You can’t update the certs without secure boot being enabled. However, you might be able to enable secure boot without a problem. It depends.
If Bitlocker isn’t enabled (server, so probably not) and UEFI is present (likely but check), I *think* you can enable SB and update the certs. Assuming it’s even necessary. But if SB is turned off, is it necessary?
--
John Wright
IT Support Specialist
![]()
1800 Old Bluegrass Avenue, Louisville, KY 40215
Please submit IT requests to Hazelwoo...@bluegrass.org
24 Hour Helpline 1.800.928.8000
CONFIDENTIALITY NOTICE: This message contains confidential information and is intended only for the individual(s) addressed in the message. If you are not the named addressee, you should not disseminate, distribute, or copy this e-mail. If you are not the intended recipient, you are notified that disclosing, distributing, or copying this e-mail is strictly prohibited.
From: ntsys...@googlegroups.com <ntsys...@googlegroups.com>
On Behalf Of Mike Leone
Sent: Monday, August 10, 2026 1:49 PM
To: NTSysAdmin <ntsys...@googlegroups.com>
Subject: [ntsysadmin] Some Secure Boot and TPM Certs questions
|
EXTERNAL EMAIL - This email was sent by a person from outside your organization. Exercise caution when clicking links, opening attachments or taking further action, before validating its authenticity. |
|
Secured by Check Point |
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com.
To view this discussion visit
https://groups.google.com/d/msgid/ntsysadmin/CAHBr%2B%2BiGku%3DPQ%3DV6z2JAP4ifWsTXdvssfNBooSGCkfNAVVr6oQ%40mail.gmail.com.
No, as long as SB is off, it doesn’t make a difference.
I don’t have anything official at hand but here’s an article talking about it: https://www.windowslatest.com/2026/06/21/microsoft-reveals-how-to-verify-windows-11s-secure-boot-update-what-to-do-if-your-pc-missed-it/
“Some older PCs, particularly those from the early UEFI era or machines running in Compatibility Support Module (CSM) mode, do not use UEFI Secure Boot at all. These devices are booting the way PCs did before Secure Boot existed. For them, the certificate update is entirely irrelevant because there are no Secure Boot certificates to update. Windows may or may not show a Secure Boot section in Windows Security on these machines, but if the system is running in Legacy BIOS mode, Secure Boot was never active in the first place.”
--
John Wright
IT Support Specialist
![]()
1800 Old Bluegrass Avenue, Louisville, KY 40215
Please submit IT requests to Hazelwoo...@bluegrass.org
24 Hour Helpline 1.800.928.8000
CONFIDENTIALITY NOTICE: This message contains confidential information and is intended only for the individual(s) addressed in the message. If you are not the named addressee, you should not disseminate, distribute, or copy this e-mail. If you are not the intended recipient, you are notified that disclosing, distributing, or copying this e-mail is strictly prohibited.
From: ntsys...@googlegroups.com <ntsys...@googlegroups.com>
On Behalf Of Mike Leone
Sent: Monday, August 10, 2026 2:57 PM
To: ntsys...@googlegroups.com
Subject: Re: [ntsysadmin] Some Secure Boot and TPM Certs questions
|
EXTERNAL EMAIL - This email was sent by a person from outside your organization. Exercise caution when clicking links, opening attachments or taking further action, before validating its authenticity. |
|
Secured by Check Point |
On Mon, Aug 10, 2026 at 2:31 PM Wright, John M <John....@newvista.org> wrote:
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/CAHBr%2B%2BibrBp8qYd_1XcoGNVSsB4qX%3D8iFuR%3DidoLCNbkta%3Dcew%40mail.gmail.com.