Did you manually update your Secure Boot Keys ?


hmmm . strange my ca 2011 is not revoked but i still used rufus to make the 25h2 iso to ca 2023 . ! think i got my iso for 25h2 from windows central website.

Part 2: Creating Windows 11 installation media that works on platforms where PCA 2011 has been revoked.​

This task is a lot easier than the previous one. However it requires the use of Rufus v4.10 or later.

  1. In Rufus, select a Windows 11 25H2 ISO (Note that Windows 11 24H2 ISOs will not work on account that Microsoft screwed up compatibility with Windows UEFI CA 2023 in those images. Only the Windows 11 25H2 ISOs are compatible with a Windows UEFI CA 2023 installation).
  2. Click START and, on the Windows User Experience dialog make sure to check the Use 'Windows CA 2023' signed bootloaders option as well as the Remove requirement for 4GB+ RAM, Secure Boot and TPM 2.0 option, as Rufus 4.10 will produce an error otherwise (please note that, contrary to what you might believe, this option will still use TPM and Secure Boot if available as it's simply a "bypass if not present", NOT a "disable if present"), along with any other installer customisation option you wish to enable.
  3. Let Rufus create the media and boot it on the target platform. Because Rufus ensured that the UEFI bootloaders on your media are the Windows UEFI CA 2023 signed ones, instead of the PCA 2011, you will then be able to proceed to a full installation of Windows without having to disable Secure Boot.
Ok i will give these steps a try first thing in morning to create my updated Windows 11 25H2 USB boot drive. As right now kinda dark in room, even with the Lamp on and every RGB light i got available, still can't see the rear system ports that well lol
(Currently searching for new batteries for dead flashlight lol--so far no luck in finding any thus far lol))--Found the batteries, i can see a bit again lol


But in Morning i'll get it done for sure
 
Last edited:

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8037AMD Ryzen 7700X32GB DDR 5 RGB 5600MhzRadeon 7800XT
    OS
    Windows 11 Pro 25H2 26200.8037
    Computer type
    PC/Desktop
    Manufacturer/Model
    PreBuilt
    CPU
    AMD Ryzen 7700X
    Motherboard
    MSI B650 VC WIfi Rev 1.0
    Memory
    32GB DDR 5 RGB 5600Mhz
    Graphics Card(s)
    Radeon 7800XT
    Sound Card
    Onboard Audio
    Monitor(s) Displays
    Asus VG245H
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 990 Evo Plus NVMe Boot
    Samsung 990 Pro 1TB Game NVMe



    External
    Western Digital Elements 500GB
    Western Digital My Passport 2TB Blue
    Western Digital My Passport 2TB Red
    Toshiba 2TB in External Enclosure
    Seagate 8TB in External Enclosure
    Seagate 1TB Portable USB 3 External Drive
    Western Digital My Book 8TB (Primary Backup drive)
    Western Digital Black 4TB In External Enclosure
    PSU
    750 Watt High Power
    Case
    Lian Li Lan Cool 216 ARGB Airflow
    Cooling
    2 160MM Front, 1 140MM Rear Exhaust
    Keyboard
    Logitech G513
    Mouse
    Logitech G502 X
    Internet Speed
    Gigabit 1100Mb/35 Upload
    Browser
    MS Edge Chromium and Bing Search
    Antivirus
    Windows Defender, Malwarebytes Premium
    Other Info
    UEFI, Secure Boot, TPM 2.0, Macrium Reflect X
  • At a glance

    Windows 11 Pro 25H2 26200.8037Ryzen 7 7735HS16GB DDR 5AMD Radeon™ 680M & Radeon 7700S
    Operating System
    Windows 11 Pro 25H2 26200.8037
    Computer type
    Laptop
    Manufacturer/Model
    Asus TUF A16 Advantage Edition FA617NT.A16.R7700
    CPU
    Ryzen 7 7735HS
    Motherboard
    OEM Asus Motherboard
    Memory
    16GB DDR 5
    Graphics card(s)
    AMD Radeon™ 680M & Radeon 7700S
    Sound Card
    Onboard
    Monitor(s) Displays
    16inch FHD 165hz
    Screen Resolution
    1920x1080
    Hard Drives
    512GB NVMe Boot Drive
    PSU
    Laptop PSU
    Case
    Laptop Case
    Cooling
    OEM Cooling
    Keyboard
    OEM Laptop Keyboard
    Mouse
    Touchpad & G502 Hero
    Internet Speed
    Gigabit 1100 Download/35 Upload
    Browser
    MS Edge with Bing search
    Antivirus
    Windows Defender & Malwarebytes Premium
    Other Info
    Macrium Reflect X
margarita try that link i posted thats where i downloaded the iso from and it seemed to work . let me try it again and see what happens. but i had checked all the boxes not sure if that would make a diff.

I just downloaded the ISO from the main Microsoft Windows 11 download site, which says it's version 25h2. The one I got was by scrolling to the bottom of the page where it says "Download Windows 11 Disk Image (ISO) for x64 devices". It downloaded an ISO directly, rather than using the Media Creation Tool, which I think is a good sign. I burned a bootable USB stick with Rufus 4.10 and the "Windows 2023 CA signed bootloader" option. I tried booting from it using a machine that has the latest certificates in the DB, and the 2011 certificate revoked using the DBx, and it booted into the setup program just fine.
 

My Computer My Computer

At a glance

Windows 11 pro 25h2AMD Ryzen 7 5700G64 GB G.Skill (F4-3200C16Q-64GVK)Integrated into CPU
OS
Windows 11 pro 25h2
Computer type
PC/Desktop
Manufacturer/Model
DIY
CPU
AMD Ryzen 7 5700G
Motherboard
MSI B450M Bazooka, BIOS version 7A38vHJ5 (latest beta as of 2025-09-23)
Memory
64 GB G.Skill (F4-3200C16Q-64GVK)
Graphics Card(s)
Integrated into CPU
Sound Card
Realtek (built into motherboard)
Monitor(s) Displays
Generic HDMI
Screen Resolution
1080p
Hard Drives
System and apps: SK hynix Gold P31 1TB M.2
Data: Toshiba HDWQ140 4TB internal SATA
PSU
Seasonic 400W SS-400FL2 fanless
Case
Fractal Design Define R5
Cooling
Cooler Master Hyper 212 Evo
Keyboard
Lenovo Preferred Pro II Wired External USB Keyboard (4X30M86879)
Mouse
Belkin cheapo corded USB mouse
Internet Speed
300 MBit/sec
Browser
Firefox
Antivirus
Windows Defender
Well, the test was performed on my device by replacing the updated bootx64.efi file, and it was successful. :D
I will try to test the continuity of the full installation, but on the virtual machine
On the my device, without replacing the updated file, the result attempt to boot forever
 

My Computer My Computer

At a glance

Windows 11 Pro 25H2Intel Core i5 12th generation16GB
OS
Windows 11 Pro 25H2
Computer type
PC/Desktop
CPU
Intel Core i5 12th generation
Motherboard
GIGABYTE
Memory
16GB
PSU
750W
margarita try that link i posted thats where i downloaded the iso from and it seemed to work . let me try it again and see what happens. but i had checked all the boxes not sure if that would make a diff.
It seems to be the same ISO. Can you test the hash?

1759281060023.webp
 

My Computer My Computer

At a glance

Windows 11 Pro 25H2Intel Core i5 12th generation16GB
OS
Windows 11 Pro 25H2
Computer type
PC/Desktop
CPU
Intel Core i5 12th generation
Motherboard
GIGABYTE
Memory
16GB
PSU
750W

My Computer My Computer

At a glance

Windows 11 Pro 25H2Intel Core i5 12th generation16GB
OS
Windows 11 Pro 25H2
Computer type
PC/Desktop
CPU
Intel Core i5 12th generation
Motherboard
GIGABYTE
Memory
16GB
PSU
750W

My Computer My Computer

At a glance

Windows 11 pro 25h2AMD Ryzen 7 5700G64 GB G.Skill (F4-3200C16Q-64GVK)Integrated into CPU
OS
Windows 11 pro 25h2
Computer type
PC/Desktop
Manufacturer/Model
DIY
CPU
AMD Ryzen 7 5700G
Motherboard
MSI B450M Bazooka, BIOS version 7A38vHJ5 (latest beta as of 2025-09-23)
Memory
64 GB G.Skill (F4-3200C16Q-64GVK)
Graphics Card(s)
Integrated into CPU
Sound Card
Realtek (built into motherboard)
Monitor(s) Displays
Generic HDMI
Screen Resolution
1080p
Hard Drives
System and apps: SK hynix Gold P31 1TB M.2
Data: Toshiba HDWQ140 4TB internal SATA
PSU
Seasonic 400W SS-400FL2 fanless
Case
Fractal Design Define R5
Cooling
Cooler Master Hyper 212 Evo
Keyboard
Lenovo Preferred Pro II Wired External USB Keyboard (4X30M86879)
Mouse
Belkin cheapo corded USB mouse
Internet Speed
300 MBit/sec
Browser
Firefox
Antivirus
Windows Defender
i have just finished burning 3x Win 11 25H2 bootable USB sticks with Rufus 4.10.2279
with the now added boot from 2023 cert. if the 2023 cert is installed in secure boot the USB will boot/load and install. if the 2023 cert is not installed the USB will still boot/load but will fail to boot after installation.

best of luck, Steve ..
edit. wrong date.
 
Last edited:

My Computers My Computers

  • At a glance

    Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
Just a fyi this method only works with 11 25h2. If u are using 11 24h2 u will have to go to upp dump for the latest version of 24h2 .
Modify the ConvertConfig.ini change UpdtBootFiles=0 to UpdtBootFiles=1 and save it to the file . see post 841 for more info
 

My Computer My Computer

At a glance

WINDOWS 11 WINDOWS 10Intel(R) Core(TM) i7 -3770K CPU 3.50 GZ 3501 ...32.0 GB (31.9 GB usable)AMD RADEON TM R5240 INTELL HD GRAPHICS 4600 T...
OS
WINDOWS 11 WINDOWS 10
Computer type
PC/Desktop
Manufacturer/Model
HP H8 1360T
CPU
Intel(R) Core(TM) i7 -3770K CPU 3.50 GZ 3501 4 CORE
Motherboard
PEGATRON 2AD5
Memory
32.0 GB (31.9 GB usable)
Graphics Card(s)
AMD RADEON TM R5240 INTELL HD GRAPHICS 4600 TIGER 1+1 USB
Sound Card
AMD HD . IDT
Monitor(s) Displays
AOC WAL MART SPECIAL . HP 2311 IX IPS LED DELL 1708 FP
Screen Resolution
1920 X 1080 1600X900 1280X940
Hard Drives
1 FAXING S 100 512GB 1 KINGSTON 120 GB SSD 1 X12 SSD 512 GB
PSU
300 WATT HP
Case
FULL
Cooling
ON BOARD FAN
Keyboard
LOGITEC K 520 WIRELESS
Mouse
LOGITEC M 510 WIRELESS
Internet Speed
55 UP 11.2 DOWN
Browser
CHROME EDGE
Antivirus
WINDOWS SECUIRTY
Other Info
NON SUPPORTED HARDWARE FOR WINDOWS 11
I followed MS instructions and it took me maybe 2 minutes max without having to disable or put secure boot into setup mode.
Everything you need can also be found in Microsoft github.
Yes but you still only have 1 of the 4 keys that are part of the Secured Boot expiring in 2026, you still don't have the other 3 keys. Try using the Microsoft method to get all 4 keys in that 2 minutes. Everything I need does not need Microsoft github either as I am running Windows 11 24H2 Beta Insiders which is updated every 1-2 weeks so it's already on the system, Microsoft just didn't provide instructions on how to use it. So basically you have only 25% of what is really needed while Mosby will provide 75% as the option ROM 2023 is not included until a future version but adding that was a 2 second thing.

1759318106538.webp
 
Last edited:

My Computer My Computer

At a glance

WindowsXP/7/8/8.1/10/11,Linux,Android,FreeBSD...Intel® Core™ i7-8750H 8th Gen 2.2Ghz up to 4....64GB using 2x32GB CL16 Mushkin redLine modulesIntel UHD 630 & NVIDIA GeForce GTX 1050 Ti wi...
OS
WindowsXP/7/8/8.1/10/11,Linux,Android,FreeBSD Unix
Computer type
Laptop
Manufacturer/Model
Dell XPS 15 9570
CPU
Intel® Core™ i7-8750H 8th Gen 2.2Ghz up to 4.1Ghz
Motherboard
Dell XPS 15 9570
Memory
64GB using 2x32GB CL16 Mushkin redLine modules
Graphics Card(s)
Intel UHD 630 & NVIDIA GeForce GTX 1050 Ti with 4GB DDR5
Sound Card
Realtek ALC3266-CG
Monitor(s) Displays
15.6" 4K Touch UltraHD 3840x2160 made by Sharp
Screen Resolution
3840x2160 4K UltraHD
Hard Drives
Samsung MZ-V9P4T0B/AM 990 PRO 4TB PCIe®4.0 NVMe™ M.2 SSD was Toshiba KXG60ZNV1T02 NVMe 1TB SSD
PSU
Dell XPS 15 9570
Case
Dell XPS 15 9570
Cooling
Stock
Keyboard
Stock
Mouse
SwitftPoint ProPoint
Internet Speed
Comcast/XFinity 1.44Gbps/42.5Mbps
Browser
Microsoft EDGE (Chromium based) & Google Chrome
Antivirus
Windows Defender that came with Windows
Except when i tried making 25H2 flash drive with Rufus to make 2023 Compatible, it crashed at the end of creating the USB Drive. During Part adding Customizations

Something about Microsoft Visual CC or something, and had option for Abort, Retry or Ignore.

You currently also need to select the first option in Rufus 4.10 if you select the CA 2023 option. See this very relevant FAQ entry, that was also quoted earlier. And yes, selecting the TPM bypass does not mean that TPM will be disabled or unused by Windows if you have it. It only means that Windows setup will bypass the requirement for systems that don't have it. On systems that have TPM 2.0, it does absolutely nothing, so it is safe to leave it enabled.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
Home Built
Screen Resolution
4k
Using the steps in the Microsoft article, How to manage the Windows Boot Manager revocations for Secure Boot changes associated with CVE-2023-24932 - Microsoft Support

Screenshot 2025-10-02 013902.webp

Now have bootable media that works with the old certificate revocation, and Clean installation succeeded without problems :D

Screenshot 2025-10-03 214900.webp

-------------------------------------------------

When messing with the secure boot settings in BIOS, there were two options: Standard and Custom.
The default option is Standard. When switching to Custom and then back to Standard, the "Microsoft Corporation KEK 2K CA 2023" certificate was added, which was not there before.
Also, The revocation of the Windows Production PCA 2011 certificate was also rolled back.

Screenshot 2025-10-03 035518.webp

After Enable the revocation again

Screenshot 2025-10-03 041958.webp
 

My Computer My Computer

At a glance

Windows 11 Pro 25H2Intel Core i5 12th generation16GB
OS
Windows 11 Pro 25H2
Computer type
PC/Desktop
CPU
Intel Core i5 12th generation
Motherboard
GIGABYTE
Memory
16GB
PSU
750W
The way your setup now is good . That will let you boot from either the 2011 or 2023 cert .
If you revoke the 2011 ca cert , and u have to do a clean install your system will not boot. As of right now they are no iso's with the 2023 cert .
You would have to manually edit the iso to the 2023 cert. when the time comes ms will prob remove it via windows update.
 

My Computer My Computer

At a glance

WINDOWS 11 WINDOWS 10Intel(R) Core(TM) i7 -3770K CPU 3.50 GZ 3501 ...32.0 GB (31.9 GB usable)AMD RADEON TM R5240 INTELL HD GRAPHICS 4600 T...
OS
WINDOWS 11 WINDOWS 10
Computer type
PC/Desktop
Manufacturer/Model
HP H8 1360T
CPU
Intel(R) Core(TM) i7 -3770K CPU 3.50 GZ 3501 4 CORE
Motherboard
PEGATRON 2AD5
Memory
32.0 GB (31.9 GB usable)
Graphics Card(s)
AMD RADEON TM R5240 INTELL HD GRAPHICS 4600 TIGER 1+1 USB
Sound Card
AMD HD . IDT
Monitor(s) Displays
AOC WAL MART SPECIAL . HP 2311 IX IPS LED DELL 1708 FP
Screen Resolution
1920 X 1080 1600X900 1280X940
Hard Drives
1 FAXING S 100 512GB 1 KINGSTON 120 GB SSD 1 X12 SSD 512 GB
PSU
300 WATT HP
Case
FULL
Cooling
ON BOARD FAN
Keyboard
LOGITEC K 520 WIRELESS
Mouse
LOGITEC M 510 WIRELESS
Internet Speed
55 UP 11.2 DOWN
Browser
CHROME EDGE
Antivirus
WINDOWS SECUIRTY
Other Info
NON SUPPORTED HARDWARE FOR WINDOWS 11
Tried to run the CheckEFIBootfile again script, now i can't even get it to run lol. Well one thing for sure i don't have to worry on BlackLotus, my Desktop very very secure lol. This was last time i get it to run lol

Most likely won't be doing a clean install for a long time, as probably will have issues booting or even doing a clean install. Think i went too far in revoking it too early lol perhaps lol, but at least System Secure lol
 

Attachments

  • Think im all set for now.webp
    Think im all set for now.webp
    37 KB · Views: 5

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8037AMD Ryzen 7700X32GB DDR 5 RGB 5600MhzRadeon 7800XT
    OS
    Windows 11 Pro 25H2 26200.8037
    Computer type
    PC/Desktop
    Manufacturer/Model
    PreBuilt
    CPU
    AMD Ryzen 7700X
    Motherboard
    MSI B650 VC WIfi Rev 1.0
    Memory
    32GB DDR 5 RGB 5600Mhz
    Graphics Card(s)
    Radeon 7800XT
    Sound Card
    Onboard Audio
    Monitor(s) Displays
    Asus VG245H
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 990 Evo Plus NVMe Boot
    Samsung 990 Pro 1TB Game NVMe



    External
    Western Digital Elements 500GB
    Western Digital My Passport 2TB Blue
    Western Digital My Passport 2TB Red
    Toshiba 2TB in External Enclosure
    Seagate 8TB in External Enclosure
    Seagate 1TB Portable USB 3 External Drive
    Western Digital My Book 8TB (Primary Backup drive)
    Western Digital Black 4TB In External Enclosure
    PSU
    750 Watt High Power
    Case
    Lian Li Lan Cool 216 ARGB Airflow
    Cooling
    2 160MM Front, 1 140MM Rear Exhaust
    Keyboard
    Logitech G513
    Mouse
    Logitech G502 X
    Internet Speed
    Gigabit 1100Mb/35 Upload
    Browser
    MS Edge Chromium and Bing Search
    Antivirus
    Windows Defender, Malwarebytes Premium
    Other Info
    UEFI, Secure Boot, TPM 2.0, Macrium Reflect X
  • At a glance

    Windows 11 Pro 25H2 26200.8037Ryzen 7 7735HS16GB DDR 5AMD Radeon™ 680M & Radeon 7700S
    Operating System
    Windows 11 Pro 25H2 26200.8037
    Computer type
    Laptop
    Manufacturer/Model
    Asus TUF A16 Advantage Edition FA617NT.A16.R7700
    CPU
    Ryzen 7 7735HS
    Motherboard
    OEM Asus Motherboard
    Memory
    16GB DDR 5
    Graphics card(s)
    AMD Radeon™ 680M & Radeon 7700S
    Sound Card
    Onboard
    Monitor(s) Displays
    16inch FHD 165hz
    Screen Resolution
    1920x1080
    Hard Drives
    512GB NVMe Boot Drive
    PSU
    Laptop PSU
    Case
    Laptop Case
    Cooling
    OEM Cooling
    Keyboard
    OEM Laptop Keyboard
    Mouse
    Touchpad & G502 Hero
    Internet Speed
    Gigabit 1100 Download/35 Upload
    Browser
    MS Edge with Bing search
    Antivirus
    Windows Defender & Malwarebytes Premium
    Other Info
    Macrium Reflect X
how did u get the option rom 2023 ?
just make you a 2023 iso cert iso boot disk and u will be good
 

My Computer My Computer

At a glance

WINDOWS 11 WINDOWS 10Intel(R) Core(TM) i7 -3770K CPU 3.50 GZ 3501 ...32.0 GB (31.9 GB usable)AMD RADEON TM R5240 INTELL HD GRAPHICS 4600 T...
OS
WINDOWS 11 WINDOWS 10
Computer type
PC/Desktop
Manufacturer/Model
HP H8 1360T
CPU
Intel(R) Core(TM) i7 -3770K CPU 3.50 GZ 3501 4 CORE
Motherboard
PEGATRON 2AD5
Memory
32.0 GB (31.9 GB usable)
Graphics Card(s)
AMD RADEON TM R5240 INTELL HD GRAPHICS 4600 TIGER 1+1 USB
Sound Card
AMD HD . IDT
Monitor(s) Displays
AOC WAL MART SPECIAL . HP 2311 IX IPS LED DELL 1708 FP
Screen Resolution
1920 X 1080 1600X900 1280X940
Hard Drives
1 FAXING S 100 512GB 1 KINGSTON 120 GB SSD 1 X12 SSD 512 GB
PSU
300 WATT HP
Case
FULL
Cooling
ON BOARD FAN
Keyboard
LOGITEC K 520 WIRELESS
Mouse
LOGITEC M 510 WIRELESS
Internet Speed
55 UP 11.2 DOWN
Browser
CHROME EDGE
Antivirus
WINDOWS SECUIRTY
Other Info
NON SUPPORTED HARDWARE FOR WINDOWS 11
The way your setup now is good . That will let you boot from either the 2011 or 2023 cert .
If you revoke the 2011 ca cert , and u have to do a clean install your system will not boot. As of right now they are no iso's with the 2023 cert .
You would have to manually edit the iso to the 2023 cert. when the time comes ms will prob remove it via windows update.

Wrong, since the 2011 cert is in the DBX database, it will NOT boot with a 2011 boot image. The only thing that will boot now is an image with the Windows 2023 cert or the Microsoft 2011 cert.
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2, Build 26200.8894Intel Core i5 1450064GB DDR4GeForce RTX 4060
    OS
    Win 11 Pro 25H2, Build 26200.8894
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14500
    Motherboard
    Gigabyte B760M G P WIFI
    Memory
    64GB DDR4
    Graphics Card(s)
    GeForce RTX 4060
    Sound Card
    Chipset Realtek
    Monitor(s) Displays
    LG 45" Ultragear, Acer 24" 1080p
    Screen Resolution
    5120x1440, 1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 3D NAND NVMe M.2 SSD (O/S)
    Silicon Power 2TB US75 NVMe PCIe Gen4 M.2 2280 SSD (backup)
    Crucial BX500 2TB 3D NAND (2nd backup)
    Seagate 4TB Ironwolf, rotating HDD archive files
    External off-line backup Drives: 2 NVMe 4TB drives in external enclosures
    PSU
    Thermaltake Toughpower GF3 750W
    Case
    LIAN LI LANCOOL 216 E-ATX PC Case
    Cooling
    Lots of fans!
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • At a glance

    Win 11 Pro 25H2, Build 26200.8894Intel Core i5 1440032GB DDR5Intel 700 Embedded GPU
    Operating System
    Win 11 Pro 25H2, Build 26200.8894
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14400
    Motherboard
    Gigabyte B760M DS3H AX
    Memory
    32GB DDR5
    Graphics card(s)
    Intel 700 Embedded GPU
    Sound Card
    Realtek Embedded
    Monitor(s) Displays
    27" HP 1080p
    Screen Resolution
    1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 eD NAND PCIe SSD
    Samsung EVO 990 2TB NVMe Gen4 SSD
    Samsung 2TB SATA SSD
    PSU
    Thermaltake Smart BM3 650W
    Case
    Okinos Micro ATX Case
    Cooling
    Fans
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • Nimo N171 17" Laptop, (Intel i3-1215U, 16GB RAM, 2TB NVMe, Win11 Pro)
    Acemagic Vista Mini PC V1 (Intel N150, 16GB RAM, 1TB NVMe, Win11 Pro)
    HP ENVY h8-1540t, (24GB RAM, 2TB SSD, 2TB HDD, Win11 Pro)
Oh ok excellent, checks that.

Not sure how i got the Option Rom 2023, all of a sudden it was there---unless came with last MSI UEFi bios update in July, waiting for 2 more to come out of beta, then will install that security related UEFI bios update, along with Agesa 1.2.0.3f version


Code:
Secure Boot: ON
BitLocker on (C:) OFF

UEFI KEK Certs
--------------
    Microsoft Corporation KEK CA 2011
    Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
    Microsoft Corporation UEFI CA 2011
    Microsoft Windows Production PCA 2011
    Microsoft Option ROM UEFI CA 2023
    Microsoft UEFI CA 2023
    Windows UEFI CA 2023

UEFI DBX Certs
--------------
    Microsoft Windows Production PCA 2011

EFI Files
---------
    Disk 0: Boot Manager [Windows UEFI CA 2023] is ALLOWED.

    Registry: WindowsUEFICA2023Capable = 2
        [Windows UEFI CA 2023] is in UEFI DB, and Windows is starting from CA 2023 Boot Manager.



Bootable Media
--------------
    USB :

    USB F: "ESD-ISO"
        Boot File [Windows UEFI CA 2023] is ALLOWED.
        boot.wim:2    Boot Manager [Windows UEFI CA 2023] is PRESENT.
        install.esd:1 Boot Manager [Windows UEFI CA 2023] is PRESENT.
                         Skipping checks on next 6 images.
 
Last edited:

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8037AMD Ryzen 7700X32GB DDR 5 RGB 5600MhzRadeon 7800XT
    OS
    Windows 11 Pro 25H2 26200.8037
    Computer type
    PC/Desktop
    Manufacturer/Model
    PreBuilt
    CPU
    AMD Ryzen 7700X
    Motherboard
    MSI B650 VC WIfi Rev 1.0
    Memory
    32GB DDR 5 RGB 5600Mhz
    Graphics Card(s)
    Radeon 7800XT
    Sound Card
    Onboard Audio
    Monitor(s) Displays
    Asus VG245H
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 990 Evo Plus NVMe Boot
    Samsung 990 Pro 1TB Game NVMe



    External
    Western Digital Elements 500GB
    Western Digital My Passport 2TB Blue
    Western Digital My Passport 2TB Red
    Toshiba 2TB in External Enclosure
    Seagate 8TB in External Enclosure
    Seagate 1TB Portable USB 3 External Drive
    Western Digital My Book 8TB (Primary Backup drive)
    Western Digital Black 4TB In External Enclosure
    PSU
    750 Watt High Power
    Case
    Lian Li Lan Cool 216 ARGB Airflow
    Cooling
    2 160MM Front, 1 140MM Rear Exhaust
    Keyboard
    Logitech G513
    Mouse
    Logitech G502 X
    Internet Speed
    Gigabit 1100Mb/35 Upload
    Browser
    MS Edge Chromium and Bing Search
    Antivirus
    Windows Defender, Malwarebytes Premium
    Other Info
    UEFI, Secure Boot, TPM 2.0, Macrium Reflect X
  • At a glance

    Windows 11 Pro 25H2 26200.8037Ryzen 7 7735HS16GB DDR 5AMD Radeon™ 680M & Radeon 7700S
    Operating System
    Windows 11 Pro 25H2 26200.8037
    Computer type
    Laptop
    Manufacturer/Model
    Asus TUF A16 Advantage Edition FA617NT.A16.R7700
    CPU
    Ryzen 7 7735HS
    Motherboard
    OEM Asus Motherboard
    Memory
    16GB DDR 5
    Graphics card(s)
    AMD Radeon™ 680M & Radeon 7700S
    Sound Card
    Onboard
    Monitor(s) Displays
    16inch FHD 165hz
    Screen Resolution
    1920x1080
    Hard Drives
    512GB NVMe Boot Drive
    PSU
    Laptop PSU
    Case
    Laptop Case
    Cooling
    OEM Cooling
    Keyboard
    OEM Laptop Keyboard
    Mouse
    Touchpad & G502 Hero
    Internet Speed
    Gigabit 1100 Download/35 Upload
    Browser
    MS Edge with Bing search
    Antivirus
    Windows Defender & Malwarebytes Premium
    Other Info
    Macrium Reflect X
I haven't followed this very long post from the beginning, so I may have missed some points, Where are the steps cert revocation“Windows Production CA 2011” ? I don't see anything in the Microsoft article.
does that mean I'm still vulnerable to the Black Lotus vulnerability?
 

My Computer My Computer

At a glance

Windows 11 Pro 25H2Intel Core i5 12th generation16GB
OS
Windows 11 Pro 25H2
Computer type
PC/Desktop
CPU
Intel Core i5 12th generation
Motherboard
GIGABYTE
Memory
16GB
PSU
750W
I haven't followed this very long post from the beginning, so I may have missed some points, Where are the steps cert revocation“Windows Production CA 2011” ? I don't see anything in the Microsoft article.
does that mean I'm still vulnerable to the Black Lotus vulnerability?
You appear to be fine if this is your current configuration. The 2011 cert is in the DBX database and revoked.

1759520229220.webp
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2, Build 26200.8894Intel Core i5 1450064GB DDR4GeForce RTX 4060
    OS
    Win 11 Pro 25H2, Build 26200.8894
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14500
    Motherboard
    Gigabyte B760M G P WIFI
    Memory
    64GB DDR4
    Graphics Card(s)
    GeForce RTX 4060
    Sound Card
    Chipset Realtek
    Monitor(s) Displays
    LG 45" Ultragear, Acer 24" 1080p
    Screen Resolution
    5120x1440, 1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 3D NAND NVMe M.2 SSD (O/S)
    Silicon Power 2TB US75 NVMe PCIe Gen4 M.2 2280 SSD (backup)
    Crucial BX500 2TB 3D NAND (2nd backup)
    Seagate 4TB Ironwolf, rotating HDD archive files
    External off-line backup Drives: 2 NVMe 4TB drives in external enclosures
    PSU
    Thermaltake Toughpower GF3 750W
    Case
    LIAN LI LANCOOL 216 E-ATX PC Case
    Cooling
    Lots of fans!
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • At a glance

    Win 11 Pro 25H2, Build 26200.8894Intel Core i5 1440032GB DDR5Intel 700 Embedded GPU
    Operating System
    Win 11 Pro 25H2, Build 26200.8894
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14400
    Motherboard
    Gigabyte B760M DS3H AX
    Memory
    32GB DDR5
    Graphics card(s)
    Intel 700 Embedded GPU
    Sound Card
    Realtek Embedded
    Monitor(s) Displays
    27" HP 1080p
    Screen Resolution
    1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 eD NAND PCIe SSD
    Samsung EVO 990 2TB NVMe Gen4 SSD
    Samsung 2TB SATA SSD
    PSU
    Thermaltake Smart BM3 650W
    Case
    Okinos Micro ATX Case
    Cooling
    Fans
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • Nimo N171 17" Laptop, (Intel i3-1215U, 16GB RAM, 2TB NVMe, Win11 Pro)
    Acemagic Vista Mini PC V1 (Intel N150, 16GB RAM, 1TB NVMe, Win11 Pro)
    HP ENVY h8-1540t, (24GB RAM, 2TB SSD, 2TB HDD, Win11 Pro)

My Computer My Computer

At a glance

WINDOWS 11 WINDOWS 10Intel(R) Core(TM) i7 -3770K CPU 3.50 GZ 3501 ...32.0 GB (31.9 GB usable)AMD RADEON TM R5240 INTELL HD GRAPHICS 4600 T...
OS
WINDOWS 11 WINDOWS 10
Computer type
PC/Desktop
Manufacturer/Model
HP H8 1360T
CPU
Intel(R) Core(TM) i7 -3770K CPU 3.50 GZ 3501 4 CORE
Motherboard
PEGATRON 2AD5
Memory
32.0 GB (31.9 GB usable)
Graphics Card(s)
AMD RADEON TM R5240 INTELL HD GRAPHICS 4600 TIGER 1+1 USB
Sound Card
AMD HD . IDT
Monitor(s) Displays
AOC WAL MART SPECIAL . HP 2311 IX IPS LED DELL 1708 FP
Screen Resolution
1920 X 1080 1600X900 1280X940
Hard Drives
1 FAXING S 100 512GB 1 KINGSTON 120 GB SSD 1 X12 SSD 512 GB
PSU
300 WATT HP
Case
FULL
Cooling
ON BOARD FAN
Keyboard
LOGITEC K 520 WIRELESS
Mouse
LOGITEC M 510 WIRELESS
Internet Speed
55 UP 11.2 DOWN
Browser
CHROME EDGE
Antivirus
WINDOWS SECUIRTY
Other Info
NON SUPPORTED HARDWARE FOR WINDOWS 11
thats what i said since he revoked the 2011 cert . and he has to do a clean install the only way he can boot is using a 2023 iso .
I already mentioned that I performed a clean installation using modified download media that I obtained by following these steps from a Microsoft article.
Screenshot 2025-10-02 013902.webp

These commands modified the efi folder and added additional files.
 
Last edited:

My Computer My Computer

At a glance

Windows 11 Pro 25H2Intel Core i5 12th generation16GB
OS
Windows 11 Pro 25H2
Computer type
PC/Desktop
CPU
Intel Core i5 12th generation
Motherboard
GIGABYTE
Memory
16GB
PSU
750W
Back
Top Bottom