ASRock.com Homepage
Forum Home Forum Home > Technical Support > Intel Motherboards
  New Posts New Posts RSS Feed - B760 PRO RS Secure Boot Key missing
  FAQ FAQ  Forum Search Search  Events   Register Register  Login Login

B760 PRO RS Secure Boot Key missing

 Post Reply Post Reply
Author
Message
666pierog View Drop Down
Newbie
Newbie
Avatar

Joined: 10 hours 52 minutes ago
Location: Poland
Status: Online
Points: 45
Post Options Post Options   Thanks (0) Thanks(0)   Quote 666pierog Quote  Post ReplyReply Direct Link To This Post Topic: B760 PRO RS Secure Boot Key missing
    Posted: 10 hours 50 minutes ago at 4:31am
Hello, My ASROCK B760 PRO RS still doesnt have Option ROM 2023 CA secure boot key..
its missing since latest bios update please fix this, certificates expire on June 2026.
Back to Top
Xaltar View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 16 May 2015
Location: Europe
Status: Online
Points: 36263
Post Options Post Options   Thanks (0) Thanks(0)   Quote Xaltar Quote  Post ReplyReply Direct Link To This Post Posted: 9 hours 41 minutes ago at 5:40am
You will probably need to open a support ticket for this issue. There is nothing
I can do to help you, I am just a moderator here. ASRock does reply here sometimes
but it's not very regular so a support ticket will be a quicker way to get the answer
you are looking for.

http://tw.asrock.com/events/tsd.asp
Back to Top
666pierog View Drop Down
Newbie
Newbie
Avatar

Joined: 10 hours 52 minutes ago
Location: Poland
Status: Online
Points: 45
Post Options Post Options   Thanks (0) Thanks(0)   Quote 666pierog Quote  Post ReplyReply Direct Link To This Post Posted: 7 hours 40 minutes ago at 7:41am
I tried, already emailed them 3 times. No any respond from them..
Back to Top
Xaltar View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 16 May 2015
Location: Europe
Status: Online
Points: 36263
Post Options Post Options   Thanks (0) Thanks(0)   Quote Xaltar Quote  Post ReplyReply Direct Link To This Post Posted: 1 hour 25 minutes ago at 1:56pm
That is strange. Have you tried the following:

1. Open PowerShell as Administrator
2. Enter the following command to check your certificate status:
Quote [System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match 'Windows UEFI CA 2023'

3. If the result is an error (variable undefined) then enter this:
Quote reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x5944 /f

4. Then enter:
Quote Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

5. Restart the system and then enter PowerShell as administrator again.
6. Reenter the command from 2 and you should see "True" confirming the update has been applied.

Let me know if it works.

Edited by Xaltar - 1 hour 21 minutes ago at 2:00pm
Back to Top
666pierog View Drop Down
Newbie
Newbie
Avatar

Joined: 10 hours 52 minutes ago
Location: Poland
Status: Online
Points: 45
Post Options Post Options   Thanks (0) Thanks(0)   Quote 666pierog Quote  Post ReplyReply Direct Link To This Post Posted: 43 minutes ago at 2:38pm
Yea that worked, i already done this before but after cleaning secureboot keys and updating bios still asrock didnt updated keys
what if they wont update that keys on june 2026?
Back to Top
Xaltar View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 16 May 2015
Location: Europe
Status: Online
Points: 36263
Post Options Post Options   Thanks (0) Thanks(0)   Quote Xaltar Quote  Post ReplyReply Direct Link To This Post Posted: 54 seconds ago at 3:20pm
I wouldn't worry, ASRock has already released updates for a number of older boards.
Even my old x370 Taichi has gotten an update for this. I suspect all that is
needed in the UEFI on newer boards may already be present. It seems only older
boards got updates so far which leads me to believe the updated security key
will come via windows update. I don't see security certificates mentioned in any
of the latest BIOS versions for newer boards (current and last gen). All the older
boards that received an update for this state:
Quote Update Secure Boot Key (2023 KEK/DB/PK)

This is why I suspect newer boards already have what is needed for the new keys.
All the older boards that got an update hadn't had a BIOS update for quite some
time, a year or more in most cases. This means the update needed for secure boot
couldn't have been implemented in an earlier update. The last official update before
this one for the x370 Taichi was in 2023 for example. There are some newer beta
updates but they only added CPU support/RAM compatibility.

I found this article while looking into your issue:
https://learn.microsoft.com/en-us/answers/questions/5652654/secure-boot-certificates-have-been-updated-but-are

It might be of some use to you.

With this kind of thing you often find that details are kept under wraps for
security reasons. I would imagine Microsoft will want as much of this process
automated/hidden as possible.

I wouldn't worry about it, your system is still current and well within the
required specs for Windows 11. ASRock (all manufacturers really) won't leave
you high and dry.

Hope this helps.
Back to Top
 Post Reply Post Reply
  Share Topic   

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.04
Copyright ©2001-2021 Web Wiz Ltd.

This page was generated in 0.098 seconds.