Recent content by Capricornus


  1. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    I would like to give an update on my battle with my HP Z440 workstation. Last week I left off with the UEFI PK having (none) when I ran the check-UEFI -verbose script, which resulted in windows 11 not running in secure boot mode. So I tried to get back a UEFI PK. Searching on the internet did...
  2. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    On my HP Z440, i deleted the secure cert keys in the bios and ran the update script. That did not get me anywhere. I then reset the factory default certs in the bios, and ran Update_UEFI.bat -revoke. That worked and this time I got the dbx updates that gave me problems before: so, it confirmed...
  3. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    I rebooted and ran .\Update_UEFI-CA2023.ps1 -Revoke ERROR: Failed to append "dbxupdate.bin" to UEFI DBX.
  4. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    Running check-dbx.bat -verbose only gives: FAILED: Missing 11/289 EFI signatures from "dbxupdate.bin" SUCCESS: Matched 3/3 SVN signatures from "DBXUpdate2024.bin" SUCCESS: Matched 3/3 SVN signatures from "DBXUpdateSVN.bin"
  5. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    I ran the update script with the revoke option on my HP Z440, but I get this error: ERROR: Failed to append "dbxupdate.bin" to UEFI DBX And this is the output from check-uefi.bat -verbose: Windows 11 25H2 (26200.8655) Secure Boot: ON Virtualization Based Security: ON BitLocker on (C:) OFF...
  6. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    Having seen that there were updated scripts (2026-06-08), I ran them on my three computers. On my oldest computer (Lenovo all-in-one with a UEFI from 2012) it worked well. I updated the SVN to 9.0 and the latest Skusipolicy, and the dbx. On running an audit, all was well. The same for my newest...
  7. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    In Post #1736 I posted that I could not get my HP Z440 workstation to revoke, as I got an error. Today, having read this article Windows 11's Secure Boot 2023 updates are failing across some PCs, exposing a wider firmware problem what caught my attention in the article was this part: Some ASUS...
  8. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    Hazel123: the secure boot is on in the bios. It just shows up in another part of the bios, and I did not take a picture of that. Everything went well, just an error when trying to revoke the old certs. And I am trying to solve that error. I have had my machine running with Optional diagnostics...
  9. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    Concerning my HP Z440 workstation: Looking at the document L49253-001 from HP, labelled HP Sure Start Technical white paper, it states that the entry for Sure Start can be found in the UEFI under Security. I have no entry there for Sure Start nor anywhere else in the BIOS. So I am pretty...
  10. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    Looking at this link https://support.hp.com/us-en/document/ish_9642671-9641393-16 my HP Z440 workstation is not on the list of HP machines with Sure Start security. So, something else seems to be going on. Before I ran your scripts on the Z440, the device security in the settings of win 11 did...
  11. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    Meanwhile I checked on my very old Lenovo C340 all-in-one with the UEFI from 2012, and there too the same command (version 2026-5-8 I believe) had run without problem. So, there seems to be a problem with this HP Z440.
  12. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    Having updated my HP Z440 workstation, today I wanted to revoke the 2011 cert. I ran .\Update_UEFI-CA2023.ps1 -Revoke (running version 5-14) But that fails with this error: Error: failed to append "DBXUpdate2024.bin" to UEFI DBX When I ran the same command on the one machine that got an...
  13. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    I would like to give some feedback on updating my older HP Z440 workstation: I first had to remove the bios admin password by removing a jumper at position E49 on the mainboard. The manual says it is a blue jumper, but it looks green to me, especially when holding it up to natural light. That...
  14. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    I would like to update the secure boot certificates of an older HP Z440 workstation. It has a bios password on it, and the password can only be removed by removing a jumper on the mainboard. So a pain in the neck. Do I need to remove the password first for those scripts to work? I assume so, but...
Back
Top Bottom