UEFICA2023 requiring upgrade of UEFI version

Hi Mike,

I have been researching issues regarding the upcoming transition to UEFICA2023.
I have the G522. The appropriate registry key lists UEFICA2023 as "Not Started".
The G522 has an ASROCK MB with UEFI vs 3.06. From my research it appears that I need to upgrade to vs 4.10 for compatibility with UEFICA2023.
Although Microsoft is supposed to include the conversion to UEFICA2023 with a monthly windows update, my research suggests that the (passive) windows update method may not be as reliable as doing a manual upgrade.

I was already on the phone with Microcenter tech support and found out that they have not made provisions for dealing with this issue (unlike Dell and HP, etc). So it appears that I will need to upgrade the UEFI vs on my own. Knowing there is always the possibility of bricking the MB during an update, I am trying to make sure I do all the possible advised steps to have a smooth transition. One issue mentioned is that prior to the update, I should set all the UEFI settings back to default. Note that I have not made any changes to the UEFI setting since I got the G522.

I am curious to know if any changes to UEFI settings were made by your team during assembly and configuration of the G522. Additionally if you have any suggestions please let me know.

Thanks in advance,
Steve G

Answers

  • PowerSpec_MikeW
    PowerSpec_MikeW PowerSpec Engineer
    Seventh Anniversary 2500 Comments 100 Answers 250 Likes

    @Stevedg

    The secured boot certificates are pushed through Windows Update, we worked with the board vendors and verified their PK signatures were provided to Microsoft to make this possible. Go into your BIOS and check details on the KEK and DB. Let me know what you have.

  • Stevedg
    Stevedg ✭✭
    10 Comments First Anniversary
    KEK.jpeg Authorized Sigs.jpeg Forbidden Sigs.jpeg

    Hi Mike,

    See above screen pics for KEK, Authorized Sigs & Forbidden Sigs. I see that CA 2023 is in the KEK and authorized sigs. Does that mean CA2023 is fully implemented live, or just a preliminary stage? Please note that the associated registry key for UEFICA2023 still says "Not Started". Also I checked history of windows update files. There is no file in the history that references UEIFICA2023, yet, so I guess they have not sent it yet.

    So at this point what stage am I at re CA 2023?

    Steve G

  • PowerSpec_MikeW
    PowerSpec_MikeW PowerSpec Engineer
    Seventh Anniversary 2500 Comments 100 Answers 250 Likes

    @Stevedg

    Correct, you're good to go and the certificates are downloaded, it'll be active when the old certificates expire in June.

  • Stevedg
    Stevedg ✭✭
    10 Comments First Anniversary
    Thanks Mike. 
    One additional question.  Should I upgrade the firmware from 3.06 to the newest version 4.10?
    I have seen ASROCK advice that says that to assure continuing proper functionality using CA 2023, I should upgrade to 4.10 because it includes AGESA 1.3.0.0a. 

    Do you agree with this advice?

    If so should I get it from the ASROCK site (I notice you sometimes post firmware updates on community.microcenter)?

    If I do the upgrade, when done, do I need to change any UEFI settings? That’s why I was asking if you tweaked any settings during assembly, or left ASROCK default settings in place. 

    I really appreciate your help in making sense of this quite comprehensive and confusing topic. 

    Steve G
  • PowerSpec_MikeW
    PowerSpec_MikeW PowerSpec Engineer
    Seventh Anniversary 2500 Comments 100 Answers 250 Likes

    @Stevedg

    I'll work on a custom BIOS, it'll take a day or two.

    For the certificate, to clarify. If it's installed the the board, it's already active. That process you're mentioning in the registry doesn't need to occur, so it won't change.

  • Stevedg
    Stevedg ✭✭
    10 Comments First Anniversary

    Hi Mike,

    Thanks so much for the custom BIOS.

    • Just to verify, this is good for my G522 configured P.C?
    • I will follow procedure recommended from ASROCK site (see att ASROCK Instant Flash Guide.pdf).
    • The last step of those instructions, after the flash is complete, and the P.C. reboots say to go back into UEFI and "Load System Defaults". Since I will be flashing from your customized file, should I still follow this step, or should I skip Loading System Defaults at the end?

    Thanks again so much for your help.

    (I probably won't do the FLASH until next week.)

    Steve G

  • PowerSpec_MikeW
    PowerSpec_MikeW PowerSpec Engineer
    Seventh Anniversary 2500 Comments 100 Answers 250 Likes

    @Stevedg

    Yes, it's good for your system. I would load defaults, just to be safe. Enable EXPO/XMP as well.

  • Stevedg
    Stevedg ✭✭
    10 Comments First Anniversary
    Thanks so much. 
    Enjoy the holidays. 
    Steve G

Leave a Comment

Rich Text Editor. To edit a paragraph's style, hit tab to get to the paragraph menu. From there you will be able to pick one style. Nothing defaults to paragraph. An inline formatting menu will show up when you select text. Hit tab to get into that menu. Some elements, such as rich link embeds, images, loading indicators, and error messages may get inserted into the editor. You may navigate to these using the arrow keys inside of the editor and delete them with the delete or backspace key.

We love seeing what our customers build

Submit photos and a description of your PC to our build showcase

Submit Now
Looking for a little inspiration?

See other custom PC builds and get some ideas for what can be done

View Build Showcase

SAME DAY CUSTOM BUILD SERVICE

If You Can Dream it, We Can Build it.

Services starting at $149.99