Solved garlin's PowerShell scripts for updating Secure Boot CA 2023


If you were to use Hasleo's currently saved WinPE (from its staging folder), it wouldn't be allowed to boot on any PC which has a SVN (in the UEFI) of 8.0 or higher. Which is any PC updated since April 2026.

But your USB drive has the updated boot file (SVN 9.0). Either because it was updated outside of Hasleo, or used a different (newer) version of the WinPE. The best solution is always see if there's a newer version of the WinPE to download. And if there isn't, to create the recovery USB using the normal methods, and then copy a newer boot file over the finished drive.
The USB had Ventoy on it before. The Hasleo was used to create the USB and it did a format first. It build the WinPE components from the Widows Recovery environment. It was not updated outside of Hasleo. The script was run after that, so I guess it gets the SVN from the WinRE.
 

My Computer My Computer

At a glance

Windows 11 ProIntel Core Ultra16GBIntel(R) Arc Graphics
OS
Windows 11 Pro
Computer type
Laptop
Manufacturer/Model
ASUS Zenbook 14 OLED
CPU
Intel Core Ultra
Memory
16GB
Graphics Card(s)
Intel(R) Arc Graphics
Sound Card
Realtek High Definition Audio(SST)
Screen Resolution
2880 x 1800
Hard Drives
500 GB NVMe SSD
Internet Speed
1,500Mbps
Browser
Firefox, Edge
Antivirus
Windows Defender
The USB had Ventoy on it before. The Hasleo was used to create the USB and it did a format first. It build the WinPE components from the Widows Recovery environment. It was not updated outside of Hasleo. The script was run after that, so I guess it gets the SVN from the WinRE.
Do you happen to know where Hasleo keeps its copy of the WinRE files? I only have the option for WinPE in the Hasleo I installed for test purposes.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Here is the result of the new Check script:
*
EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.352, SVN 9.0

Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

SkuSiPolicy.p7b is CURRENT.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b
Version: 3.0.0.16

Macrium Folders
---------------
Windows Boot Manager [Production PCA 2011] is BANNED.
c:\boot\macrium\WinREFiles\media\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.352, SVN 9.0

Bootable Media
--------------
USB Drive J:
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
J:\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.352, SVN 9.0


STATUS REPORT
-------------
Registry: "UEFICA2023Status" = Updated

SUCCESS: UPDATES ARE FINISHED.
UEFI CA 2023 certs are present, PCA 2011 cert is revoked.
*
Everything works The rescue USB boots prpoperly into Macrium.

But why does the script show BANNED in Macrium Folders? I forced Macrium to build a new WIM.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 24H2Intel i7-1260P 12th Gen 4.7GHz32GB DDR4-3200NVIDIA T550 Laptop GPU
    OS
    Windows 11 Pro 24H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo P16s Workstation
    CPU
    Intel i7-1260P 12th Gen 4.7GHz
    Memory
    32GB DDR4-3200
    Graphics Card(s)
    NVIDIA T550 Laptop GPU
    Sound Card
    Realtek Audio
    Monitor(s) Displays
    16" Laptop Display
    Screen Resolution
    2560x1600
    Hard Drives
    2TB Samsung M.2 2280 SSD PCIe 4.0 x 4 NVMe
    Mouse
    Logitech MX Anywhere 2s
    Internet Speed
    1000 Mb
    Browser
    Firefox
    Antivirus
    Avast
  • At a glance

    Windows 11 Pro 24H2i7-6820HQ 6th Gen 3.6 GHz32GB DDR4-2133NVIDIA Quadro M2000M Laptop GPU
    Operating System
    Windows 11 Pro 24H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo P50 Workstation
    CPU
    i7-6820HQ 6th Gen 3.6 GHz
    Memory
    32GB DDR4-2133
    Graphics card(s)
    NVIDIA Quadro M2000M Laptop GPU
    Sound Card
    Realtek Audio
    Monitor(s) Displays
    15.6" Laptop Display
    Screen Resolution
    1920x1080
    Hard Drives
    2 x 1TB Samsung M.2 2280 SSD PCIe 3.0 x 4 NVMe
    Cooling
    Dual Fan System
    Mouse
    Logitech MX Anywhere 2s
    Internet Speed
    1000 Mb
    Browser
    Firefox
    Antivirus
    Avast

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 26200.8894Intel® Core™ i7-14700KG.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5ASUS GeForce RTX 4070 Super 12GB
    OS
    Win 11 Pro 25H2 26200.8894
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel® Core™ i7-14700K
    Motherboard
    ASUS TUF Z690-PLUS WIFI (BIOS 4505)
    Memory
    G.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5
    Graphics Card(s)
    ASUS GeForce RTX 4070 Super 12GB
    Sound Card
    Sound Blaster AE-5 Plus
    Monitor(s) Displays
    ASUS TUF Gaming 27" 2K HDR Gaming
    Screen Resolution
    2560 x 1440
    Hard Drives
    Samsung 990 Pro 1TB NVMe (Win 11 25H2)
    SK hynix P41 500GB NVMe
    SK hynix P41 2TB NVMe (x3)
    Crucial P3 Plus 4TB
    PSU
    Corsair RM850x Shift
    Case
    Antec Dark Phantom DP502 FLUX
    Cooling
    Corsair Nautilus 360 RS AIO
    Keyboard
    Logitech MK 320
    Mouse
    Razer Basilisk V3
    Internet Speed
    750Mbs
    Browser
    Firefox
    Antivirus
    Winows Security
    Other Info
    MR 8.1 Home
  • At a glance

    Win 11 Pro 25H2 26200.8894Intel Core i5-1140064 GB DDR4MSI GeForce RTX 3060 Ventus 2X 12GB
    Operating System
    Win 11 Pro 25H2 26200.8894
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel Core i5-11400
    Motherboard
    Asus TUF Gaming Z590 Plus WiFi (BIOS 2803)
    Memory
    64 GB DDR4
    Graphics card(s)
    MSI GeForce RTX 3060 Ventus 2X 12GB
    Sound Card
    SoundBlaster Audigy Fx V2
    Monitor(s) Displays
    Samsung F27T350
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 980 Pro 1TB
    Samsung 970 EVO Plus 2TB
    Samsung 870 EVO 500GB SSD
    PSU
    Corsair HX750
    Case
    Cougar MX330-G Window
    Cooling
    Thermalright Frozen Edge 240 Black AIO
    Internet Speed
    350Mbps
    Browser
    Firefox
    Antivirus
    Windows Security
  • System Three
    Win 11 Pro 25H2 26200.8894
    ASUS PRIME Z370-P II BIOS 3004 7/12/21
    Intel Core i7-8700 CPU @ 3.20GHz
    32GB DDR4 RAM (4x8)
    iGPU Intel UHD Graphics 630
    Mid-Tower Desktop
Here is my HP Spectre with Macrium Reflect USB which works on all my PC.

PS C:\Users\thele> powershell -nop -ep bypass -f C:\TEMP\Check_UEFI-CA2023_2026-07-21.ps1 -BootMedia
Secure Boot: ON
Virtualization Based Security: OFF
BitLocker on (C:) OFF

BIOS Firmware
-------------
Hewlett-Packard HP Spectre x360 Convertible 13
Version: F.54
Date: 2019-12-26
This BIOS may be damaged by updating Secure Boot certs.

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
MosbyKey [2025.12.17]
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 9.0

EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.

Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

Macrium Folders
---------------
Windows Boot Manager [Production PCA 2011] is BANNED.

Hasleo Folders
--------------
Windows Boot Manager [Windows UEFI CA 2023] is BANNED.

Bootable Media
--------------
USB Drive D: "MACRIUMRESC"
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.

USB Drive F: "Spectre"
F:\EFI\Microsoft\Boot\boot.stl is MISSING.

STATUS REPORT
-------------
Registry: "UEFICA2023Status" = Updated
Registry: "ConfidenceLevel" = Temporarily Paused

WARNING: This BIOS may be damaged by updating Secure Boot certs.
Please check your PC vendor for a future BIOS update.

PS C:\Users\thele>
 

My Computers My Computers

  • At a glance

    Windows 11 Home, ver 25H2 build 26200.8246Intel Core i5 5200U @ 2.20GH4 GBIntel HD Graphics 5500 on board
    OS
    Windows 11 Home, ver 25H2 build 26200.8246
    Computer type
    Laptop
    Manufacturer/Model
    Hewlett-Packard Spectre 13-4001 x360 convertable
    CPU
    Intel Core i5 5200U @ 2.20GH
    Motherboard
    Hewlett-Packard 802D
    Memory
    4 GB
    Graphics Card(s)
    Intel HD Graphics 5500 on board
    Sound Card
    Intel Smart Sound Technology (Intel SST)
    Hard Drives
    Micron 256GB M.2 2280 NGFF SSD MTFDDAV256TBN, (SATA 6.0 Gb/s)
    Keyboard
    Model # G01KB
    Antivirus
    Microsoft Defender
    Other Info
    born on date: 25 Feb 2016
  • At a glance

    Win 11 Home 25H2 build 26200.7922Intel Core i7 4th Gen 4790 (3.60GHz), Haswell...Samsung 16 GB DDR3 (8GB in 2 modules)NVIDIA GeForce GTX 760, 3GB, and on-board Int...
    Operating System
    Win 11 Home 25H2 build 26200.7922
    Computer type
    PC/Desktop
    Manufacturer/Model
    Asus Desktop model M32AD-US019S (DOM: 6/9/2014 )
    CPU
    Intel Core i7 4th Gen 4790 (3.60GHz), Haswell 22nm Technology, SOCKET 1150
    Motherboard
    H81M-E/M51AD/DP_MB
    Memory
    Samsung 16 GB DDR3 (8GB in 2 modules)
    Graphics card(s)
    NVIDIA GeForce GTX 760, 3GB, and on-board Intel HD Graphics 4600 Rev 6
    Monitor(s) Displays
    HP EliteDisplay E241i LED; HP EliteDisplay E243
    Hard Drives
    Samsung 500GB SSD, 870 EVO (SATA 6.0 )
    Micron 250GB SSD, CT250MX500
    Toshiba HDD, 3GB (original drive w/PC)
    Case
    ASUS
    Keyboard
    ASUS-------------------------
    Antivirus
    MS Defender
    Other Info
    Additional Laptops:

    HEWLETT PACKARD
    HP OmniBook X Flip NGAI (Next Gen AI),
    Model: 16-as0023dx
    PT# B5UH1UA#ABA Product #: B5UH1UA
    delivered and setup 7/25/25
    16" 2K Touch-Screen Laptop
    Intel Core Ultra 7 256V '24 Series 2 - CPU
    Boost Clock Frequency 4.8 gigahertz; Neural Processing Unit (NPU) Yes;
    16GB Memory, LPDDR5X
    1TB SSD PCIe 4.0
    Graphics: Intel Arc 140V
    1 x HDMI 2.1
    1 x Thunderbolt 4
    2K Touch-Screen display, LED, IPS; 1920 x 1200 (Full HD+)
    USB Ports: 1 x USB-C 3.1, 2 x USB-A 3.1
    Wi-Fi 6E
    weight 4.15 pounds

    DELL
    Model:I7591-7483BLK-PUS 2-in-1 (7000 Series)
    purchased 12/3/2019,
    15.6 inch 2-IN-1;
    4K Ultra HD Touch-Screen, 3840 x 2160,
    Intel Core i7 10510U CPU 1.80GHz,
    16GB RAM DDR4 SDRAM 2400 megahert (2 slots),
    dedicated graphics Nvidia GeForce MX250 2 GB Graphics,
    PCIe 512GB Intel SSD + 32GB Optane Memory (Intel Optane Memory H10 with solid-state storage),
    wireless-AX & Bluetooth
    Battery: 68wh, Type 4VGMP 4 cell
Since it been revoked, it's now banned.

This is what matters
Duh! I guess I should pay attention to what I'm reading. PCA 2011 is banned. Of course it is!
Thanks.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 24H2Intel i7-1260P 12th Gen 4.7GHz32GB DDR4-3200NVIDIA T550 Laptop GPU
    OS
    Windows 11 Pro 24H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo P16s Workstation
    CPU
    Intel i7-1260P 12th Gen 4.7GHz
    Memory
    32GB DDR4-3200
    Graphics Card(s)
    NVIDIA T550 Laptop GPU
    Sound Card
    Realtek Audio
    Monitor(s) Displays
    16" Laptop Display
    Screen Resolution
    2560x1600
    Hard Drives
    2TB Samsung M.2 2280 SSD PCIe 4.0 x 4 NVMe
    Mouse
    Logitech MX Anywhere 2s
    Internet Speed
    1000 Mb
    Browser
    Firefox
    Antivirus
    Avast
  • At a glance

    Windows 11 Pro 24H2i7-6820HQ 6th Gen 3.6 GHz32GB DDR4-2133NVIDIA Quadro M2000M Laptop GPU
    Operating System
    Windows 11 Pro 24H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo P50 Workstation
    CPU
    i7-6820HQ 6th Gen 3.6 GHz
    Memory
    32GB DDR4-2133
    Graphics card(s)
    NVIDIA Quadro M2000M Laptop GPU
    Sound Card
    Realtek Audio
    Monitor(s) Displays
    15.6" Laptop Display
    Screen Resolution
    1920x1080
    Hard Drives
    2 x 1TB Samsung M.2 2280 SSD PCIe 3.0 x 4 NVMe
    Cooling
    Dual Fan System
    Mouse
    Logitech MX Anywhere 2s
    Internet Speed
    1000 Mb
    Browser
    Firefox
    Antivirus
    Avast
Here is my HP Spectre with Macrium Reflect USB which works on all my PC.

-------------
Hewlett-Packard HP Spectre x360 Convertible 13
Version: F.54
Date: 2019-12-26
This BIOS may be damaged by updating Secure Boot certs.
STATUS REPORT
-------------
Registry: "UEFICA2023Status" = Updated
Registry: "ConfidenceLevel" = Temporarily Paused

WARNING: This BIOS may be damaged by updating Secure Boot certs.
Please check your PC vendor for a future BIOS update.
I gotta fix this bug, it's confusing you have a HP BIOS which is missing a specific version string ("SBKPFV3") with your BIOS is in danger of bricking (it's not).
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Macrium Folders
---------------
Windows Boot Manager [Production PCA 2011] is BANNED.
c:\boot\macrium\WinREFiles\media\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.352, SVN 9.0
I'm just reporting what's in the staging folder. Presumably these files are used when they build a new WIM.

Bootable Media
--------------
USB Drive J:
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
J:\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.352, SVN 9.0
But why does the script show BANNED in Macrium Folders? I forced Macrium to build a new WIM.
What happens if you rebuild the USB right now? Do you end up with the same results?
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
@starchase, can you run two commands for me?
Code:
Get-ItemPropertyValue 'HKLM:\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing' -Name 'ConfidenceLevel'
Get-ItemPropertyValue 'HKLM:\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing' -Name 'BucketHash'

BucketHash is "generic" value assigned to everyone with the exact same HP model/BIOS as you, so there's no personal data associated with this value.

I need to cross-index your BucketHash against the published Confidence files to see if MS categorized this PC as "maybe HP is working an official update for this model". It might not be true, but according to the process detailed by MS, that's supposed to be what's going on.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
I'm just reporting what's in the staging folder. Presumably these files are used when they build a new WIM.



What happens if you rebuild the USB right now? Do you end up with the same results?
Yes, same results, except I have to run your Update script again for the USB boot drive. The Macrium folders still have the banned PCA 2011.

BTW, when I run your Update script for the USB, I get this in bright red:

*
The regular expression pattern *LENOVO*M700* is not valid.
At [path to script] \Update_UEFI-CA2023.ps1:1749 char:5
+ '*LENOVO*M700*' { $Unsafe_Model = $true }
+ ~~~~~~~~~~~~~~~
+ CategoryInfo : InvalidOperation: (*LENOVO*M700*:String) [], RuntimeException
+ FullyQualifiedErrorId : InvalidRegularExpression
*

The script still completes and updates the USB.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 24H2Intel i7-1260P 12th Gen 4.7GHz32GB DDR4-3200NVIDIA T550 Laptop GPU
    OS
    Windows 11 Pro 24H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo P16s Workstation
    CPU
    Intel i7-1260P 12th Gen 4.7GHz
    Memory
    32GB DDR4-3200
    Graphics Card(s)
    NVIDIA T550 Laptop GPU
    Sound Card
    Realtek Audio
    Monitor(s) Displays
    16" Laptop Display
    Screen Resolution
    2560x1600
    Hard Drives
    2TB Samsung M.2 2280 SSD PCIe 4.0 x 4 NVMe
    Mouse
    Logitech MX Anywhere 2s
    Internet Speed
    1000 Mb
    Browser
    Firefox
    Antivirus
    Avast
  • At a glance

    Windows 11 Pro 24H2i7-6820HQ 6th Gen 3.6 GHz32GB DDR4-2133NVIDIA Quadro M2000M Laptop GPU
    Operating System
    Windows 11 Pro 24H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo P50 Workstation
    CPU
    i7-6820HQ 6th Gen 3.6 GHz
    Memory
    32GB DDR4-2133
    Graphics card(s)
    NVIDIA Quadro M2000M Laptop GPU
    Sound Card
    Realtek Audio
    Monitor(s) Displays
    15.6" Laptop Display
    Screen Resolution
    1920x1080
    Hard Drives
    2 x 1TB Samsung M.2 2280 SSD PCIe 3.0 x 4 NVMe
    Cooling
    Dual Fan System
    Mouse
    Logitech MX Anywhere 2s
    Internet Speed
    1000 Mb
    Browser
    Firefox
    Antivirus
    Avast
The regular expression pattern *LENOVO*M700* is not valid.
At [path to script] \Update_UEFI-CA2023.ps1:1749 char:5
+ '*LENOVO*M700*' { $Unsafe_Model = $true }
+ ~~~~~~~~~~~~~~~
+ CategoryInfo : InvalidOperation: (*LENOVO*M700*:String) [], RuntimeException
+ FullyQualifiedErrorId : InvalidRegularExpression
*

The script still completes and updates the USB.
Yeah, someone already flagged that bug on my GitHub. Forgot to copy a fix from the check script.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Ok Asus Plus Gaming b650

Code:
powershell -nop -ep bypass -f E:\Z_c2023\Check_UEFI-CA2023.ps1 -BootMedia
Secure Boot: ON
Virtualization Based Security: ON
BitLocker on (C:) OFF

UEFI KEK Certs
--------------
    Microsoft Corporation KEK CA 2011
    Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
    Microsoft Corporation UEFI CA 2011
    Microsoft Windows Production PCA 2011
    Microsoft Option ROM UEFI CA 2023
    Microsoft UEFI CA 2023
    Windows UEFI CA 2023

UEFI DBX Certs
--------------
    Microsoft Windows Production PCA 2011
    Windows BootMgr SVN 9.0

EFI Files
---------
    Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.

    Registry: "WindowsUEFICA2023Capable" = 2
        [Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

    SkuSiPolicy.p7b is CURRENT.

Macrium Folders
---------------
    Windows Boot Manager [Production PCA 2011] is BANNED.

Bootable Media
--------------
    USB Drive F: "ATUFMAC0726"
        Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.


STATUS REPORT
-------------
    Registry: "UEFICA2023Status" = Updated

    SUCCESS: UPDATES ARE FINISHED.
    UEFI CA 2023 certs are present, PCA 2011 cert is revoked.

PS C:\Users\jwdav>

Then I run this:

mountvol s: /s
copy s:\EFI\Boot\bootx64.efi c:\boot\macrium\WinREFiles\media\EFI\Boot\bootx64.efi
copy S:\EFI\Microsoft\Boot\bootmgfw.efi c:\boot\macrium\WinREFiles\media\EFI\Microsoft\Boot\bootmgfw.efi

mountvol s: /d

Then Rufus to USB, been working all along, btw. bootable USB was done after july update
 

My Computer My Computer

At a glance

Win11 24H2 IOT LTSC / Win11 Pro 25H2AMD Ryzen 7 8700G / AMD Ryzen 7 8700GF5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB ...internal
OS
Win11 24H2 IOT LTSC / Win11 Pro 25H2
Computer type
PC/Desktop
Manufacturer/Model
Gigabyte / Asus Home build
CPU
AMD Ryzen 7 8700G / AMD Ryzen 7 8700G
Motherboard
Gigabyte B650 AORUS ELITE AX V2 / ASUS TUF GAMING B650-PLUS
Memory
F5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB LD5BU016G-R6000GDLA 32GB
Graphics Card(s)
internal
Sound Card
Realtek
Monitor(s) Displays
BenQ 27 L EW2780
Screen Resolution
1920x1080
Hard Drives
Many M.2's
Internet Speed
400 mbs
Browser
Vivaldi
Antivirus
Eset

Latest Support Threads

Back
Top Bottom