using secure boot settings, I also noticed key update options. Was this something I previously encountered? The Microsoft support page discusses certificate expiration and key updates—relevant here. Are my BIOS firmware versions sufficient for the latest versions? Thank you for the guidance; it’s helpful to know whether I should have updated earlier. Most users tend to disable features that cause errors, which reduces security compared to older keys.
The B850 MB version released in 2025 is newer than 2023. This suggests a 2023 release already exists. How will I confirm if something needs updating? It might prevent the system from starting or notify me beforehand. I prefer not to make changes without confirmation—avoid touching a running machine. I also have a TPM warning: updated Secure Boot certificates aren’t applied yet. Check the official guidance to finish the update and maintain security. The device details are listed above, including manufacturer and firmware info.
It appears a recently installed CPU rendered an outdated key unusable, prompting the device to power down and restart, which generated a fresh key. I’m not sure, but I keep secure boot enabled—better safe than sorry!
I own an old i7-6700 built with the original configuration (HP), and it also experiences the same issue in EventViewer. Yes, disabling secure boot is an option, though it goes against their security goals. I also tried a similar workaround on my older B650m board—successfully set it up, but I saw a BIOS message about updating keys. It might be a concern for 2026, but I’m still wondering the best approach if I want to maintain secure boot.
Thank you for the feedback. I’m not sure if there’s an official manual from MS or Gigabyte for this process. The instructions might be included in a BIOS update, but it’s unclear whether they’re required or the same steps for different hardware. Since it’s part of the BIOS, I’d expect a recent update to be available. If your 2025 model doesn’t have a key that appears to be from 2023, that would be concerning for the manufacturer.
It’s a built-in process in Windows, not something you try. The certificate authority can be adjusted manually. It’s essential for installing any Linux system with secure boot enabled. This has always been part of the picture since early 2023. You have choices: refresh it inside Windows (the only option for older boards), wait for manufacturers to provide updated BIOS before 2011 CA expires, or turn off secure boot entirely. These are your available paths.