Did you manually update your Secure Boot Keys ?


Looks like the HP Spectre laptop has a firmware limitation. I've been discussing this with Copilot and I run up against a hard wall.

"You’ve diagnosed it exactly right. On your HP Spectre x360, the “Clear All Secure Boot Keys” option wipes the PK/KEK/db/dbx databases, which forces the system into Setup Mode. In that state, Secure Boot can’t be enabled because there are no keys to enforce. When you reload HP Factory Default Keys, the firmware repopulates those databases with the original 2016 set, and Secure Boot becomes available again.

"That behavior confirms the limitation: HP’s firmware only trusts its own factory key bundle, and it doesn’t provide a path for you to insert updated Microsoft certificates manually. Mosby can’t override that because the firmware rejects non‑OEM KEKs once User Mode is active."

So, indeed a BIOS update from HP is required and they already say none is forthcoming. tant pis, peu importe!

i have two HP all in one systems, purchased in 2022, both have the same BIOS setup as yours.
(both of these all in ones are made with laptop components)

i have updated both secure boot certs to the new 2023 secure boot certs
without doing anything in or to the BIOS
1764293558090.webp

using the secure boot update HowTo

best of luck Steve ..
 

My Computers My Computers

  • At a glance

    Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
Looks like the HP Spectre laptop has a firmware limitation. I've been discussing this with Copilot and I run up against a hard wall.

"You’ve diagnosed it exactly right. On your HP Spectre x360, the “Clear All Secure Boot Keys” option wipes the PK/KEK/db/dbx databases, which forces the system into Setup Mode. In that state, Secure Boot can’t be enabled because there are no keys to enforce. When you reload HP Factory Default Keys, the firmware repopulates those databases with the original 2016 set, and Secure Boot becomes available again.

"That behavior confirms the limitation: HP’s firmware only trusts its own factory key bundle, and it doesn’t provide a path for you to insert updated Microsoft certificates manually. Mosby can’t override that because the firmware rejects non‑OEM KEKs once User Mode is active."

So, indeed a BIOS update from HP is required and they already say none is forthcoming. tant pis, peu importe!
I'm having pretty much the same issue with an unsupported Lenovo laptop. Tried to use Mosby and it installed the keys ( sort of ) and messed up Secure Boot so that I couldn't turn it back on again. Blew out all the keys to factory and reinstalled windows, then did the entries to reinstall the Windows UEFI CA 2023 key so that I could re-image from a backup. It was an interesting experiment, as I only need the 2023 KEK key, but I've had enough. Spent untold hours messing with it. The one clue that may explain the issue was when Mosby finished updating all the keys, there was a warning error about a Security Violation, when checking all the keys installed there seemed to have been a error reading a PK key.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Looks like the HP Spectre laptop has a firmware limitation. I've been discussing this with Copilot and I run up against a hard wall.

"You’ve diagnosed it exactly right. On your HP Spectre x360, the “Clear All Secure Boot Keys” option wipes the PK/KEK/db/dbx databases, which forces the system into Setup Mode. In that state, Secure Boot can’t be enabled because there are no keys to enforce. When you reload HP Factory Default Keys, the firmware repopulates those databases with the original 2016 set, and Secure Boot becomes available again.

"That behavior confirms the limitation: HP’s firmware only trusts its own factory key bundle, and it doesn’t provide a path for you to insert updated Microsoft certificates manually. Mosby can’t override that because the firmware rejects non‑OEM KEKs once User Mode is active."

So, indeed a BIOS update from HP is required and they already say none is forthcoming. tant pis, peu importe!
The first bit seems logically right to me. But once you "Clear All Secure Boot Keys" you don't want to enable secure boot, you want to boot straight into the USB EFI boot drive with Secure Boot disabled. And you'd not want to reload HP factory Default Keys either before booting into MOSBY, or after a successful run, but after failing it's the way to get back to square one.

But then it seems completely illogical that they'd give you the setting to "Clear All Secure Boot Keys" -- which puts it in Setup Mode -- and then NOT allow installing keys, the reason for the existence of Setup Mode. Not saying HP wouldn't prevent users from updating keys... HP, Dell and Lenovo are all quite famous for completely screwing their customers with proprietary twists on their implementations of industry standards... but why even allow clearing the keys in the first place.

Frankly, it puts me off on ever buying a laptop. Just get a cheap throw-away Android tablet or Chromebook for portability.
 

My Computers My Computers

  • At a glance

    Windows 11 ProRyzen 7 5800XGSkill 3200, 2x8GBMSI RX 6800 XT Gaming Z
    OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 5800X
    Motherboard
    Gigabyte B550M Aorus Pro
    Memory
    GSkill 3200, 2x8GB
    Graphics Card(s)
    MSI RX 6800 XT Gaming Z
    Sound Card
    on-board Realtek
    Monitor(s) Displays
    MSI 180hz
    Screen Resolution
    1440p
    Hard Drives
    Samsung 980 Pro, Samsung 870 Evo, generic PCIe NVME, WD 1TB 2.5" laptop spinner
    PSU
    Corsair RM 650
    Case
    mATX
    Cooling
    BeQuiet 240mm AIO and a bunch of case fans
    Keyboard
    one that clacks softly
    Mouse
    logitech
    Internet Speed
    bunches of bps
    Browser
    Firefox
    Antivirus
    Windows' own
  • At a glance

    Win11 ProRyzen 7 170016GB DDR4RX-480
    Operating System
    Win11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 1700
    Motherboard
    GA-AB350M G-3
    Memory
    16GB DDR4
    Graphics card(s)
    RX-480
    Sound Card
    In-Built Realtek
    Monitor(s) Displays
    Samsung
    Screen Resolution
    1440p
    Hard Drives
    NVME/SSD's
    PSU
    Thermaltake BX1 550W
    Case
    Some junky thing
    Cooling
    ThermalTake Assassin(?)
    Browser
    FF/Edge
    Antivirus
    Whatever Windows does
    Other Info
    Secure Boot enabled updated to 2023 CA keys, TPM2.0 enabled with system drive Bitlocker'd.
i have two HP all in one systems, purchased in 2022, both have the same BIOS setup as yours.
(both of these all in ones are made with laptop components)

i have updated both secure boot certs to the new 2023 secure boot certs
without doing anything in or to the BIOS
View attachment 154569

using the secure boot update HowTo

best of luck Steve ..
Yes, I've used your instructions to work my other 3 computers, 2 laptops and an ASUS desktop, with success, so thanks very much for your detailed instructions, I've saved them in a text file for future use. But I'm currently getting a Security Violation (see below) when I ran mosby tonight. And my Spectre was made in Feb 2016, and HP may have done things a bit strange. But, hey, if I hear of any uses of mosby that are different than the current iteration I will give that a shot.

Mosby.log

[Mosby session started: 2025-11-27 19:09:37 [UTC]
UEFI v2.40 (American Megatrends, 0x0005000A)
American Megatrends Inc. F.54
Hewlett-Packard HP Spectre x360 Convertible 13
Reusing existing MosbyKey.crt certificate...
Not installing SBAT since this system's SBAT is either the same or newer
Generating PK certificate...
Installing SSPV: 'SkuSiPolicyVersion [2023.04.29]'
Installing SSPU: 'SkuSiPolicyUpdateSigners [2023.04.29]'
Installing DBX: 'Windows Bootmgr SVN 7.0 DBX update [2025-06-06]'
Failed to set Secure Boot variable: Security Violation
[Mosby session ended: 2025-11-27 19:09:40 [UTC]

[Mosby session started: 2025-11-27 19:54:58 [UTC]
UEFI v2.40 (American Megatrends, 0x0005000A)
American Megatrends Inc. F.54
Hewlett-Packard HP Spectre x360 Convertible 13
Reusing existing MosbyKey.crt certificate...
Not installing SBAT since this system's SBAT is either the same or newer
Generating PK certificate...
Installing SSPV: 'SkuSiPolicyVersion [2023.04.29]'
Installing SSPU: 'SkuSiPolicyUpdateSigners [2023.04.29]'
Installing DBX: 'Windows Bootmgr SVN 7.0 DBX update [2025-06-06]'
Failed to set Secure Boot variable: Security Violation
[Mosby session ended: 2025-11-27 19:55:30 [UTC]
 

My Computers My Computers

  • At a glance

    Windows 11 Home, ver 25H2 build 26200.8246Intel Core i5 5200U @ 2.20GH4 GBIntel HD Graphics 5500 on board
    OS
    Windows 11 Home, ver 25H2 build 26200.8246
    Computer type
    Laptop
    Manufacturer/Model
    Hewlett-Packard Spectre 13-4001 x360 convertable
    CPU
    Intel Core i5 5200U @ 2.20GH
    Motherboard
    Hewlett-Packard 802D
    Memory
    4 GB
    Graphics Card(s)
    Intel HD Graphics 5500 on board
    Sound Card
    Intel Smart Sound Technology (Intel SST)
    Hard Drives
    Micron 256GB M.2 2280 NGFF SSD MTFDDAV256TBN, (SATA 6.0 Gb/s)
    Keyboard
    Model # G01KB
    Antivirus
    Microsoft Defender
    Other Info
    born on date: 25 Feb 2016
  • At a glance

    Win 11 Home 25H2 build 26200.7922Intel Core i7 4th Gen 4790 (3.60GHz), Haswell...Samsung 16 GB DDR3 (8GB in 2 modules)NVIDIA GeForce GTX 760, 3GB, and on-board Int...
    Operating System
    Win 11 Home 25H2 build 26200.7922
    Computer type
    PC/Desktop
    Manufacturer/Model
    Asus Desktop model M32AD-US019S (DOM: 6/9/2014 )
    CPU
    Intel Core i7 4th Gen 4790 (3.60GHz), Haswell 22nm Technology, SOCKET 1150
    Motherboard
    H81M-E/M51AD/DP_MB
    Memory
    Samsung 16 GB DDR3 (8GB in 2 modules)
    Graphics card(s)
    NVIDIA GeForce GTX 760, 3GB, and on-board Intel HD Graphics 4600 Rev 6
    Monitor(s) Displays
    HP EliteDisplay E241i LED; HP EliteDisplay E243
    Hard Drives
    Samsung 500GB SSD, 870 EVO (SATA 6.0 )
    Micron 250GB SSD, CT250MX500
    Toshiba HDD, 3GB (original drive w/PC)
    Case
    ASUS
    Keyboard
    ASUS-------------------------
    Antivirus
    MS Defender
    Other Info
    Additional Laptops:

    HEWLETT PACKARD
    HP OmniBook X Flip NGAI (Next Gen AI),
    Model: 16-as0023dx
    PT# B5UH1UA#ABA Product #: B5UH1UA
    delivered and setup 7/25/25
    16" 2K Touch-Screen Laptop
    Intel Core Ultra 7 256V '24 Series 2 - CPU
    Boost Clock Frequency 4.8 gigahertz; Neural Processing Unit (NPU) Yes;
    16GB Memory, LPDDR5X
    1TB SSD PCIe 4.0
    Graphics: Intel Arc 140V
    1 x HDMI 2.1
    1 x Thunderbolt 4
    2K Touch-Screen display, LED, IPS; 1920 x 1200 (Full HD+)
    USB Ports: 1 x USB-C 3.1, 2 x USB-A 3.1
    Wi-Fi 6E
    weight 4.15 pounds

    DELL
    Model:I7591-7483BLK-PUS 2-in-1 (7000 Series)
    purchased 12/3/2019,
    15.6 inch 2-IN-1;
    4K Ultra HD Touch-Screen, 3840 x 2160,
    Intel Core i7 10510U CPU 1.80GHz,
    16GB RAM DDR4 SDRAM 2400 megahert (2 slots),
    dedicated graphics Nvidia GeForce MX250 2 GB Graphics,
    PCIe 512GB Intel SSD + 32GB Optane Memory (Intel Optane Memory H10 with solid-state storage),
    wireless-AX & Bluetooth
    Battery: 68wh, Type 4VGMP 4 cell
there is another forum member with similar problems updating the secure boot cert of one of their systems
and it looks like there is no 2023 cert available for that particular system
i wondering if that applies to your system as well at this time.

Microsoft will be releasing an update but for which computers and there specs are unknown at this time.
apart from the lack of data in regard to which systems are going to be updated and when.

best of luck Steve ..
 

My Computers My Computers

  • At a glance

    Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
there is another forum member with similar problems updating the secure boot cert of one of their systems
and it looks like there is no 2023 cert available for that particular system
i wondering if that applies to your system as well at this time.

Microsoft will be releasing an update but for which computers and there specs are unknown at this time.
apart from the lack of data in regard to which systems are going to be updated and when.

best of luck Steve ..
Yeah, it does seem like there will be quite a few users like me with perfectly good machines that currently use Secure Boot but won't be able to update and will resort to having Secure Boot disabled. I've gotten the feeling that this won't be that big of a deal so I'm not going to get too worked up about it. It's too bad HP has decided to pick 2017 as the last year supported. Oh well.
 

My Computers My Computers

  • At a glance

    Windows 11 Home, ver 25H2 build 26200.8246Intel Core i5 5200U @ 2.20GH4 GBIntel HD Graphics 5500 on board
    OS
    Windows 11 Home, ver 25H2 build 26200.8246
    Computer type
    Laptop
    Manufacturer/Model
    Hewlett-Packard Spectre 13-4001 x360 convertable
    CPU
    Intel Core i5 5200U @ 2.20GH
    Motherboard
    Hewlett-Packard 802D
    Memory
    4 GB
    Graphics Card(s)
    Intel HD Graphics 5500 on board
    Sound Card
    Intel Smart Sound Technology (Intel SST)
    Hard Drives
    Micron 256GB M.2 2280 NGFF SSD MTFDDAV256TBN, (SATA 6.0 Gb/s)
    Keyboard
    Model # G01KB
    Antivirus
    Microsoft Defender
    Other Info
    born on date: 25 Feb 2016
  • At a glance

    Win 11 Home 25H2 build 26200.7922Intel Core i7 4th Gen 4790 (3.60GHz), Haswell...Samsung 16 GB DDR3 (8GB in 2 modules)NVIDIA GeForce GTX 760, 3GB, and on-board Int...
    Operating System
    Win 11 Home 25H2 build 26200.7922
    Computer type
    PC/Desktop
    Manufacturer/Model
    Asus Desktop model M32AD-US019S (DOM: 6/9/2014 )
    CPU
    Intel Core i7 4th Gen 4790 (3.60GHz), Haswell 22nm Technology, SOCKET 1150
    Motherboard
    H81M-E/M51AD/DP_MB
    Memory
    Samsung 16 GB DDR3 (8GB in 2 modules)
    Graphics card(s)
    NVIDIA GeForce GTX 760, 3GB, and on-board Intel HD Graphics 4600 Rev 6
    Monitor(s) Displays
    HP EliteDisplay E241i LED; HP EliteDisplay E243
    Hard Drives
    Samsung 500GB SSD, 870 EVO (SATA 6.0 )
    Micron 250GB SSD, CT250MX500
    Toshiba HDD, 3GB (original drive w/PC)
    Case
    ASUS
    Keyboard
    ASUS-------------------------
    Antivirus
    MS Defender
    Other Info
    Additional Laptops:

    HEWLETT PACKARD
    HP OmniBook X Flip NGAI (Next Gen AI),
    Model: 16-as0023dx
    PT# B5UH1UA#ABA Product #: B5UH1UA
    delivered and setup 7/25/25
    16" 2K Touch-Screen Laptop
    Intel Core Ultra 7 256V '24 Series 2 - CPU
    Boost Clock Frequency 4.8 gigahertz; Neural Processing Unit (NPU) Yes;
    16GB Memory, LPDDR5X
    1TB SSD PCIe 4.0
    Graphics: Intel Arc 140V
    1 x HDMI 2.1
    1 x Thunderbolt 4
    2K Touch-Screen display, LED, IPS; 1920 x 1200 (Full HD+)
    USB Ports: 1 x USB-C 3.1, 2 x USB-A 3.1
    Wi-Fi 6E
    weight 4.15 pounds

    DELL
    Model:I7591-7483BLK-PUS 2-in-1 (7000 Series)
    purchased 12/3/2019,
    15.6 inch 2-IN-1;
    4K Ultra HD Touch-Screen, 3840 x 2160,
    Intel Core i7 10510U CPU 1.80GHz,
    16GB RAM DDR4 SDRAM 2400 megahert (2 slots),
    dedicated graphics Nvidia GeForce MX250 2 GB Graphics,
    PCIe 512GB Intel SSD + 32GB Optane Memory (Intel Optane Memory H10 with solid-state storage),
    wireless-AX & Bluetooth
    Battery: 68wh, Type 4VGMP 4 cell
I'm still learning here. Interesting statement here Security Violation on Dell XPS 15 9570 Notebook · Issue #6 · pbatard/Mosby that may explain my HP specific situation, pbatard writes:

"I'm not sure why you are quoting this to me. As I mentioned in this elevenforum thread which you know about, the UEFI specs are pretty clear that if Mosby reports that the platform is in Setup Mode but the Secure Boot variables can't be written, then the UEFI firmware does not comply to the UEFI specs. Therefore that Dell UEFI firmware of yours is not UEFI compliant if it reported a security violation when writing the Secure Boot variables after Mosby validated that the relevant UEFI variables said that, per specs, the platform reported to be in Setup Mode."

So it may be likely that the HP UEFI firmware also does not comply with the UEFI specification. He mentions that some manufactures played "fast and loose" with the specification, resulting in firmware incapable of being written in Setup Mode.
 

My Computers My Computers

  • At a glance

    Windows 11 Home, ver 25H2 build 26200.8246Intel Core i5 5200U @ 2.20GH4 GBIntel HD Graphics 5500 on board
    OS
    Windows 11 Home, ver 25H2 build 26200.8246
    Computer type
    Laptop
    Manufacturer/Model
    Hewlett-Packard Spectre 13-4001 x360 convertable
    CPU
    Intel Core i5 5200U @ 2.20GH
    Motherboard
    Hewlett-Packard 802D
    Memory
    4 GB
    Graphics Card(s)
    Intel HD Graphics 5500 on board
    Sound Card
    Intel Smart Sound Technology (Intel SST)
    Hard Drives
    Micron 256GB M.2 2280 NGFF SSD MTFDDAV256TBN, (SATA 6.0 Gb/s)
    Keyboard
    Model # G01KB
    Antivirus
    Microsoft Defender
    Other Info
    born on date: 25 Feb 2016
  • At a glance

    Win 11 Home 25H2 build 26200.7922Intel Core i7 4th Gen 4790 (3.60GHz), Haswell...Samsung 16 GB DDR3 (8GB in 2 modules)NVIDIA GeForce GTX 760, 3GB, and on-board Int...
    Operating System
    Win 11 Home 25H2 build 26200.7922
    Computer type
    PC/Desktop
    Manufacturer/Model
    Asus Desktop model M32AD-US019S (DOM: 6/9/2014 )
    CPU
    Intel Core i7 4th Gen 4790 (3.60GHz), Haswell 22nm Technology, SOCKET 1150
    Motherboard
    H81M-E/M51AD/DP_MB
    Memory
    Samsung 16 GB DDR3 (8GB in 2 modules)
    Graphics card(s)
    NVIDIA GeForce GTX 760, 3GB, and on-board Intel HD Graphics 4600 Rev 6
    Monitor(s) Displays
    HP EliteDisplay E241i LED; HP EliteDisplay E243
    Hard Drives
    Samsung 500GB SSD, 870 EVO (SATA 6.0 )
    Micron 250GB SSD, CT250MX500
    Toshiba HDD, 3GB (original drive w/PC)
    Case
    ASUS
    Keyboard
    ASUS-------------------------
    Antivirus
    MS Defender
    Other Info
    Additional Laptops:

    HEWLETT PACKARD
    HP OmniBook X Flip NGAI (Next Gen AI),
    Model: 16-as0023dx
    PT# B5UH1UA#ABA Product #: B5UH1UA
    delivered and setup 7/25/25
    16" 2K Touch-Screen Laptop
    Intel Core Ultra 7 256V '24 Series 2 - CPU
    Boost Clock Frequency 4.8 gigahertz; Neural Processing Unit (NPU) Yes;
    16GB Memory, LPDDR5X
    1TB SSD PCIe 4.0
    Graphics: Intel Arc 140V
    1 x HDMI 2.1
    1 x Thunderbolt 4
    2K Touch-Screen display, LED, IPS; 1920 x 1200 (Full HD+)
    USB Ports: 1 x USB-C 3.1, 2 x USB-A 3.1
    Wi-Fi 6E
    weight 4.15 pounds

    DELL
    Model:I7591-7483BLK-PUS 2-in-1 (7000 Series)
    purchased 12/3/2019,
    15.6 inch 2-IN-1;
    4K Ultra HD Touch-Screen, 3840 x 2160,
    Intel Core i7 10510U CPU 1.80GHz,
    16GB RAM DDR4 SDRAM 2400 megahert (2 slots),
    dedicated graphics Nvidia GeForce MX250 2 GB Graphics,
    PCIe 512GB Intel SSD + 32GB Optane Memory (Intel Optane Memory H10 with solid-state storage),
    wireless-AX & Bluetooth
    Battery: 68wh, Type 4VGMP 4 cell
please have a look at this about enrolling your own MOK key on a Windows 11 system

that may unlock secure boot so updating the 2023 cert could be made possible.
best of luck Steve ..
 

My Computers My Computers

  • At a glance

    Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
please have a look at this about enrolling your own MOK key on a Windows 11 system

that may unlock secure boot so updating the 2023 cert could be made possible.
best of luck Steve ..
Is Machine Owner Key (MOK) Dell's name for PK (Platform Key)?
 

My Computers My Computers

  • At a glance

    Windows 11 ProRyzen 7 5800XGSkill 3200, 2x8GBMSI RX 6800 XT Gaming Z
    OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 5800X
    Motherboard
    Gigabyte B550M Aorus Pro
    Memory
    GSkill 3200, 2x8GB
    Graphics Card(s)
    MSI RX 6800 XT Gaming Z
    Sound Card
    on-board Realtek
    Monitor(s) Displays
    MSI 180hz
    Screen Resolution
    1440p
    Hard Drives
    Samsung 980 Pro, Samsung 870 Evo, generic PCIe NVME, WD 1TB 2.5" laptop spinner
    PSU
    Corsair RM 650
    Case
    mATX
    Cooling
    BeQuiet 240mm AIO and a bunch of case fans
    Keyboard
    one that clacks softly
    Mouse
    logitech
    Internet Speed
    bunches of bps
    Browser
    Firefox
    Antivirus
    Windows' own
  • At a glance

    Win11 ProRyzen 7 170016GB DDR4RX-480
    Operating System
    Win11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 1700
    Motherboard
    GA-AB350M G-3
    Memory
    16GB DDR4
    Graphics card(s)
    RX-480
    Sound Card
    In-Built Realtek
    Monitor(s) Displays
    Samsung
    Screen Resolution
    1440p
    Hard Drives
    NVME/SSD's
    PSU
    Thermaltake BX1 550W
    Case
    Some junky thing
    Cooling
    ThermalTake Assassin(?)
    Browser
    FF/Edge
    Antivirus
    Whatever Windows does
    Other Info
    Secure Boot enabled updated to 2023 CA keys, TPM2.0 enabled with system drive Bitlocker'd.

My Computers My Computers

  • At a glance

    Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
this maybe of help
best of luck Steve ..
That was an interesting read. One of the more interesting things I got out of it is apparently the KEK can be used to validate boot manager files for booting an OS. Since the KEK is signed by and validated by the PK it's trust chain is solidly linked to it. A DB key, in contrast, can be signed and then validated by any KEK, regardless of the PK that KEK was validated with. This would make it possible to link an OS to one specific machine or "class" of machines. That sounds like a way to limit use of proprietary OS's I suppose: the machines would require a PK and KEK signed by it to run the OS.

They would have to maintain tight control on the PK and KEK certificates signed by it, and of course the OS would only operate in UEFI/Secure Boot so there's no disabling it and starting anyway.
 
Last edited:

My Computers My Computers

  • At a glance

    Windows 11 ProRyzen 7 5800XGSkill 3200, 2x8GBMSI RX 6800 XT Gaming Z
    OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 5800X
    Motherboard
    Gigabyte B550M Aorus Pro
    Memory
    GSkill 3200, 2x8GB
    Graphics Card(s)
    MSI RX 6800 XT Gaming Z
    Sound Card
    on-board Realtek
    Monitor(s) Displays
    MSI 180hz
    Screen Resolution
    1440p
    Hard Drives
    Samsung 980 Pro, Samsung 870 Evo, generic PCIe NVME, WD 1TB 2.5" laptop spinner
    PSU
    Corsair RM 650
    Case
    mATX
    Cooling
    BeQuiet 240mm AIO and a bunch of case fans
    Keyboard
    one that clacks softly
    Mouse
    logitech
    Internet Speed
    bunches of bps
    Browser
    Firefox
    Antivirus
    Windows' own
  • At a glance

    Win11 ProRyzen 7 170016GB DDR4RX-480
    Operating System
    Win11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 1700
    Motherboard
    GA-AB350M G-3
    Memory
    16GB DDR4
    Graphics card(s)
    RX-480
    Sound Card
    In-Built Realtek
    Monitor(s) Displays
    Samsung
    Screen Resolution
    1440p
    Hard Drives
    NVME/SSD's
    PSU
    Thermaltake BX1 550W
    Case
    Some junky thing
    Cooling
    ThermalTake Assassin(?)
    Browser
    FF/Edge
    Antivirus
    Whatever Windows does
    Other Info
    Secure Boot enabled updated to 2023 CA keys, TPM2.0 enabled with system drive Bitlocker'd.
That was an interesting read. One of the more interesting things I got out of it is apparently the KEK can be used to validate boot manager files for booting an OS. Since the KEK is signed by and validated by the PK it's trust chain is solidly linked to it. A DB key, in contrast, can be signed and then validated by any KEK, regardless of the PK that KEK was validated with. This would make it possible to link an OS to one specific machine or "class" of machines. That sounds like a way to limit use of proprietary OS's I suppose: the machines would require a PK and KEK signed by it to run the OS.

They would have to maintain tight control on the PK and KEK certificates signed by it, and of course the OS would only operate in UEFI/Secure Boot so there's no disabling it and starting anyway.

the idea is with your own MOK is that you control the secure boot/TPM infrastructure and data
as its your key it should let you take control and update the secure boot certs which Windows requires to boot.

this is not a major problem on newish systems as the secure boot cert is updatable
but on older systems that they, whoever they maybe, have stated wont get updated certs.

i had to do this on Ubuntu Linux 16 or 18 LTS as the secure boot keys weren't made available for Linux at that time
once i had created my own MOK then i was able to use the Debian boot shim for Ubuntu Linux to use secure boot.

a bit off topic
best of luck Steve ..
 

My Computers My Computers

  • At a glance

    Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
Will a tutorial be put out for those of us that aren't experts in Secure Boot and certificates? I have (3) older/unsupported devices. Since I barely use the oldest one, I opted to attempt and run Mosby yesterday...no luck. I followed the steps on the Mosby GitHub site...only result was an image security validation error. I'm sure it is operator (me) error...what should I try or what am I failing to do properly:

1) I disabled Secure Boot in the BIOS...restart
2) I created a UEFI Shell boot disk using Rufus and the instructions provided on the Mosby Page...I selected/used the UEFI Shell 2.2 25H2 option.
3) I downloaded the latest Mosby zip file...2.7. I extracted it and cut/paste the contents onto the drive...it replaces 7 files (I think) that were originally created by the UEFI Shell process.
4) I start machine, hit the function key to load boot menu, and select the drive...it attempts but fails with error.
5) I also tried booting the drive without copying the latest Mosby files to it...still didn't work.

The only other thing I can think of is that I did see a "clear certificates" option in the BIOS...security tab where I disabled Secure Boot. I was fearful of doing that as I don't know what the consequences are.
 

My Computers My Computers

  • At a glance

    Windows 11Intel i7-7700K32GB 2666Mhz (Kingston Hyper X Fury)Asus Nvidia 1050Ti
    OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom
    CPU
    Intel i7-7700K
    Motherboard
    Asus Prime Z-270A
    Memory
    32GB 2666Mhz (Kingston Hyper X Fury)
    Graphics Card(s)
    Asus Nvidia 1050Ti
    Sound Card
    N/A
    Monitor(s) Displays
    Samsung C27F390
    Screen Resolution
    1920 x 1080
    Hard Drives
    1TB Western Digital SN770 (System) and 2TB Western Digital SN770 (Storage)
    Antivirus
    Windows Security
  • At a glance

    Windows 11 Homei9-11900H32GBIntegrated Intel and Nvidia 3050Ti
    Operating System
    Windows 11 Home
    Computer type
    Laptop
    Manufacturer/Model
    Dell/XPS 15 9510
    CPU
    i9-11900H
    Motherboard
    Unknown
    Memory
    32GB
    Graphics card(s)
    Integrated Intel and Nvidia 3050Ti
    Sound Card
    Integrated (Realtek)
    Monitor(s) Displays
    None
    Screen Resolution
    1920 x 1200 (non-Touch)
    Hard Drives
    2TB SK Hynix P41 Platinum
    Antivirus
    Windows Security
Will a tutorial be put out for those of us that aren't experts in Secure Boot and certificates? I have (3) older/unsupported devices. Since I barely use the oldest one, I opted to attempt and run Mosby yesterday...no luck. I followed the steps on the Mosby GitHub site...only result was an image security validation error. I'm sure it is operator (me) error...what should I try or what am I failing to do properly:

1) I disabled Secure Boot in the BIOS...restart
2) I created a UEFI Shell boot disk using Rufus and the instructions provided on the Mosby Page...I selected/used the UEFI Shell 2.2 25H2 option.
3) I downloaded the latest Mosby zip file...2.7. I extracted it and cut/paste the contents onto the drive...it replaces 7 files (I think) that were originally created by the UEFI Shell process.
4) I start machine, hit the function key to load boot menu, and select the drive...it attempts but fails with error.
5) I also tried booting the drive without copying the latest Mosby files to it...still didn't work.

The only other thing I can think of is that I did see a "clear certificates" option in the BIOS...security tab where I disabled Secure Boot. I was fearful of doing that as I don't know what the consequences are.
I did this......

How to manage the Windows Boot Manager revocations for Secure Boot changes associated with CVE-2023-24932

Then I did what is in @Scott #1104 post in this thread.

@Scott #1104
 

My Computer My Computer

At a glance

Windows 11 Enterprise
OS
Windows 11 Enterprise
Will a tutorial be put out for those of us that aren't experts in Secure Boot and certificates? I have (3) older/unsupported devices. Since I barely use the oldest one, I opted to attempt and run Mosby yesterday...no luck. I followed the steps on the Mosby GitHub site...only result was an image security validation error. I'm sure it is operator (me) error...what should I try or what am I failing to do properly:

1) I disabled Secure Boot in the BIOS...restart
2) I created a UEFI Shell boot disk using Rufus and the instructions provided on the Mosby Page...I selected/used the UEFI Shell 2.2 25H2 option.
3) I downloaded the latest Mosby zip file...2.7. I extracted it and cut/paste the contents onto the drive...it replaces 7 files (I think) that were originally created by the UEFI Shell process.
4) I start machine, hit the function key to load boot menu, and select the drive...it attempts but fails with error.
5) I also tried booting the drive without copying the latest Mosby files to it...still didn't work.

The only other thing I can think of is that I did see a "clear certificates" option in the BIOS...security tab where I disabled Secure Boot. I was fearful of doing that as I don't know what the consequences are.
I don't see the part where you put the BIOS in Setup Mode after turning off Secure Boot? You could probably Clear Certificates providing you also see an option to Reset Factory Keys if Mosby still doesn't work. Security Violations seem to be related to the Platform Key when using Mosby, only way around it is to see if you can clear that key. Some devices may have the PK key locked by the OEM so that you can't override it, more likely on a used corporate business device. From what I've read on the matter, ASUS devices seem play very nicely with Mosby.
 
Last edited:

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
only result was an image security validation error.

That's because you have Secure Boot enabled. The UEFI Shell is not Secure Boot signed (and cannot be, since it would allow bad actors to install malware), so you need to make sure that Secure Boot is really disabled, or else you won't boot the shell.

As long as you see a security validation error when attempting to boot your media, Secure Boot is enabled, and you need to figure out how to disable it.

The only other thing I can think of is that I did see a "clear certificates" option in the BIOS...security tab where I disabled Secure Boot. I was fearful of doing that as I don't know what the consequences are.

Well, you will need to do that if you wanna run Mosby. And doing so will disable Secure Boot. So you should do that. If you want to run Mosby, that's the first thing you should do. And this has the nice consequence of also disabling Secure Boot, which you also need if you want to run Mosby. And don't worry, almost every UEFI firmware out there provides an option to restore the keys if you screw up or encounter a problem (and Windows will happily boot with Secure Boot disabled anyway), so you're not going to end up with a Windows that can no longer boot.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
Home Built
Screen Resolution
4k
Will a tutorial be put out for those of us that aren't experts in Secure Boot and certificates? I have (3) older/unsupported devices. Since I barely use the oldest one, I opted to attempt and run Mosby yesterday...no luck. I followed the steps on the Mosby GitHub site...only result was an image security validation error. I'm sure it is operator (me) error...what should I try or what am I failing to do properly:

1) I disabled Secure Boot in the BIOS...restart
2) I created a UEFI Shell boot disk using Rufus and the instructions provided on the Mosby Page...I selected/used the UEFI Shell 2.2 25H2 option.
3) I downloaded the latest Mosby zip file...2.7. I extracted it and cut/paste the contents onto the drive...it replaces 7 files (I think) that were originally created by the UEFI Shell process.
4) I start machine, hit the function key to load boot menu, and select the drive...it attempts but fails with error.
5) I also tried booting the drive without copying the latest Mosby files to it...still didn't work.

The only other thing I can think of is that I did see a "clear certificates" option in the BIOS...security tab where I disabled Secure Boot. I was fearful of doing that as I don't know what the consequences are.
I would do nothing and rely on Windows Updates!
 

My Computer My Computer

At a glance

Windows 11 ProCore i7-13700K64 GB Kingston Fury Beast DDR5Gigabyte GeForce RTX 2060 Super Gaming OC 8G
OS
Windows 11 Pro
Computer type
PC/Desktop
Manufacturer/Model
Self build
CPU
Core i7-13700K
Motherboard
Asus TUF Gaming Plus WiFi Z790
Memory
64 GB Kingston Fury Beast DDR5
Graphics Card(s)
Gigabyte GeForce RTX 2060 Super Gaming OC 8G
Sound Card
Realtek S1200A
Monitor(s) Displays
Viewsonic VP2770 & Dell (secondary)
Screen Resolution
2560 x 1440
Hard Drives
Kingston KC3000 2TB NVME SSD & SATA HDDs & SSD
PSU
EVGA SuperNova G2 850W
Case
Nanoxia Deep Silence 1
Cooling
Noctua NH-D14
Keyboard
Microsoft Digital Media Pro
Mouse
Logitech Wireless
Internet Speed
80 Mb / s
Browser
Chrome
Antivirus
Defender, Malwarebytes Free & AdwCleaner

My Computer My Computer

At a glance

Windows 11 Home x64 Version 25H2 Build 26200....
OS
Windows 11 Home x64 Version 25H2 Build 26200.8037
I would do nothing and rely on Windows Updates!
Or just create a file and name it config.sys , then add the line BUGS = 0,0
 

My Computer My Computer

At a glance

windows 11Intel i5-10600kf32gb corsair vengerance proAMD RX 6500XT
OS
windows 11
Computer type
PC/Desktop
Manufacturer/Model
Antec/Case
CPU
Intel i5-10600kf
Motherboard
GIGABYTE Z590 UD AC
Memory
32gb corsair vengerance pro
Graphics Card(s)
AMD RX 6500XT
Sound Card
onboard
Monitor(s) Displays
40" Hisense
Hard Drives
Samsung 850
Samsung 870
Seagate 2TB
PSU
EVGA GQ 750
Or just create a file and name it config.sys , then add the line BUGS = 0,0
Please explain that unique suggestion and complete the suggestion by telling us all where we can stick it.


Denis
 

My Computer My Computer

At a glance

Windows 11 Home x64 Version 25H2 Build 26200....
OS
Windows 11 Home x64 Version 25H2 Build 26200.8037

Latest Support Threads

Back
Top Bottom