for me there's :
UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 8.0
EFI_CERT_SHA256_GUID Signatures: 492
and install media up to date as well
USB Drive J: "ESD-USB"
Boot File [Windows UEFI CA 2023] is ALLOWED...