UEFI CA 2023 migration hits HP hard | Sure Start boot loops, 2018-and-earlier devices left EOSL
TL;DR
UEFI CA 2011 certificates expired in June; Microsoft has been pushing UEFI CA 2023 since early 2026. At the July Microsoft IT admin roundtable, admins reported extensive migration failures — especially on HP devices. HP Sure Start misreads the new cert as tampered and enters a boot loop; ProBook 640 G4 hits 0xC0000022 auth errors. HP 2018-and-earlier machines are EOSL and get no update.
UEFI CA 2011 certificates expired in June — old certs can no longer sign Microsoft boot manager files. Microsoft has been pushing the UEFI CA 2023 replacement since early 2026, theoretically a smooth migration. At the July Microsoft IT admin roundtable, the real-world feedback was "many devices can't migrate cleanly" — with HP devices hardest hit.
The bottleneck sits at the intersection of hardware age, BIOS firmware, and OEM support:
- HP commercial 2024+: ships with UEFI CA 2023 baked in, no BIOS update needed.
- HP commercial 2022-2023: BIOS update around September 30, 2025.
- HP commercial 2019-2021 (some 2018): BIOS update around December 31, 2025.
- HP 2018 and earlier: EOSL, no BIOS update.
The real crash is on HP Sure Start — some HP PCs installing CA 2023 enter continuous boot loops because Sure Start misreads the new certs as "tampered" and tries to overwrite them with the old certs from NVRAM protected storage. HP ProBook 640 G4 devices additionally saw Platform Key replacement fail with 0xC0000022 auth errors.
The enterprise IT bind: either update BIOS and risk Sure Start boot loops, or hold off and get locked out of future Windows updates. HP 2018-and-earlier commercial devices are effectively sentenced — the only path is full replacement.
This is Microsoft's first mandatory rotation of the Secure Boot trust chain in 15 years — Secure Boot, sold as "boot-time security," becomes the accelerator for retiring old hardware.
via landiannews / HP Support
The bottleneck sits at the intersection of hardware age, BIOS firmware, and OEM support:
- HP commercial 2024+: ships with UEFI CA 2023 baked in, no BIOS update needed.
- HP commercial 2022-2023: BIOS update around September 30, 2025.
- HP commercial 2019-2021 (some 2018): BIOS update around December 31, 2025.
- HP 2018 and earlier: EOSL, no BIOS update.
The real crash is on HP Sure Start — some HP PCs installing CA 2023 enter continuous boot loops because Sure Start misreads the new certs as "tampered" and tries to overwrite them with the old certs from NVRAM protected storage. HP ProBook 640 G4 devices additionally saw Platform Key replacement fail with 0xC0000022 auth errors.
The enterprise IT bind: either update BIOS and risk Sure Start boot loops, or hold off and get locked out of future Windows updates. HP 2018-and-earlier commercial devices are effectively sentenced — the only path is full replacement.
This is Microsoft's first mandatory rotation of the Secure Boot trust chain in 15 years — Secure Boot, sold as "boot-time security," becomes the accelerator for retiring old hardware.
via landiannews / HP Support