Manual update

As an alternative to updating the secure boot keys via Windows updates, you can also replace the keys directly in the UEFI firmware setup. To do this, you must download the keys from the Microsoft website and save them on a USB stick.

https://learn.microsoft.com/de-de/windows-hardware/manufacture/desktop/windows-secure-boot-key-creation-and-management-guidance?view=windows-11#14-signature-databases-db-and-dbx

You must download the following components and save them on a USB stick:

Manual update 1:Fig.3: Components

Follow the steps below to replace the secure boot keys directly in the UEFI firmware setup:

1. Plug the prepared USB stick into the PC.
2. Press F7 immediately after starting the PC until the boot menu appears.
3. Press Enter Setup.
Manual update 2:Fig.4: Boot menu
4. Navigate to the Security tab.
5. Select the Secure Boot menu item.
Manual update 3:Fig.5: Secure Boot
6. Set the Secure Boot menu item to [Enabled] and the Secure Boot Mode menu item to [Custom].
Manual update 4:Fig.6: Secure boot settings
The Expert Key Management menu item is now enabled.
7. In the Expert Key Management menu item, choose the appropriate key range from the highlighted options.
Manual update 5:Fig.7: Key areas
8. Select Append to add the key range.
9. Select No.
10. Choose the USB stick in your PC.
Manual update 6:Fig.8: Choice of USB stick
11. Choose the corresponding file on the USB stick (KEK or db).
Manual update 7:Fig.9: File selection
12. Select Public Key Certificate.
13. Confirm the Certificate Owner GUID with Enter to start the import of the Microsoft KEK and db keys from the USB stick into the BIOS.
Manual update 8:Fig.10: Key Certificate
14. Confirm the exchange of the key with Yes.
15. Confirm with OK.
Manual update 9:Fig.11: Confirm exchange key
16. Activate Secure Boot.
17. Save the changes with F4 before exiting the UEFI firmware setup.
Manual update 10:Fig.12: Save changes
18. Check whether Secure Boot is active and the new keys have been loaded. Please note that after loading the "Factory Key Defaults", the manually loaded keys are no longer available.
You have exchanged the secure boot keys.