- Local time
- 10:19 AM
- Posts
- 3,637
- Location
- San Francisco, California USA
- OS
- WindowsXP/7/8/8.1/10/11,Linux,Android,FreeBSD Unix
I thought it was a PK because from what @garlin told me to do in the comment here:MobsyKey is NOT a PK. It's a DB. It should NOT be used as a PK, ever.
Unless you provide your own (but then don't use MosbyKey for that as again, it is NOT meant to be used as a PK) the PK is never saved. It is generated each time, and then, after the public key is saved as the PK, discarded from memory. This is how we ensure that a platform can not be compromised from the root of the chain, ever, because, with the Mosby defaults, nobody, including yourself or your motherboard's manufacturer, has the private key associated with the PK.
MosbyKey is what you can use to sign UEFI bootloaders for Secure Boot (as documented in the README). It will be automatically reinstalled as a DB key if present on your media. But it should never, ever be used as a PK.
Therefore, if you experience an issue after installing MosbyKey as the PK, I'm afraid you misunderstood how to use Mosby, and the error is on you...
Act now: Secure Boot certificates expire in June 2026
UPDATE: https://www.elevenforum.com/t/updating-microsoft-secure-boot-keys-before-expiration-in-june-2026.22477/ Windows IT Pro Blog: Prepare for the first global large-scale certificate update to Secure Boot. The Microsoft certificates used in Secure Boot are the basis of trust for operating...
www.elevenforum.com
I tried it using the Reset to Default keys and this is what it showed:

and then this is what it showed when Mosby was ran:

So at least that command is showing Mosby as a Generated PK but I am not having problems.
The only problem I am having is how to use the -db switch as I tried:
Mosby -db microsoftoptionromuefica2023.der
with the file on the UEFI Shell Drive which popped up a screen saying security violation and I needed to get to Setup mode again if I choose yes but Setup mode on Dell means deleting all the keys or the PK.
So what I ended up doing was as you had mentioned I can use DBUpdateOROM2023.bin so the methods which I tried is the UEFI Custom Key Management where I did a Amend from file and it added it without any issues. Just trying to learn how to use the -db switch so it can add the DB to the existing Mosby added keys.
My Computer
System One
-
- OS
- WindowsXP/7/8/8.1/10/11,Linux,Android,FreeBSD Unix
- Computer type
- Laptop
- Manufacturer/Model
- Dell XPS 15 9570
- CPU
- Intel® Core™ i7-8750H 8th Gen 2.2Ghz up to 4.1Ghz
- Motherboard
- Dell XPS 15 9570
- Memory
- 64GB using 2x32GB CL16 Mushkin redLine modules
- Graphics Card(s)
- Intel UHD 630 & NVIDIA GeForce GTX 1050 Ti with 4GB DDR5
- Sound Card
- Realtek ALC3266-CG
- Monitor(s) Displays
- 15.6" 4K Touch UltraHD 3840x2160 made by Sharp
- Screen Resolution
- 3840x2160 4K UltraHD
- Hard Drives
- Samsung MZ-V9P4T0B/AM 990 PRO 4TB PCIe®4.0 NVMe™ M.2 SSD was Toshiba KXG60ZNV1T02 NVMe 1TB SSD
- PSU
- Dell XPS 15 9570
- Case
- Dell XPS 15 9570
- Cooling
- Stock
- Keyboard
- Stock
- Mouse
- SwitftPoint ProPoint
- Internet Speed
- Comcast/XFinity 1.44Gbps/42.5Mbps
- Browser
- Microsoft EDGE (Chromium based) & Google Chrome
- Antivirus
- Windows Defender that came with Windows







