Forum Discussion

pmaddimsetty's avatar
pmaddimsetty
Icon for Microsoft rankMicrosoft
Sep 14, 2026

Linux Intune enrollment blocked by Secure Boot CA2023 requirement on HP Z4 G4

a { text-decoration: none; color: #464feb; } tr th, tr td { border: 1px solid #e6e6e6; } tr th { background-color: #f5f5f5; }

Device: HP Z4 G4 Workstation
BIOS: P61 v02.97, 06/17/2025
OS: Ubuntu Desktop 26.04 LTS
Secure Boot: Enabled
Disk encryption: Enabled
Intune Portal: 1.2607.4-resolute
Microsoft Identity Broker: 3.0.2-resolute

Intune enrollment reports a Secure Boot / 2023 certificate issue and references the Linux Secure Boot certificates expiring in 2026 guidance.

Firmware has already been updated through fwupd:

  • System Firmware: 1.66 → 2.97
  • UEFI dbx: 20230501 → 20260402
  • fwupdmgr refresh succeeds
  • fwupdmgr get-updates reports no firmware updates
  • fwupdmgr get-releases <Secure Boot device ID> reports No releases found

Current firmware Secure Boot DB/KEK still exposes legacy Microsoft trust including:

  • Microsoft Windows Production PCA 2011
  • Microsoft Corporation UEFI CA 2011
  • Microsoft Corporation KEK CA 2011
  • HP UEFI Secure Boot 2013

Request:

Please confirm the supported remediation for adding the required Microsoft 2023 Secure Boot CA/KEK trust anchors on this HP Z4 G4/P61 platform, or whether this platform requires an Intune compliance exception / OEM firmware update.

I do not want to manually modify PK/KEK/db because this machine previously experienced a GRUB/Secure Boot boot failure and is currently booting correctly with Secure Boot enabled.

1 Reply

  • Your firmware and dbx updates have completed, but the enrolled Secure Boot trust certificates still show the older generations. Those are separate components: db contains trusted signatures and certificates, while dbx contains revoked ones. Updating dbx therefore does not demonstrate that replacement trust certificates were installed.

     

    Microsoft currently lists Ubuntu Desktop 26.04 LTS as supported for Intune enrollment, so its version alone is not a reason to reject this configuration. Capture Intune’s exact failure details together with the BIOS version, db and KEK inventories, and fwupd results. Submit them to HP and your Intune administrator for a supported, model-specific certificate update path. An empty firmware update list does not establish that every required certificate is present. I cannot verify an HP Z4 G4 remediation or supported enrollment exception from Microsoft’s documentation. Avoid manually replacing keys or disabling Secure Boot to bypass enrollment.