Forum Discussion
Gwensdolyn
Jun 10, 2026Copper Contributor
UEFI KEK Certs not updated on Windows 10
I have a Huawei D14 matebook from 2021 and updated the microsoft certificates, when I check this I get the following output, I see that the KEK cert is not updated is that stored in the bios ? Am I s...
MaxThunder
Jun 14, 2026Iron Contributor
Yes, KEK is stored in UEFI firmware/NVRAM, not just Windows; you’re probably okay for now if Secure Boot is enabled and Windows Update/BIOS are current, but the KEK should eventually be updated via Microsoft/OEM firmware updates because Microsoft says both DB and KEK need the newer 2023 certs before the older Secure Boot certs expire in 2026.