Recent content by Ingenon


  1. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    It was my mistake that the first attempt using Mosby failed. Where the menu shows UEFI 2.2 releases to pick, it lists 26H1, 25H2, 25H1, as choices. Without any written direction, I picked the version 25H2 that matches the installed version of Windows 11 on my Lenovo T460 (25H2). My mistake, but...
  2. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    Update Script run once on each computer. Success! Windows Security says Secure Boot is on and all required certificate updates have been applied. No further certificate changes are needed. Thanks @garlin @Dirtyflash @Akeo for helping update my Lenovo T460 and HP EliteDesk 800 G1!
  3. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    I tried what you said and saw no difference in the results. Then I formatted the USB flash drive and started over. When I picked the UEFI Shell in Rufus, I picked 26H1, even though I know that my Lenovo is running 25H2. And then I got different results. [Mosby session started: 2026-05-18...
  4. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    [Mosby session started: 2026-05-18 14:23:04 [UTC] UEFI v2.40 (Lenovo, 0x00001450) LENOVO R06ET71W (1.45 ) LENOVO 20FN002NUS Generating Secure Boot signing credentials... Saved Secure Boot signing credentials as 'MosbyKey' Generating PK certificate... Installing SSPV: 'SkuSiPolicyVersion...
  5. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    I looked online and could not find any BIOS for the Lenovo T460 other than the current version 1.45.1.11 dated 06 Mar 2022 which does not include the CA 2023 certificates. I tried the BIOS option to clear to defaults, but on the Lenovo T460 BIOS it says that does not clear Security settings...
  6. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    This BIOS is limited to Factory/Delete All Keys. I have tried twice to reflash the BIOS, once while Windows was running, and the second time from a bootable USB, and both times the Lenovo installer says it is the same version as is already installed and gives me the option of Exit (only).
  7. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    I am glad that your notebook is working without the PK. The following is a full listing of commands entered and responses. Boot into UEFI, Disabled Secure Boot, Reset to Setup Mode, Clear All Secure Boot Keys. Download latest version of script from GitHub. Unzip files to c:\temp. Open Terminal...
  8. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    Thanks for the reply! Option 1 is not possible, because the Lenovo UEFI does not have KEK key file management option. And I already have the latest BIOS. Option 2 is a repeat of what I already did. I tried it again, in UEFI setting the following: Secure Boot [Disabled] Restore Factory Keys...
  9. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    Lenovo T460, no longer supported by Lenovo, no updated BIOS available. Trying to avoid having secure boot disabled on a working Windows 11 with all updates installed laptop. Boot into UEFI, Disabled Secure Boot, Reset to Setup Mode, Clear All Secure Boot Keys. Download latest version of script...
Back
Top Bottom