This article provides step-by-step instructions for manually updating the Microsoft CA 2023 certificates through Windows on Elo All-in-One systems with Intel-based hardware.
Microsoft CA 2023 Certificate Update Guide
Follow the steps below to place the system in Setup Mode, import the updated certificates, verify the installation, and re-enable Secure Boot.
Step 1: Enter BIOS and Enable Setup Mode
- Restart the system and repeatedly press Delete during startup to enter the BIOS Setup Utility.
- Navigate to Security > Secure Boot Menu.
- Configure the following settings:
- Secure Boot: Disabled
- Secure Boot Mode: Custom
- Select Reset To Setup Mode.
-
When the confirmation message appears, select Yes:
“Deleting all variables will reset the system to Setup Mode. Do you want to proceed?”
-
Confirm that the BIOS settings match the following example:
- Press F10 to save the changes and exit the BIOS.
Step 2: Import the Certificates Using PowerShell
-
Open PowerShell as Administrator:
- Open the Windows Start menu and search for PowerShell.
- Right-click Windows PowerShell, and then select Run as administrator.
- If prompted by User Account Control, select Yes.
- Download ELO_Key_Update.zip, and then extract its contents to a folder such as
D:\ELO_Key_Update. -
In PowerShell, navigate to the extracted folder:
cd D:\ELO_Key_Update -
Run the following command to verify that the system is in Setup Mode:
Get-SecureBootUEFI -Name SetupModeThe output should show a value of
1. Do not continue unless Setup Mode is active. -
Enter the following commands individually and in the order shown:
$CurrentTime = (Get-Date).ToString("yyyy-MM-ddTHH:mm:ssZ") Set-SecureBootUEFI -Name KEK -Content (Get-Content "KEK_SigList.bin" -Raw -Encoding Byte) -Time $CurrentTime Set-SecureBootUEFI -Name DB -Content (Get-Content "DB_SigList.bin" -Raw -Encoding Byte) -Time $CurrentTime Set-SecureBootUEFI -Name DBX -Content (Get-Content "DBX_Content.bin" -Raw -Encoding Byte) -Time $CurrentTime Set-SecureBootUEFI -Name PK -ContentFilePath PK.sig -SignedFilePath PK.ser.p7 -Time $CurrentTime -
Confirm that each command completes successfully without errors.
The example above shows a Setup Mode value of 1 followed by the successful execution of each Set-SecureBootUEFI command.
Step 3: Verify the Certificate Update
Run the following commands individually. Each command should return True.
[System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match 'Windows UEFI CA 2023'
[System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match 'Microsoft UEFI CA 2023'
[System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match 'Microsoft Option ROM UEFI CA 2023'
[System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI KEK).bytes) -match 'Microsoft Corporation KEK 2K CA 2023'True, the Microsoft CA 2023 certificates were installed successfully.Step 4: Re-enable Secure Boot
- Restart the system and press Delete during startup to enter the BIOS Setup Utility.
- Navigate to Security > Secure Boot Menu.
- Set Secure Boot to Enabled.
- Press F10 to save the changes and exit the BIOS.
- Allow Windows to start normally.
Additional Notes
- Use only the official files included in the ELO_Key_Update package.
- If a command fails, verify the folder location, file names, and command spelling before trying again.
- Do not continue if
Get-SecureBootUEFI -Name SetupModedoes not return a value of1. - If the system does not start after completing the update, contact Elo Technical Support.
Keywords
EloPOS, EloPOS Pack, PayPoint for Windows, Microsoft CA 2023, certificate update, BIOS, Secure Boot, PowerShell, UEFI, Setup Mode
Please report any broken links by emailing elo.support@zebra.com and include a link to the knowledge article