Did you manually update your Secure Boot Keys ?


I have a self built desktop PC based on an Asus TUF GAMING Z790-PLUS WIFI motherboard so do I need to do anything?
ASUS is the motherboard manufacturer. They would provide the UEFI updates in their "Drivers" section.
 

My Computer

System One

  • OS
    Windows 7
I have a self built desktop PC based on an Asus TUF GAMING Z790-PLUS WIFI motherboard so do I need to do anything?

You can use @garlin script to check CA 2023 certificate. If it is not there, you can wait for Microsoft to update or add it manually.
 

My Computer

System One

  • OS
    Windows 11, version 25H2 (26200)
    Computer type
    PC/Desktop
    CPU
    AMD Ryzen 9 9950X 16-Core Processor
    Motherboard
    ASRock B650M PG Riptide
    Memory
    DDR5-6000 (CL36) 64.0 GB
    Graphics Card(s)
    NVIDIA GeForce RTX 4090
    PSU
    1200W
    Case
    Phanteks Enthoo Pro 2
    Cooling
    Noctua NH-D12L
You would be surprised how many ElevenForum users actively use UUP dump, combined with Rufus.

many ElevenForum users =/= global users.

You can't require all people to download Windows ISOs from UUP.
 

My Computer

System One

  • OS
    Windows 11, version 25H2 (26200)
    Computer type
    PC/Desktop
    CPU
    AMD Ryzen 9 9950X 16-Core Processor
    Motherboard
    ASRock B650M PG Riptide
    Memory
    DDR5-6000 (CL36) 64.0 GB
    Graphics Card(s)
    NVIDIA GeForce RTX 4090
    PSU
    1200W
    Case
    Phanteks Enthoo Pro 2
    Cooling
    Noctua NH-D12L
UUP dump already supports the creation of CA 2023-compatible ISO's, all you have to do is to edit ConvertConfig.ini before running their execution script. You change "UpdtBootFiles=1".

This is within easy reach of less technical users.
i would but i dont know how to do that , can u explain in detail how to do it please
 

My Computer

System One

  • OS
    WINDOWS 11 WINDOWS 10
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP H8 1360T
    CPU
    Intel(R) Core(TM) i7 -3770K CPU 3.50 GZ 3501 4 CORE
    Motherboard
    PEGATRON 2AD5
    Memory
    32.0 GB (31.9 GB usable)
    Graphics Card(s)
    AMD RADEON TM R5240 INTELL HD GRAPHICS 4600 TIGER 1+1 USB
    Sound Card
    AMD HD . IDT
    Monitor(s) Displays
    AOC WAL MART SPECIAL . HP 2311 IX IPS LED DELL 1708 FP
    Screen Resolution
    1920 X 1080 1600X900 1280X940
    Hard Drives
    1 FAXING S 100 512GB 1 KINGSTON 120 GB SSD 1 X12 SSD 512 GB
    PSU
    300 WATT HP
    Case
    FULL
    Cooling
    ON BOARD FAN
    Keyboard
    LOGITEC K 520 WIRELESS
    Mouse
    LOGITEC M 510 WIRELESS
    Internet Speed
    55 UP 11.2 DOWN
    Browser
    CHROME EDGE
    Antivirus
    WINDOWS SECUIRTY
    Other Info
    NON SUPPORTED HARDWARE FOR WINDOWS 11
@garlin Done. Thanks. This is a new computer so it should be OK. What you think?

Secure boot Bo.webp

Bo
 

My Computer

System One

  • OS
    Windows11
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP
    Memory
    16GB
    Keyboard
    HP 310
    Mouse
    HP
    Browser
    Firefox
i would but i dont know how to do that , can u explain in detail how to do it please
If you have never used UUP dump, then don't waste your time on it because it's not needed yet. Re-installing Windows will not wipe out the current UEFI settings, and you can always disable Secure Boot from BIOS (which allows any version of Windows to run).

UUP dump instructions:
1. Follow the normal process of picking a Windows build (typically the latest or near latest build, because it guarantees the Monthly Update has the extra CA 2023 files included).
2. Download the ZIP file they created for you.
3. Extract the ZIP file.
4. Edit ConvertConfig.ini inside the extract folder. Change "UpdtBootfiles=0" to "=1"
5. Run the Windows cmd script likely you normally would do.
6. The created ISO will be compliant.
7. Use Rufus to convert the ISO to an USB drive.
 

My Computer

System One

  • OS
    Windows 7
@garlin Done. Thanks. This is a new computer so it should be OK. What you think?
You're good for now. This PC will accept either the old or new boot files for Windows.

Don't ban the old CA 2011 (under DBX) until you've updated your copy of the Windows ISO. This is where MS expects you to be in the process. Sometime next year, MS will do the banning of CA 2011 for you.
 

My Computer

System One

  • OS
    Windows 7
You're good for now. This PC will accept either the old or new boot files for Windows.

Don't ban the old CA 2011 (under DBX) until you've updated your copy of the Windows ISO. This is where MS expects you to be in the process. Sometime next year, MS will do the banning of CA 2011 for you.
Alright, so basically I reckon that means I don't have to do anything for this computer. What is left to do, is Microsoft that will do it with an update. Thanks.

Bo
 

My Computer

System One

  • OS
    Windows11
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP
    Memory
    16GB
    Keyboard
    HP 310
    Mouse
    HP
    Browser
    Firefox
Alright, so basically I reckon that means I don't have to do anything for this computer. What is left to do, is Microsoft that will do it with an update. Thanks.

Bo
I think the Microsoft developers are working on it, trying to figure out how they can add more bugs to Windows with this update—but they haven’t succeeded. That’s why no updates have been released yet.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    Huawei MateBook D15
    CPU
    Ryzen 5 3500U
    Memory
    8GB
    Graphics Card(s)
    Vega 8
    Screen Resolution
    FHD
    Hard Drives
    256GB Samsung SSD + 1TB HDD
    Browser
    Microsoft Edge
    Antivirus
    ESET Smart Security Premium
  • Operating System
    Windows 10 Enterprise LTSC 21H2
    Computer type
    Laptop
    Manufacturer/Model
    MSI GS73 6RF Stealth Pro
    CPU
    intel core i7 6700HQ
    Memory
    16GB
    Graphics card(s)
    Nvidia Geforce GTX1060 (6GB)
    Screen Resolution
    FHD
    Hard Drives
    128GB SSD + 1TB HDD
    Browser
    Microsoft Edge
    Antivirus
    Windows Defender
UUP dump instructions:
1. Follow the normal process of picking a Windows build (typically the latest or near latest build, because it guarantees the Monthly Update has the extra CA 2023 files included).
2. Download the ZIP file they created for you.
3. Extract the ZIP file.
4. Edit ConvertConfig.ini inside the extract folder. Change "UpdtBootfiles=0" to "=1"
5. Run the Windows cmd script likely you normally would do.
6. The created ISO will be compliant.
7. Use Rufus to convert the ISO to an USB drive.

For those using UUPdump for the first time, the process of creating the ISO can take a lot of time - at least it does for me. My internet connection is 300 Mbits/sec, and creating the ISO takes about an hour for me. Maybe others have a different experience?

Anyway, I first tried it about a month ago, and after it had been running for about a half an hour, I falsely assumed something was wrong and stopped the process. Then I tried to delete the files and directories it had created, and Windows wouldn't let me, even with an Admin account. As I recall, I had to mess with directory and/or file ownership to be able to delete the data.

So be patient as the process runs. After a completed run, the downloaded files and the directories created can be deleted with no problem.

I just upgraded both my machines from W10 to W11 last week using the process above to make a bootable Windows 11 23h2 USB stick with the 2023 boot certificate. I did an in-place upgrade (running setup.exe on the USB drive from within Windows 10), so strictly speaking, I didn't need the USB drive to be bootable on a machine having the 2011 certificates revoked. But it does so just fine, so I have it if I need it.
 
Last edited:

My Computer

System One

  • OS
    Windows 11 pro 25h2
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    AMD Ryzen 7 5700G
    Motherboard
    MSI B450M Bazooka, BIOS version 7A38vHJ5 (latest beta as of 2025-09-23)
    Memory
    64 GB G.Skill (F4-3200C16Q-64GVK)
    Graphics Card(s)
    Integrated into CPU
    Sound Card
    Realtek (built into motherboard)
    Monitor(s) Displays
    Generic HDMI
    Screen Resolution
    1080p
    Hard Drives
    System and apps: SK hynix Gold P31 1TB M.2
    Data: Toshiba HDWQ140 4TB internal SATA
    PSU
    Seasonic 400W SS-400FL2 fanless
    Case
    Fractal Design Define R5
    Cooling
    Cooler Master Hyper 212 Evo
    Keyboard
    Lenovo Preferred Pro II Wired External USB Keyboard (4X30M86879)
    Mouse
    Belkin cheapo corded USB mouse
    Internet Speed
    300 MBit/sec
    Browser
    Firefox
    Antivirus
    Windows Defender
Anyway, I first tried it about a month ago, and after it had been running for about a half an hour, I falsely assumed something was wrong and stopped the process. Then I tried to delete the files and directories it had created, and Windows wouldn't let me, even with an Admin account. As I recall, I had to mess with directory and/or file ownership to be able to delete the data.
Temporarily disabling Defender or your 3rd-party AV while it's running will dramatically speed up performance.
 

My Computer

System One

  • OS
    Windows 7
Temporarily disabling Defender or your 3rd-party AV while it's running will dramatically speed up performance.

I have real-time protection disabled in Group Policy Editor, as it speeds up C++ compilation in Visual Studio quite a bit. I just manually check downloaded files before executing them (except for Visual Studio updates that just run). My data drive is a hard drive, not an SSD, so maybe this contributes. Is there more that can be done?
 

My Computer

System One

  • OS
    Windows 11 pro 25h2
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    AMD Ryzen 7 5700G
    Motherboard
    MSI B450M Bazooka, BIOS version 7A38vHJ5 (latest beta as of 2025-09-23)
    Memory
    64 GB G.Skill (F4-3200C16Q-64GVK)
    Graphics Card(s)
    Integrated into CPU
    Sound Card
    Realtek (built into motherboard)
    Monitor(s) Displays
    Generic HDMI
    Screen Resolution
    1080p
    Hard Drives
    System and apps: SK hynix Gold P31 1TB M.2
    Data: Toshiba HDWQ140 4TB internal SATA
    PSU
    Seasonic 400W SS-400FL2 fanless
    Case
    Fractal Design Define R5
    Cooling
    Cooler Master Hyper 212 Evo
    Keyboard
    Lenovo Preferred Pro II Wired External USB Keyboard (4X30M86879)
    Mouse
    Belkin cheapo corded USB mouse
    Internet Speed
    300 MBit/sec
    Browser
    Firefox
    Antivirus
    Windows Defender

My Computers

System One System Two

  • OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    Huawei MateBook D15
    CPU
    Ryzen 5 3500U
    Memory
    8GB
    Graphics Card(s)
    Vega 8
    Screen Resolution
    FHD
    Hard Drives
    256GB Samsung SSD + 1TB HDD
    Browser
    Microsoft Edge
    Antivirus
    ESET Smart Security Premium
  • Operating System
    Windows 10 Enterprise LTSC 21H2
    Computer type
    Laptop
    Manufacturer/Model
    MSI GS73 6RF Stealth Pro
    CPU
    intel core i7 6700HQ
    Memory
    16GB
    Graphics card(s)
    Nvidia Geforce GTX1060 (6GB)
    Screen Resolution
    FHD
    Hard Drives
    128GB SSD + 1TB HDD
    Browser
    Microsoft Edge
    Antivirus
    Windows Defender
Search indexing doesn't really matter, unless you're running UUP dump in the early morning hours, when file indexing is run.
 

My Computer

System One

  • OS
    Windows 7
Would downloading an ISO from Microsoft and doing an in-place upgrade/repair result in updated UEFI/secure boot keys?
 

My Computers

System One System Two

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    Intel i7-7700K
    Motherboard
    Asus Prime Z-270A
    Memory
    32GB 2666Mhz (Kingston Hyper X Fury)
    Graphics Card(s)
    Asus Nvidia 1050Ti
    Sound Card
    N/A
    Monitor(s) Displays
    Samsung C27F390
    Screen Resolution
    1920 x 1080
    Hard Drives
    1TB Western Digital SN770 (System) and 2TB Western Digital SN770 (Storage)
    Antivirus
    Windows Security
  • Operating System
    Windows 11 Home
    Computer type
    Laptop
    Manufacturer/Model
    Dell/XPS 15 9510
    CPU
    i9-11900H
    Motherboard
    Unknown
    Memory
    32GB
    Graphics card(s)
    Integrated Intel and Nvidia 3050Ti
    Sound Card
    Integrated (Realtek)
    Monitor(s) Displays
    None
    Screen Resolution
    1920 x 1200 (non-Touch)
    Hard Drives
    2TB SK Hynix P41 Platinum
    Antivirus
    Windows Security
Would downloading an ISO from Microsoft and doing an in-place upgrade/repair result in updated UEFI/secure boot keys?
A good question for where some look amiss.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro x64 24H2
    Computer type
    PC/Desktop
    CPU
    Ryzen 9 5900X
    Motherboard
    ASRock B550 PG Velocita (UEFI-BIOS 3.90)
    Memory
    64 GB G.Skill RipJaws V F4-3200C16D-64GVK
    Graphics Card(s)
    ASRock Steel Legend Arc B580 12 GB
    Monitor(s) Displays
    Alienware AW3423DWF OLED ultrawide
    Hard Drives
    Samsung 990 Pro 1 TB NVMe SSD
    PSU
    eVGA Supernova 750 G3
    Case
    Corsair 275R
    Internet Speed
    VTel FTTH 1 Gb down and 1 Gb up
  • Computer type
    PC/Desktop
    CPU
    Ryzen 7 5800X3D
    Motherboard
    Asus ROG Strix B550-F Gaming (UEFI-BIOS version 3607)
    Memory
    32 GB (2x16 GB G.Skill TridentZ Neo)
    Graphics card(s)
    Sapphire Nitro+ Radeon RX 6750 XT
    Hard Drives
    Samsung 970 Pro 512 GB NVMe SSD
    PSU
    Corsair RM850x
    Case
    Fractal Focus G
Would downloading an ISO from Microsoft and doing an in-place upgrade/repair result in updated UEFI/secure boot keys?
No, the Secure Boot certs are only updated by changing some reg keys and running a Windows task. If you wiped your disk and reinstalled Windows, none of the UEFI settings will be changed. The installation or upgrade of Windows does not touch UEFI.

Now UEFI might care about which files are written to disk, if Secure Boot is enabled.
 

My Computer

System One

  • OS
    Windows 7
Disable "SysMain" and "Search indexing".
Indexing was disabled, but I was not aware of SysMain. I disabled that, so we'll se how it goes next time. That will be a while though, as I intend to run W11 23h2 until support for it ends in November.
 

My Computer

System One

  • OS
    Windows 11 pro 25h2
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    AMD Ryzen 7 5700G
    Motherboard
    MSI B450M Bazooka, BIOS version 7A38vHJ5 (latest beta as of 2025-09-23)
    Memory
    64 GB G.Skill (F4-3200C16Q-64GVK)
    Graphics Card(s)
    Integrated into CPU
    Sound Card
    Realtek (built into motherboard)
    Monitor(s) Displays
    Generic HDMI
    Screen Resolution
    1080p
    Hard Drives
    System and apps: SK hynix Gold P31 1TB M.2
    Data: Toshiba HDWQ140 4TB internal SATA
    PSU
    Seasonic 400W SS-400FL2 fanless
    Case
    Fractal Design Define R5
    Cooling
    Cooler Master Hyper 212 Evo
    Keyboard
    Lenovo Preferred Pro II Wired External USB Keyboard (4X30M86879)
    Mouse
    Belkin cheapo corded USB mouse
    Internet Speed
    300 MBit/sec
    Browser
    Firefox
    Antivirus
    Windows Defender
Indexing was disabled, but I was not aware of SysMain. I disabled that, so we'll se how it goes next time.
If that is a HDD then you may want to leave SysMain on.
SysMain is what used to be called superfetch and can help speed up file access on HDD.
SSD not so much gained from superfetch/SysMain.
 
Last edited:

My Computer

System One

  • OS
    Windows 11 Pro

Latest Support Threads

Back
Top Bottom