ASRock.com Homepage
Forum Home Forum Home > Technical Support > Intel Motherboards
  New Posts New Posts RSS Feed - B760 PRO RS Secure Boot Key missing
  FAQ FAQ  Forum Search Search  Events   Register Register  Login Login

B760 PRO RS Secure Boot Key missing

 Post Reply Post Reply Page  12>
Author
Message Reverse Sort Order
Xaltar View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 16 May 2015
Location: Europe
Status: Offline
Points: 40758
Post Options Post Options   Thanks (0) Thanks(0)   Quote Xaltar Quote  Post ReplyReply Direct Link To This Post Topic: B760 PRO RS Secure Boot Key missing
    Posted: 09 Jun 2026 at 6:34pm
Sorry to be the bearer of bad news. Good luck, here's hoping for a third party
fix
Back to Top
tolunq View Drop Down
Newbie
Newbie


Joined: 07 Jun 2026
Status: Offline
Points: 165
Post Options Post Options   Thanks (0) Thanks(0)   Quote tolunq Quote  Post ReplyReply Direct Link To This Post Posted: 09 Jun 2026 at 6:10pm
ok. thanks well...
Back to Top
Xaltar View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 16 May 2015
Location: Europe
Status: Offline
Points: 40758
Post Options Post Options   Thanks (0) Thanks(0)   Quote Xaltar Quote  Post ReplyReply Direct Link To This Post Posted: 09 Jun 2026 at 5:59pm
Their issue was resolved, a BIOS update was not necessary for their board as the
version they were using already included the security key update. Your situation
is different as your hardware is "EOL" (End Of Life). This means that ASRock is
no longer providing support for the board regarding BIOS updates etc. You will
have to either contact Microsoft and inquire with them or wait and see if other
third party solutions become available once the new keys have been in use for a
while.
Back to Top
tolunq View Drop Down
Newbie
Newbie


Joined: 07 Jun 2026
Status: Offline
Points: 165
Post Options Post Options   Thanks (0) Thanks(0)   Quote tolunq Quote  Post ReplyReply Direct Link To This Post Posted: 09 Jun 2026 at 5:54pm
Hello.
How are you getting on with the certificates?
Still nothing?

Same for me. They?™re there but they don?™t work.

Back to Top
Xaltar View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 16 May 2015
Location: Europe
Status: Offline
Points: 40758
Post Options Post Options   Thanks (1) Thanks(1)   Quote Xaltar Quote  Post ReplyReply Direct Link To This Post Posted: 21 Apr 2026 at 12:03am
Nothing at all, you are sorted
Back to Top
666pierog View Drop Down
Newbie
Newbie
Avatar

Joined: 20 Apr 2026
Location: Poland
Status: Offline
Points: 60
Post Options Post Options   Thanks (0) Thanks(0)   Quote 666pierog Quote  Post ReplyReply Direct Link To This Post Posted: 20 Apr 2026 at 11:39pm
Thank you so much!
so theres nothing to worry about?
Back to Top
Xaltar View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 16 May 2015
Location: Europe
Status: Offline
Points: 40758
Post Options Post Options   Thanks (0) Thanks(0)   Quote Xaltar Quote  Post ReplyReply Direct Link To This Post Posted: 20 Apr 2026 at 4:10pm
OK, I can confirm, the steps I listed above do NOT work on a system that does not
support the new keys. I tested on one of my older systems before updating the BIOS
and it still says "variable undefined". After updating my BIOS the process succeeds.

In other words, your system is already set up for them and you don't need to do
anything more. This process wouldn't work if you needed a BIOS update.

Enjoy your system worry free
Back to Top
Xaltar View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 16 May 2015
Location: Europe
Status: Offline
Points: 40758
Post Options Post Options   Thanks (0) Thanks(0)   Quote Xaltar Quote  Post ReplyReply Direct Link To This Post Posted: 20 Apr 2026 at 3:20pm
I wouldn't worry, ASRock has already released updates for a number of older boards.
Even my old x370 Taichi has gotten an update for this. I suspect all that is
needed in the UEFI on newer boards may already be present. It seems only older
boards got updates so far which leads me to believe the updated security key
will come via windows update. I don't see security certificates mentioned in any
of the latest BIOS versions for newer boards (current and last gen). All the older
boards that received an update for this state:
Quote Update Secure Boot Key (2023 KEK/DB/PK)

This is why I suspect newer boards already have what is needed for the new keys.
All the older boards that got an update hadn't had a BIOS update for quite some
time, a year or more in most cases. This means the update needed for secure boot
couldn't have been implemented in an earlier update. The last official update before
this one for the x370 Taichi was in 2023 for example. There are some newer beta
updates but they only added CPU support/RAM compatibility.

I found this article while looking into your issue:
https://learn.microsoft.com/en-us/answers/questions/5652654/secure-boot-certificates-have-been-updated-but-are

It might be of some use to you.

With this kind of thing you often find that details are kept under wraps for
security reasons. I would imagine Microsoft will want as much of this process
automated/hidden as possible.

I wouldn't worry about it, your system is still current and well within the
required specs for Windows 11. ASRock (all manufacturers really) won't leave
you high and dry.

Hope this helps.
Back to Top
666pierog View Drop Down
Newbie
Newbie
Avatar

Joined: 20 Apr 2026
Location: Poland
Status: Offline
Points: 60
Post Options Post Options   Thanks (0) Thanks(0)   Quote 666pierog Quote  Post ReplyReply Direct Link To This Post Posted: 20 Apr 2026 at 2:38pm
Yea that worked, i already done this before but after cleaning secureboot keys and updating bios still asrock didnt updated keys
what if they wont update that keys on june 2026?
Back to Top
Xaltar View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 16 May 2015
Location: Europe
Status: Offline
Points: 40758
Post Options Post Options   Thanks (0) Thanks(0)   Quote Xaltar Quote  Post ReplyReply Direct Link To This Post Posted: 20 Apr 2026 at 1:56pm
That is strange. Have you tried the following:

1. Open PowerShell as Administrator
2. Enter the following command to check your certificate status:
Quote [System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match 'Windows UEFI CA 2023'

3. If the result is an error (variable undefined) then enter this:
Quote reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x5944 /f

4. Then enter:
Quote Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

5. Restart the system and then enter PowerShell as administrator again.
6. Reenter the command from 2 and you should see "True" confirming the update has been applied.

Let me know if it works.

Edited by Xaltar - 20 Apr 2026 at 2:00pm
Back to Top
 Post Reply Post Reply Page  12>
  Share Topic   

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.04
Copyright ©2001-2021 Web Wiz Ltd.

This page was generated in 0.078 seconds.