Share via

How to fix the SecureBoot Cert expire issue in HP and HPE Server which not connect to internet ?

Lui Lui 0 Reputation points
2026-03-20T07:33:53.84+00:00

How to fix the SecureBoot Cert expire issue in HP and HPE Server which not connect to internet ?

Windows 11 and Windows Server 2022

Windows for business | Windows Server | Devices and deployment | Other
0 comments No comments

4 answers

Sort by: Most helpful
  1. Jason Nguyen Tran 15,205 Reputation points Independent Advisor
    2026-03-20T08:25:05.8366667+00:00

    Hi Lui Lui,

    For HP and HPE servers running Windows 11 or Windows Server 2022, the fix usually involves applying the Secure Boot DB update that Microsoft released to address expired certificates. Since your servers are offline, you’ll need to manually download the update package from the Microsoft Update Catalog on a machine with internet access, then transfer it to the affected servers. Once copied, you can install it using wusa.exe or DISM.

    It’s also important to check the firmware/BIOS updates from HP/HPE, as they sometimes include updated SecureBoot keys that align with Microsoft’s changes. Applying both the OS patch and the latest firmware ensures the system can validate boot files correctly.

    If you continue to see boot errors after applying the patch, verify that SecureBoot is enabled in BIOS and that the certificates are updated in the SecureBoot database. In rare cases, you may need to clear and re‑import the SecureBoot keys from the vendor’s support site.

    In short, the fix is to manually apply the SecureBoot certificate update from Microsoft Update Catalog and ensure your HP/HPE firmware is current. This combination should resolve the expiry issue even without internet connectivity.

    I hope the response provided some helpful insight. If it clarified the issue for you, please consider marking it as Accept Answer so others with the same issue can find the solution.

    Jason.

    1 person found this answer helpful.

  2. Lui Lui 0 Reputation points
    2026-03-30T07:13:50.26+00:00

    Dear Jason,

    Thanks for support, we applied it to some Phyical server , VM and PC

    Can help to provide powershell to confirm the secure boot cert issue fixed ?

    Many thanks for support again,

    0 comments No comments

  3. Lui Lui 0 Reputation points
    2026-03-25T05:53:44.64+00:00

    Dear Jason,The KB5036210 can't find any download URL.

    Please kindly advise for further action,

    Many thanks again


  4. Jason Nguyen Tran 15,205 Reputation points Independent Advisor
    2026-03-25T03:19:25.29+00:00

    Hi Lui Lui,

    I’m following up to check whether the issue has been resolved. Feel free to reply if you need further information. If the information provided was helpful, please click "Accept Answer" to help others in the community. Thank you!


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.