Garlin, thanks for the response. I will attempt the manual KEK enrollment with crossed fingers and fall to back deleting all keys method if necessary.
Barry
Hi Garlin, I'm here again needing your help with updating a Dell computer. This time it's my daughter's XPS 15 9550. Here is the result of the Check UEFI PK, KEK, DB and DBX command. I'm not sure of my next steps, and I don't want to guess. It does have the latest Dell BIOS.
Thanks
Barry
Hi garlin,
All sounds good. Thanks again for you expertise and help with this.
You know what's really funny is I have an older Lenovo laptop with a i7-6500 cpu and a BIOS dated 1011/2016 and these certificates were all updated via windows update sucessfully.
Thanks again
Barry
I completed the action above with the .der file
Re-ran the update script and here is the output:
Windows PowerShell
Copyright (C) Microsoft Corporation. All rights reserved.
Install the latest PowerShell for new features and improvements! Windows PowerShell update message FAQ - PowerShell...
Hi garlin, Making progress but not sure how to continue.
1) deleted keys and restart with Secure Boot enabled
2) failed restart, had to disable Secure Boot
3) successfully booted windows
4 executed Update-UEFI.bat and here's the output
Windows PowerShell
Copyright (C) Microsoft Corporation...
Hi , I didn't drill in the the Custom Mode options last night, so I just did and here are the options
So I assume I want to
1. select Delete All Secure Boot Variables
2. save settings
3. restart and let windows boot
4. run Update-UEFI.bat
5. cross fingers all goes well
Do I want to do a...
Hi Garlin, I found the setting to change to get to Key Management Screen.
When I followed steps 1-3 and then went to step 4 I there was no BIOS options for Key Management
1. Check if BitLocker encryption is enabled on the system drive, disable or suspend it.
2. Check if you're using...
Hi, I checked this page for the BIOS examples
How To Update Secure Boot Active Database from BIOS | Dell US
I have BIOS Type 4. however there the menus don't match exactly
The link you sent says this:
Perform the following steps:
Press F2 to enter the BIOS
Select Security tab along top...
Hi Garlin, silly me, I didn't look close enough to the options.
I have now set UEFI Boot Mode, Secure Boot Off
However, I don't see any options like Delete keys or Custom Mode or Manual Enrollment
I do see some cryptic settings like:
UEFI Firmware Capsule Updates and it is set to <ENABLE>...
Hi zbook, I am not using these adapters so I disabled them via Device Manager
In regard to the CA-2023 Certificates issues I am currently working with Garlin in this thread
I think at this point I am ready to close this Win11 update failure thread
Please let me know if you concur and I will...
Hi Garlin, I am not using either item mentioned in steps 1 and 2
When I enter the BIOS, the selections regarding Secure Boot Mode are
UEFI Boot Mode, Secure Boot ON
or
Legacy Boot Mode, Secure Boot Off
So I selected - Legacy Boot Mode, Secure Boot Off
I exited BIOS and let system attempt a...
Hi Team, can you help with this:
Checking for Administrator permission...
Running as administrator - continuing execution...
20 May 2026
Manufacturer: Dell Inc.
Model: XPS 8930
BIOS: Dell Inc., 1.1.31, 1.1.31, DELL - 1072009
Windows version: 25H2 (Build 26200.8457)
Secure Boot status...
Hi zbook, things are looking better
1. the stuck Selective Restart is no longer stuck. Normal startup can now be selected and the setting sticks betewwn selectiny apply and subsequent reboots. I'm not sure what fixed that but it's resolved
2. I went ahead and installed the the new Realtek...
Hi zbook, I took a look at USBDeview. I can see the "unknown" device but looking at all the fields doesn't help determine what device this is.
I did notice this - Can 2 devices have the same Port and Hub number?
Also I used Search PCI & USB Hardware Devices — DeviceHunt to search for the...