Instructions Regarding the SecureBoot Certificate for GEEKOM Devices

Updated on Mar,19, 2026


According to an official announcement from Microsoft, the legacy certificate used for Microsoft Secure Boot, which has been in place since 2011, will expire between June and October 2026. The expiration of this certificate may have certain implications for personal devices.

SituationImpact Level説明
Can the computer still boot normally?Almost no impactThe computer can still start up, run programs, and access the internet normally after expiration
Daily use (office work, gaming, watching videos)Basically no impactDoes not affect the browser, software, or files
Normal Windows updatesMost are possibleRegular security updates and feature updates can still be installed
Security protection during startupGradually decreasesUnable to receive new Boot Manager, Secure Boot database, or revocation list updates
Newly discovered bootkit/startup-level vulnerability fixesCannot be obtainedSecurity decreases over the long term (like an house’s防盗门 lock not being replaced, but the door can still be used)
BitLocker encrypted drivesMay be affectedSome enhanced functions or new mitigation measures cannot be applied
Very rare special casesThird-party startup items may failSuch as certain older graphics card VBIOS, special dual-boot bootloaders

In the short term, there will be virtually no noticeable impact, but long-term security will be compromised—especially when new vulnerabilities emerge after the second half of 2026.

As shown in the figure, the method to enable the Secure Boot option in BIOS. On most devices, it is enabled by default and requires no manual configuration.

What Do You Need to Do as a Personal User?

1.Keep Windows Update enabled and install updates promptly

Settings → Windows Update → Advanced Options → Receive updates for other Microsoft products (turn on)
For most computers manufactured after 2020, the new 2023 certificate will be automatically pushed via regular cumulative updates in 2025–2026.

2.Check if the update has been applied

Open PowerShell as an administrator, then paste and run the following commands:

Check for the 2011 certificate:

([System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match ‘Microsoft Windows Production PCA 2011’)

Check for the 2023 certificate:

([System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match ‘Windows UEFI CA 2023’)

3.Check if the BIOS is Up to Date

According to information disclosed by the GEEKOM R&D department, as of March 19, 2026, the BIOS versions for the following models (and newer) already support the UEFI 2023 certificate. Updates for other models will also be completed before the UEFI 2011 security certificate expires.

Intel SeriesBIOS VersionAMD SeriesBIOS Version
Air12 Lite0.17A5 U Series(5825u 7430u)(65W Adapter)2.43
Mini Air12(N95)0.44A5 7640hs0.01
IT122.34A5 Pro2.43
IT131.23A5 Pro(7640HS)0.02
GT12 Pro2.34AE70.54
GT13 Pro1.21AE80.57
XT12 Pro2.33A7 7940HS
A7 7535HS
0.58
2.42
XT13 Pro1.22A80.61
IT1 Mega0.68A62.39
IT13 Max0.68AX7 Pro0.54
IT15 Max0.68AX8 Pro0.56
GT1 Mega0.68AE8 Max1.22
GT13 Max0.68A7 Max1.26
GT15 Max0.68/0.14A8 Max1.22
XT1 Mega0.68AX8 Max1.22
A9 Max0.25
A9 Mega0.09

ご視聴ありがとうございます。間違いがありましたら、訂正をお願いします。

ja日本語