Event details
Answered at 34:00
In response to the answer, this is the website url: https://www.dell.com/support/kbdoc/en-us/000402373/poweredge-server-bios-update-guidelines-for-microsoft-secure-boot-certificates
Is there a tool that can help us to check whether the server is ready for secure boot certificate update also perform the update for us?
- mihiApr 24, 2026Brass Contributor
Oh my...
That PowerShell script does nothing more than update the DB and KEK certificates via the unsupported way via PowerShell (that's why they require BitLocker to be disabled). It also seems that the included "Cerifcates" (sic!) are also included in Microsoft's SecureBootObjects KEK list, so from an outsider's perspective there should be absolutely no reason at all to prefer this script to the official registry method. In case the official method runs into any errors, you could try that script, of course, if you trust your vendor's skill of writing PowerShell scripts (since it has been provided by your vendor)