Recent content by misar


  1. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    For the avoidance of doubt I am grateful to garlin for the time he takes responding to my questions AND for his scripts which I used back in May when I first posted about this issue. My problem is twofold and entirely of Acer's making. Firstly, as they have not updated the BIOS of my two...
  2. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    I admit to being confused by this. You seem to be saying that Secure Boot protections will cease without the current 2023 certificate update. I was under the impression that Secure Boot protections will continue to function but the device will stop receiving updates to key components: Windows...
  3. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    Fair enough but there is another side to this rather unique update. What are you missing if you don't attempt to force it? My estimation is probably not a lot, especially if you have aging hardware that has or will soon be declared obsolete by MS. There must have been some examples but over...
  4. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    Back in May I noticed my Acer laptops had an issue with the cert update, found garlin's advice/scripts, and discovered that his instructions to add the KEK did not match my very simple Acer BIOS. He and some others kindly responded to my request for advice (#1977) but I realised I was out of my...
  5. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    Thanks but TBH I am totally confused by your description and the subsequent discussion. I think before moving ahead I need to spend time studying the scripts and garlin's detailed notes but it would also help if you could post your copy of the script output. One question, does your BIOS have an...
  6. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    Tried the suggestion but the BIOS interface was unchanged after rebooting. Re Garlin's suggestion a supervisor password had to be set before anything important in the BIOS could be changed.
  7. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    As I said previously, the Acer InsydeH20 interface on my laptops has no option to manage keys or "enroll a file". It seems that the only likely option I could find ("users may select all available .efi in FAT32 partitions and add the .efi hash into secure DB") is intended to add a new boot...
  8. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    Ran the script but same KEK problem as before. It seems Acer have not obliged. Very annoying because I have a really old Lenovo stuck on Windows 10 and the extended security automatic update worked perfectly. PS D:\Install\SecureBoot-CA-2023-Updates\SecureBoot-CA-2023-Updates.v2026.05.27>...
  9. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    Thanks. I updated the BIOS to v1.10 and it appears unchanged with the same cert update command that I noted in #1981. What do you suggest as next step? I could wait to see what Windows Update does in due course or should I now run your automatic update script?
  10. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    I previously did several checks and all the 2023 certs are present except KEK. Here is the output from Check-UEFI.bat -Verbose Windows 11 25H2 (26200.8457) Secure Boot: ON Virtualization Based Security: ON BitLocker on (C:) OFF BIOS Firmware ------------- Acer Swift SFA16-41...
  11. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    One of the laptops is less than two years old so I would have thought Acer/Insyde need to do something. I'm rather nervous with Case 4 so will wait until the old certs actually expire and only then if necessary resort to deleting all keys. Thanks again for the advice and your very fast response.
  12. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    I looked again at the BIOS and the help notes say "users may select all available .efi in FAT32 partitions and add the .efi hash into secure DB". I assume that is why the .der file is not listed. Does that mean the manual part of Case 3 will still fail? There is no other option to add a cert.
  13. Solved Updating Secure Boot on Alienware Aurora R7

    Thanks for the very quick reply. I have reposted as suggested. Re the folder, the option is "Select an UEFI file as trusted for executing". When I do that it lists HDD0 and hitting enter again appears to select <EFI>. That has a list of folders but no files.
  14. Solved garlin's PowerShell scripts for updating Secure Boot CA 2023

    (Repost from another thread) I have two Acer laptops running 25H2 and with the InsydeH20 UEFI BIOS. Windows update did a partial certificate update but failed as the new KEK has not been provided by the OEM. Using garlin's manual suggestion I copied "microsoft corporation kek 2k ca 2023.der" to...
  15. Solved Updating Secure Boot on Alienware Aurora R7

    I have two Acer laptops running 25H2 and with the InsydeH20 UEFI BIOS. Windows update did a partial certificate update but failed as the new KEK has not been provided by the OEM. Using garlin's manual suggestion I copied "microsoft corporation kek 2k ca 2023.der" to the EFI folder. The BIOS...
Back
Top Bottom