Solved garlin's PowerShell scripts for updating Secure Boot CA 2023


I wrote a blog post today that includes a PS script to repair a freshly-built Macrium Reflect X Rescue Media UFD to workable condition. Check it out at: Fixing Macrium Rescue Disk - Ed Tittel.
Hope some readers find this helpful,
--Ed--
Why am I getting this:
PS C:\SecureBoot USB Boot drive fix Macrium> .\fixmrrd.ps1 -TargetDrive I:
At C:\SecureBoot USB Boot drive fix Macrium\fixmrrd.ps1:174 char:58
+ if (-not (Test-Path (Split-Path $destExternal))) {
+ ~
Missing closing '}' in statement block or type definition.
At C:\SecureBoot USB Boot drive fix Macrium\fixmrrd.ps1:171 char:33
+ if (-not $SkipExternalBoot) {
+ ~
Missing closing '}' in statement block or type definition.
At C:\SecureBoot USB Boot drive fix Macrium\fixmrrd.ps1:73 char:5
+ try {
+ ~
Missing closing '}' in statement block or type definition.
At C:\SecureBoot USB Boot drive fix Macrium\fixmrrd.ps1:175 char:71
+ ... Write-Fail "EFI boot directory not found on $TargetDrive."
+ ~
The Try statement is missing its Catch or Finally block.
+ CategoryInfo : ParserError: (:) [], ParseException
+ FullyQualifiedErrorId : MissingEndCurlyBrace

PS C:\SecureBoot USB Boot drive fix Macrium>
 

My Computer My Computer

At a glance

win 11Intell Core i7 4900 MQDDR3 16 GB
OS
win 11
Computer type
Laptop
Manufacturer/Model
Dell Precision M4800
CPU
Intell Core i7 4900 MQ
Motherboard
Dell QT3YTY A00
Memory
DDR3 16 GB
That's easy. The second half of the script is missing from Ed's OneDrive link.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7

My Computer My Computer

At a glance

win 11Intell Core i7 4900 MQDDR3 16 GB
OS
win 11
Computer type
Laptop
Manufacturer/Model
Dell Precision M4800
CPU
Intell Core i7 4900 MQ
Motherboard
Dell QT3YTY A00
Memory
DDR3 16 GB
If the update script cannot find a matching KEK bin for your PC, it will recommend you first try manual KEK enrollment.

That's wheere you enter Custom Mode, and see if you're allowed to add a KEK cert from a file. Depending on your BIOS, this may not be supported. If it works, add the KEK cert and run the update script again. If you're not allowed to add a KEK file, then use the Clear All Keys option, and run the update script.


Run the update script first without -Revoke to see if it's successful. Presuming everything work, then run the -Revoke.


26H2 is the same as 24H2 & 25H2 in terms of Secure Boot. The certs are the same for all Windows releases.
Hello Garlin, I had to delete all keys, ran script, looked good, ran script with -Revoke, here's the outcome:

PS C:\User\Bob\GarlinUEFI2023> .\check_uefi-ca2023.ps1 -audit -verbose
Windows 11 25H2 (26200.9550)
Secure Boot: OFF (Audit Report runs as ON)
Virtualization Based Security: OFF (Audit Report runs as ON)
BitLocker on (C:) OFF

BIOS Firmware
-------------
Sony Corporation SVE15128CXS
Version: R0200D5
Date: 2016-09-25

Factory Default UEFI PK Cert
----------------------------
(NONE)

UEFI PK Cert
------------
Windows OEM Devices PK

Factory Default UEFI KEK Certs
------------------------------
(NONE)

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023

Factory Default UEFI DB Certs
-----------------------------
(NONE)

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

Factory Default UEFI DBX Certs
------------------------------
(NONE)
EFI_CERT_SHA256_GUID Signatures: 0

UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 11.0
EFI_CERT_SHA256_GUID Signatures: 5

UEFI Variables
--------------
SBAT (Linux only): sbat,1,2025051000 / shim,4 / grub,5 / grub.debian,4 / grub.peimage,2 / grub.proxmox,2

EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] will be ALLOWED.
\\.\HarddiskVolume3\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.367, SVN 11.0

Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

[OPTIONAL] SkuSiPolicy.p7b (for VBS) is MISSING.

AUDIT REPORT
============
1. Secure Boot is DISABLED
2. DBX Updates are missing from UEFI DBX

[OPTIONAL] SkuSiPolicy.p7b (for VBS) is missing from EFI

STATUS REPORT
-------------
Registry: "UEFICA2023Status" = Updated


REQUIRED ACTION
===============

To update DBXUpdate signatures, run the commands:

reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x2 /f
powershell Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

I have'nt done the above "required actions". Should I?
================================

FAILED: Missing 291/291 SVN signatures from "dbxupdate.bin"
SUCCESS: Matched 3/3 SVN signatures from "DBXUpdate2024.bin"
SUCCESS: Matched 3/3 SVN signatures from "DBXUpdateSVN.bin"
===========================================
anything I should do?
I have'nt applied:
schtasks /change /disable /tn "\Microsoft\Windows\PI\Secure-Boot-Update, should I?

Thank you so much for you guidance!
 

My Computer My Computer

At a glance

Windows 11 25H2Intel Core i7-3632QM 2.20GHZ / 3.20GHZ8MB DDR3-1600 SDRAM (SODRAM)Intel HD4000
OS
Windows 11 25H2
Computer type
Laptop
Manufacturer/Model
Sony Vaio sve15128cxs
CPU
Intel Core i7-3632QM 2.20GHZ / 3.20GHZ
Motherboard
Ivy Bridge, Insyde Bios- R0200D5 (9/26/2016)
Memory
8MB DDR3-1600 SDRAM (SODRAM)
Graphics Card(s)
Intel HD4000
Hard Drives
1 TB-HDD Western Digital WDC WD10JPVT-55A1YT0
Cooling
3 fan cooling pad plus internal.
Mouse
Logitech ERGO
Antivirus
Norton365, Norton AntiTrack.
Other Info
Sony doesn’t support anymore and has deleted all firmware and software from their site.
UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 11.0
EFI_CERT_SHA256_GUID Signatures: 5
DBX -> PCA 2011 is banned + 5 SVN's
So you're in no danger of overflowing the DBX.

REQUIRED ACTION
===============

To update DBXUpdate signatures, run the commands:

reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x2 /f
powershell Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"
You should ignore this advice, since the check script has no idea you DON'T WANT THIS.
It's providing instructions for the 95% of other users who can update the DBX without any concerns.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Hi, i found this forum when looking for a solution regarding the 2023 certificate.

I have an old computer enrolled with esu but the event viewer keep giving error everytime the computer startup,
there are error 1797: The Secure Boot update failed as the Windows UEFI CA 2023 certificate is not present in Db
and error 1802: The Secure Boot update KEK 2023 was blocked due to a known firmware issue on the device.

I ran the script for checking and the below is the result, the computer is already eol so it will not get any new bios update, does this mean i shouldn't proceed and can only ignore the event viewer?

Thanks in advance.

Secure Boot: ON
Virtualization Based Security: ON
BitLocker on (C:) OFF

BIOS Firmware
-------------
Hewlett-Packard HP Pro 3330 MT
Version: 8.06
Date: 2013-01-24
This BIOS may be corrupted by updating Secure Boot certs.

UEFI PK Cert
------------
(NONE)
Platform Key is UNTRUSTED.

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011

UEFI DBX Certs
--------------
(NONE)

EFI Files
---------
Windows Boot Manager [Production PCA 2011] is ALLOWED.

Registry: "WindowsUEFICA2023Capable" = 0
[Windows UEFI CA 2023] not in UEFI DB.

[OPTIONAL] SkuSiPolicy.p7b (for VBS) is MISSING.

STATUS REPORT
-------------
Registry: "UEFICA2023Status" = InProgress
Registry: "ConfidenceLevel" = Temporarily Paused

This device is affected by a known issue. This may require a firmware update.
 

My Computer My Computer

At a glance

Windows 10
OS
Windows 10
Computer type
PC/Desktop
I have an old computer enrolled with esu but the event viewer keep giving error everytime the computer startup,
there are error 1797: The Secure Boot update failed as the Windows UEFI CA 2023 certificate is not present in Db
and error 1802: The Secure Boot update KEK 2023 was blocked due to a known firmware issue on the device.

I ran the script for checking and the below is the result, the computer is already eol so it will not get any new bios update, does this mean i shouldn't proceed and can only ignore the event viewer?

Thanks in advance.

Secure Boot: ON
Virtualization Based Security: ON
BitLocker on (C:) OFF

BIOS Firmware
-------------
Hewlett-Packard HP Pro 3330 MT
Version: 8.06
Date: 2013-01-24
This BIOS may be corrupted by updating Secure Boot certs.
There is a possibility that some older PC's can get "bricked" when trying to the update certs, due to HW or firmware limitation on how much space is allocated to Secure Boot variables.

For about a year, MS has been collecting telemetry data from different PC's and organizing them into "buckets" based on motherboard model and BIOS revision. Based on this data and working with the OEM's, it has marked some buckets as ineligible for updates because of known issues. MS won't provide a specific reason why, other than updates should not go forward on tagged models.

Your BIOS is dated from 2013, and no longer supported. It might be possible to perform a manual enrollment, but it's not clear if revoking the PCA 2011 cert will lead to UEFI errors or not. You can obviously try, but since no one else has reported whether it worked on this model, it's a big unknown.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
UPDATE: 2026-10-08

1. Add option for Update_UEFI-CA2023.ps1 to block dbxupdate.bin updates
2. Update_UEFI-CA2023.ps1 needs to update SecureBoot reg keys when "Secure-Boot-Update" task is disabled or removed

Update_UEFI-CA2023.ps1 now has the -RevokeNoDBX option, which can be used in the place of -Revoke. Both options are mutually exclusive; you can only pick between one of the two. -RevokeNoDBX will ban the CA 2011 cert and update the SVN, without adding the hundreds of potentially new EFI signatures to the DBX.

Some users with older BIOS'es have a known (or suspected) HW or firmware limitation where overflowing the DBX with too much data can "brick" the UEFI. In order to provide partial Secure Boot protection, we can ban CA 2011 boot managers. This leaves the PC insecure as the DBX signatures are designed to block banned non-Windows EFI boot files with known security exploits.

It's not a recommended solution, but some users have specifically asked for this type of outcome rather than give up their unsupported PC. Most normal users should be using the regular -Revoke option (when needed).

-RevokeNoDBX will disable the Secure Boot task, because we don't want Windows to force a DBX update whenever MS announces they will finally enforce the CA 2011 revocation. When the Secure Boot task is no longer running, the status reg keys are not updated. So the update script has to update the WindowsUEFICA2023Capable & UEFICA2023Status keys.
 
Last edited:

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Nice addition.

1791525349793.webp
 

My Computers My Computers

  • At a glance

    Win 11 Pro 26H2 26300.9550Intel® Core™ i7-14700KG.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5ASUS GeForce RTX 4070 Super 12GB
    OS
    Win 11 Pro 26H2 26300.9550
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel® Core™ i7-14700K
    Motherboard
    ASUS TUF Z690-PLUS WIFI (BIOS 4601)
    Memory
    G.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5
    Graphics Card(s)
    ASUS GeForce RTX 4070 Super 12GB
    Sound Card
    Sound Blaster AE-5 Plus
    Monitor(s) Displays
    ASUS TUF Gaming 27" 2K HDR Gaming
    Screen Resolution
    2560 x 1440
    Hard Drives
    Samsung 990 Pro 1TB NVMe (Win 11 25H2)
    SK hynix P41 500GB NVMe
    SK hynix P41 2TB NVMe (x3)
    Crucial P3 Plus 4TB
    PSU
    Corsair RM850x Shift
    Case
    Antec Dark Phantom DP502 FLUX
    Cooling
    Corsair Nautilus 360 RS AIO
    Keyboard
    Logitech MK 320
    Mouse
    Razer Basilisk V3
    Internet Speed
    750Mbs
    Browser
    Firefox
    Antivirus
    Winows Security
    Other Info
    MR 8.1 Home
  • At a glance

    Win 11 Pro 25H2 26300.9550Intel Core i5-1140064 GB DDR4MSI GeForce RTX 3060 Ventus 2X 12GB
    Operating System
    Win 11 Pro 25H2 26300.9550
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel Core i5-11400
    Motherboard
    Asus TUF Gaming Z590 Plus WiFi (BIOS 2803)
    Memory
    64 GB DDR4
    Graphics card(s)
    MSI GeForce RTX 3060 Ventus 2X 12GB
    Sound Card
    SoundBlaster Audigy Fx V2
    Monitor(s) Displays
    Samsung F27T350
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 980 Pro 1TB
    Samsung 970 EVO Plus 2TB
    Samsung 870 EVO 500GB SSD
    PSU
    Corsair HX750
    Case
    Cougar MX330-G Window
    Cooling
    Thermalright Frozen Edge 240 Black AIO
    Internet Speed
    350Mbps
    Browser
    Firefox
    Antivirus
    Windows Security
  • System Three
    Win 11 Pro 25H2 26300.9550
    ASUS PRIME Z370-P II BIOS 3004 7/12/21
    Intel Core i7-8700 CPU @ 3.20GHz
    32GB DDR4 RAM (4x8)
    Samsung 980 Pro 500 GB
    SK hynix P41 1 TB
    EVGA RTX 2060 (used)
    iGPU Intel UHD Graphics 630 (backup)
    Cooler Master Hyper 212
    Mid-Tower Desktop
UPDATE: 2026-10-08

1. Add option for Update_UEFI-CA2023.ps1 to block dbxupdate.bin updates
2. Update_UEFI-CA2023.ps1 needs to update SecureBoot reg keys when "Secure-Boot-Update" task is disabled or removed

Update_UEFI-CA2023.ps1 now has the -RevokeNoDBX option, which can be used in the place of -Revoke. Both options are mutually exclusive; you can only pick between one of the two. -RevokeNoDBX will ban the CA 2011 cert and update the SVN, without adding the hundreds of potentially new EFI signatures to the DBX.

Some users with older BIOS'es have a known (or suspected) HW or firmware limitation where overflowing the DBX with too much data can "brick" the UEFI. In order to provide partial Secure Boot protection, we can ban CA 2011 boot managers. This leaves the PC insecure as the DBX signatures are designed to block banned non-Windows EFI boot files with known security exploits.

It's not a recommended solution, but some users have specifically asked for this type of outcome rather than give up their unsupported PC. Most normal users should be using the regular -Revoke option (when needed).

-RevokeNoDBX will disable the Secure Boot task, because we don't want Windows to force a DBX update whenever MS announces they will finally enforce the CA 2011 revocation. When the Secure Boot task is no longer running, the status reg keys are not updated. So the update script has to update the WindowsUEFICA2023Capable & UEFICA2023Status keys.

This is my main machine:

1791525889975.webp
 

My Computer My Computer

At a glance

Windows 11 Pro 25H2Intel I9-9900K64GBNVIDIA RTX 2060
OS
Windows 11 Pro 25H2
Computer type
PC/Desktop
Manufacturer/Model
Dell XPS 8930
CPU
Intel I9-9900K
Memory
64GB
Graphics Card(s)
NVIDIA RTX 2060
Sound Card
NVIDIA High Definition Audio
Monitor(s) Displays
4k Samsung
Screen Resolution
3840 x 2160
Hard Drives
512GB NVMe, ADATA SU 800, 2TB HDD
Nice addition.
Some users have to disable the Secure Boot task because of unrelated TPM issues (for example, Dell's with a STMicroelectronics chip). When the task runs 5 min. after every reboot, it triggers a TPM attestation call (or audit). This locks up the system.

The task isn't necessarily doing any changes, but in order to refresh the status reg keys, it needs to run attestation to definitively prove that Secure Boot is indeed actually working. Without positive confirmation, certain updates are paused until the status can be verified. The lockups are an unintentional side effect of the task doing its normal thing.

Until there's a firmware fix for your TPM chip, some users are stuck disabling the task. It's not ideal, but you don't have an option. The good news is you can use the update script to do most of the same work (like updating the SVN and boot manager). My script can't do any attestation (it's a highly priviledged system call), so it won't hang your PC.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7

Latest Support Threads

Back
Top Bottom