Did you manually update your Secure Boot Keys ?


Yes i can manually put keys in but i can't seem to find the keys anywhere
 

My Computer My Computer

At a glance

Windows 1112th Gen Intel(R) Core(TM) i9-12900H (2.50 GHz)64.0 GB (63.7 GB usable)NVIDIA GeForce RTX 3080 Ti Laptop GPU (16 GB)
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
Maingear
CPU
12th Gen Intel(R) Core(TM) i9-12900H (2.50 GHz)
Motherboard
VECTOR Pro 2 15
Memory
64.0 GB (63.7 GB usable)
Graphics Card(s)
NVIDIA GeForce RTX 3080 Ti Laptop GPU (16 GB)
Hard Drives
INTEL SSDPEKNU020TZ
SAMSUNG MZVL22T0HBLB-00BTW
1. Download the scripts from here, and run:
garlin's PowerShell scripts for updating Secure Boot CA 2023

Code:
Update-UEFI.bat

2. A copy of the KEK CA 2023 cert file will be copied to the system drive's EFI volume. When adding the KEK key, browse for the folder "EFI\Certs". Under the folder, you should see the file.

3. After adding the key, restart Windows. Run the update script again.
Code:
Update-UEFI.bat

4. If the update script successfully added new certs, run the check script and post the output:
Code:
Check-UEFI.bat -Verbose
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2, Build 26200.9278Intel Core i5 14500, 14th Generation64GB DDR4GeForce RTX 4060
    OS
    Win 11 Pro 25H2, Build 26200.9278
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14500, 14th Generation
    Motherboard
    Gigabyte B760M G P WIFI
    Memory
    64GB DDR4
    Graphics Card(s)
    GeForce RTX 4060
    Sound Card
    Chipset Realtek
    Monitor(s) Displays
    LG 45" Ultragear & Acer 24" 1080p
    Screen Resolution
    5120x1440 & 1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 3D NAND NVMe M.2 SSD (O/S)
    Silicon Power 2TB US75 NVMe PCIe Gen4 M.2 2280 SSD (backup)
    Crucial BX500 2TB 3D NAND (2nd backup)
    Seagate 4TB Ironwolf, rotating HDD secondary backup
    External off-line backup Drives: 2 NVMe 4TB drives in external enclosures
    PSU
    Thermaltake Toughpower GF3 750W
    Case
    LIAN LI LANCOOL 216 E-ATX PC Case
    Cooling
    Lots of fans!
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • At a glance

    Win 11 Pro 25H2, Build 26200.9168Intel Core i5 1440032GB DDR5Intel 700 Embedded GPU
    Operating System
    Win 11 Pro 25H2, Build 26200.9168
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14400
    Motherboard
    Gigabyte B760M DS3H AX
    Memory
    32GB DDR5
    Graphics card(s)
    Intel 700 Embedded GPU
    Sound Card
    Realtek Embedded
    Monitor(s) Displays
    27" HP 1080p
    Screen Resolution
    1920x1080
    Hard Drives
    Crucial P310 2TB NVMe Gen4 SSD
    Samsung EVO 990 2TB NVMe Gen4 SSD
    Samsung 2TB SATA SSD
    Seagate 4TB Ironwolf, rotating HDD secondary backup
    PSU
    Thermaltake Smart BM3 650W
    Case
    Okinos Micro ATX Case
    Cooling
    Fans
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • Nimo N171 17" Laptop, (Intel i3-1215U, 16GB RAM, 2TB NVMe, Win11 Pro)
    Acemagic Vista Mini PC V1 (Intel N150, 16GB RAM, 1TB NVMe, Win11 Pro)
    HP ENVY h8-1540t, (24GB RAM, 2TB SSD, 2TB HDD, Win11 Pro)
It won't execute that bat command though I've tried that too. I can manually update them through the bios if I knew which file they were in on windows 11
 

My Computer My Computer

At a glance

Windows 1112th Gen Intel(R) Core(TM) i9-12900H (2.50 GHz)64.0 GB (63.7 GB usable)NVIDIA GeForce RTX 3080 Ti Laptop GPU (16 GB)
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
Maingear
CPU
12th Gen Intel(R) Core(TM) i9-12900H (2.50 GHz)
Motherboard
VECTOR Pro 2 15
Memory
64.0 GB (63.7 GB usable)
Graphics Card(s)
NVIDIA GeForce RTX 3080 Ti Laptop GPU (16 GB)
Hard Drives
INTEL SSDPEKNU020TZ
SAMSUNG MZVL22T0HBLB-00BTW
EOSL Dell Inspiron 5559, BIOS 1.9.0 (final). After the 2023 db certs landed, BitLocker TPM protector failed with 0x80310002, PCR7 Binding Not Possible, Event 813 naming 'dbx', Event 1796 “BIOS did not correctly communicate with the TPM.”

Cause is not a dead TPM. This BIOS has a ~32 KiB TCG event log. Full db + current dbx overflows it. Firmware stops writing the log but keeps extending PCRs, so Windows cannot bind PCR 7.

Workaround that restored PCR 7,11: delete dbx in Expert Key Management. Do not clear the TPM. Windows servicing will try to put the full dbx back; HighConfidenceOptOut = 1 stopped that here.

Write-up and MeasuredBoot parser: GitHub - Sizzlechest/inspiron-5559-tcg-log-overflow: Dell Inspiron 5459/5559/5759 BIOS 1.9.0: ~32KiB TCG event log buffer silently truncates measured boot and breaks BitLocker PCR7

Same family: 5459 / 5559 / 5759. If anyone else on BIOS 1.9.0 can check dir C:\Windows\Logs\MeasuredBoot -Force and whether the newest log’s firmware portion dies right after db, that would confirm scope.
 

My Computer My Computer

At a glance

Windows 10 LTSCIntel Core i5-6200U8 GBIntel HD Graphics 520
OS
Windows 10 LTSC
Computer type
Laptop
Manufacturer/Model
Dell Inspiron 5559
CPU
Intel Core i5-6200U
Motherboard
Dell 0WTXH9 A00
Memory
8 GB
Graphics Card(s)
Intel HD Graphics 520
Sound Card
Realtek onboard
Monitor(s) Displays
15.6" built-in
Browser
Firefox
Other Info
BIOS 1.9.0 (2020-09-07, final). Intel PTT TPM 2.0. UEFI, Secure Boot On.
Back
Top Bottom