Forum Discussion
Linux Intune enrollment blocked by Secure Boot CA2023 requirement on HP Z4 G4
a { text-decoration: none; color: #464feb; } tr th, tr td { border: 1px solid #e6e6e6; } tr th { background-color: #f5f5f5; }
Device: HP Z4 G4 Workstation
BIOS: P61 v02.97, 06/17/2025
OS: Ubuntu Desktop 26.04 LTS
Secure Boot: Enabled
Disk encryption: Enabled
Intune Portal: 1.2607.4-resolute
Microsoft Identity Broker: 3.0.2-resolute
Intune enrollment reports a Secure Boot / 2023 certificate issue and references the Linux Secure Boot certificates expiring in 2026 guidance.
Firmware has already been updated through fwupd:
- System Firmware: 1.66 → 2.97
- UEFI dbx: 20230501 → 20260402
- fwupdmgr refresh succeeds
- fwupdmgr get-updates reports no firmware updates
- fwupdmgr get-releases <Secure Boot device ID> reports No releases found
Current firmware Secure Boot DB/KEK still exposes legacy Microsoft trust including:
- Microsoft Windows Production PCA 2011
- Microsoft Corporation UEFI CA 2011
- Microsoft Corporation KEK CA 2011
- HP UEFI Secure Boot 2013
Request:
Please confirm the supported remediation for adding the required Microsoft 2023 Secure Boot CA/KEK trust anchors on this HP Z4 G4/P61 platform, or whether this platform requires an Intune compliance exception / OEM firmware update.
I do not want to manually modify PK/KEK/db because this machine previously experienced a GRUB/Secure Boot boot failure and is currently booting correctly with Secure Boot enabled.