Solved garlin's PowerShell scripts for updating Secure Boot CA 2023


I have Windows 11 recovery and Marium Reflect 8.0 Free boot sticks for both of my PCs. Is there a way to check the Secure Boot certificates on them now that I have updated both of my PCs? I have not yet revoked the 2011 certs on either PC. What will happen to boot sticks when Microsoft finally does revoke them?
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo T490 (2020 Hardware)
    CPU
    i7-8565U
    Motherboard
    20N20028US
    Memory
    16GB
    Graphics Card(s)
    Intel UHD Graphics 620
    Sound Card
    Realtec Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 970 PRO 512GB NVMe
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Supported hardware, upgraded from Windows 10 Pro to Windows 11 Pro version 24H2 on 06/01/2025 using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/07/2025. Secure boot enabled.
  • Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Lenovo ThinkCentre M83 (2014 Hardware)
    CPU
    i7-4770 (with SSE4.2, and POPCNT)
    Motherboard
    10AL000GUS
    Memory
    16GB
    Graphics card(s)
    Intel HD Graphics 4600
    Sound Card
    Realtec High Definition Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 860 PRO 1TB SATA
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Unsupported hardware, upgraded from Windows 10 Pro (TPM 1.2 & unsupported CPU, but does have SSE4.2, and POPCNT) to Windows 11 Pro version 24H2 on 06/15/2025. Added Registry Key HKEY_LOCAL_MACHINE\SYSTEM\Setup\MoSetup – AllowUpgradesWithUnsupportedTPMOrCPU=1 to allow installation using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/08/2025. Secure boot enabled.
Hello @garlin!
When you have a moment, could you help me interpret these outputs?I still don't understand why it says Windows UEFI CA 2023 is banned and if I should be worried about it?
Anyway, I tried running UEFI-Ca 2023 ps1 -revoque as suggested, and the output I got is what you can see in the screenshot.
error.webpI'm unsure what to do next.
(I'm one of thesupposedly lucky users who has a cert KEK CA 2023 in the secure boot updates folder), and according to a script you provided, it reassured me because it said Microsoft would take care of updating it), I don't know if that's relevant to this issue...
2.webp

Thanks for patience ;-)
 

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    Dell XPS 13 9360
    CPU
    Intel(R) Core(TM) i7-7500U CPU @ 2.70GHz
    Memory
    8 GB
Ran the Reg Add command to fix SkuSiPolicy.p7b, after Check again, and looks like now i'm all set
How did you manage to get it to work? When I tried I got a not recognized error.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    PowerSpec B746
    CPU
    Intel Core i7-10700K
    Motherboard
    ASRock Z490 Phantom Gaming 4/ax
    Memory
    16GB (8GB PC4-19200 DDR4 SDRAM x2)
    Graphics Card(s)
    NVIDIA GeForce GTX 1050 TI
    Sound Card
    Realtek Audio
    Monitor(s) Displays
    #1. LG ULTRAWIDE 34" #2. AOC Q32G2WG3 32"
    Screen Resolution
    #1. 3440 X 1440 #2. 1920 x 1080
    Hard Drives
    NVMe WDC WDS100T2B0C-00PXH0 1TB
    Samsung SSD 860 EVO 1TB
    PSU
    750 Watts (62.5A)
    Case
    PowerSpec/Lian Li ATX 205
    Keyboard
    Logitech K270
    Mouse
    Logitech M185
    Browser
    Microsoft Edge and Firefox
    Antivirus
    Webroot SecureAnywhere CE 26.1
  • Operating System
    Windows 11 Canary Channel
    Computer type
    PC/Desktop
    Manufacturer/Model
    PowerSpec G156
    CPU
    Intel Core i5-8400 CPU @ 2.80GHz
    Motherboard
    AsusTeK Prime B360M-A
    Memory
    16 MB DDR 4-2666
    Monitor(s) Displays
    23" Speptre HDMI 75Hz
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 970 EVO 500GB NVMe
    Keyboard
    Logitek K270
    Mouse
    Logitek M185
    Browser
    Firefox, Edge and Edge Canary
    Antivirus
    Windows Defender
Is this something else to fix?
1-20-26.webp
 

My Computer

System One

  • OS
    windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Antec/Case
    CPU
    Intel i5-10600kf
    Motherboard
    GIGABYTE Z590 UD AC
    Memory
    32gb corsair vengerance pro
    Graphics Card(s)
    AMD RX 6500XT
    Sound Card
    onboard
    Monitor(s) Displays
    40" Hisense
    Hard Drives
    Samsung 850
    Samsung 870
    Seagate 2TB
    PSU
    EVGA GQ 750
How did you manage to get it to work? When I tried I got a not recognized error.
Well at the time it worked fine, but they might've changed to where it no longer works maybe is my guess, originally when i did it, i got no error at all, and all was smooth.

I don't have another Windows 11 PC or Gaming Laptop to test it on currently in the household
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 25H2 26200.8037
    Computer type
    PC/Desktop
    Manufacturer/Model
    PreBuilt
    CPU
    AMD Ryzen 7700X
    Motherboard
    MSI B650 VC WIfi Rev 1.0
    Memory
    32GB DDR 5 RGB 5600Mhz
    Graphics Card(s)
    Radeon 7800XT
    Sound Card
    Onboard Audio
    Monitor(s) Displays
    Asus VG245H
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 990 Evo Plus NVMe Boot
    Samsung 990 Pro 1TB Game NVMe



    External
    Western Digital Elements 500GB
    Western Digital My Passport 2TB Blue
    Western Digital My Passport 2TB Red
    Toshiba 2TB in External Enclosure
    Seagate 8TB in External Enclosure
    Seagate 1TB Portable USB 3 External Drive
    Western Digital My Book 8TB (Primary Backup drive)
    Western Digital Black 4TB In External Enclosure
    PSU
    750 Watt High Power
    Case
    Lian Li Lan Cool 216 ARGB Airflow
    Cooling
    2 160MM Front, 1 140MM Rear Exhaust
    Keyboard
    Logitech G513
    Mouse
    Logitech G502 X
    Internet Speed
    Gigabit 1100Mb/35 Upload
    Browser
    MS Edge Chromium and Bing Search
    Antivirus
    Windows Defender, Malwarebytes Premium
    Other Info
    UEFI, Secure Boot, TPM 2.0, Macrium Reflect X
  • Operating System
    Windows 11 Pro 25H2 26200.8037
    Computer type
    Laptop
    Manufacturer/Model
    Asus TUF A16 Advantage Edition FA617NT.A16.R7700
    CPU
    Ryzen 7 7735HS
    Motherboard
    OEM Asus Motherboard
    Memory
    16GB DDR 5
    Graphics card(s)
    AMD Radeon™ 680M & Radeon 7700S
    Sound Card
    Onboard
    Monitor(s) Displays
    16inch FHD 165hz
    Screen Resolution
    1920x1080
    Hard Drives
    512GB NVMe Boot Drive
    PSU
    Laptop PSU
    Case
    Laptop Case
    Cooling
    OEM Cooling
    Keyboard
    OEM Laptop Keyboard
    Mouse
    Touchpad & G502 Hero
    Internet Speed
    Gigabit 1100 Download/35 Upload
    Browser
    MS Edge with Bing search
    Antivirus
    Windows Defender & Malwarebytes Premium
    Other Info
    Macrium Reflect X
No, the default UEFI values represent the Factory Defaults hard-coded in the BIOS firmware. Only your vendor can rewrite the firmware so a Factory reset will copy the starting values back in.

The reason I wrote Check_UEFI-CA2023.ps1, is my disagreement about cjee21's script output.

While both scripts are technically accurate, the presentation of the Factory Defaults and the check marks leads to unnecessary confusion. If your vendor didn't provide a KEK CA 2023 in the factory default, that's their decision. I can't tell you if the vendor might fix it one day (we know they probably abandoned this model, but we can't be absolutely sure). Rather than guess the vendor's intention, I don't flag it.

Some vendors are still checking in KEK updates to MS!

The BootMgr SVN is the only SVN number you should care about. The other two are for actual CD/DVD's (are people still burning physical ISO's today?) and WDS (network boot from a MS deployment system). A single file DBXUpdateSVN.bin will update the SVN numbers as needed. There isn't a practical point to reporting CD or WDS SVN's.

If you want an output closer to cjee21's script, run Check_UEFI-CA2023.ps1 -Verbose

Verbose mode isn't the default, because most non-technical users don't need to review things like the factory defaults. The factory defaults are a "nice to know" detail, but doesn't help you do updates. It won't tell you if you can manually enroll the KEK CA 2023, or if you need to perform a Setup Mode upgrade.


Next question would be: How many EFI_CERT_SHA256 signatures should I have in verbose mode?
Answer: At least 437.

The current DBXUpdate.bin has 431 signatures, DBXUpdate2024.bin (which bans CA 2011) adds 3 SVN's, and DBXUpdateSVN.bin adds 3 more SVN's.
431 + 3 + 3 = 437

Your factory default DBX may have a random number of banned EFI signatures as a baseline. They may or may not overlap with DBXUpdate.bin.

There isn't a "correct number" for the factory DBX entries since it represents a snapshot of what was going on when that version of the BIOS firmware was being written. Some number of non-overlapping factory DBX entries could bump your EFI_CERT_SHA256 count above 437.

A SVN is really a special form of EFI_CERT_SHA256 signature. It pretends to have a normal hash value, but it hides the SVN revision number inside the "hash" digits so they didn't have to invent a new data type for the UEFI spec.
I also have a Red "x" under Default UEFI KEK (KEK 2K CA 2023) with cjee21's script. I thought it was unreliable, but it's actually a matter of interpretation of this script.

I hope that the fact that KEK 2K CA 2023 isn't the default certificate in the firmware won't hinder the transition to 2023 certificates.
 

My Computer

System One

  • OS
    windows 11
I dunno what's different about your Windows. But run this test script for me, it tries to walk down the folder path.
Thanks for the patience. Results:

$Paths = (C:\WINDOWS\System32\SecureBootUpdates)

Testing path to "C:\WINDOWS\System32\SecureBootUpdates"

Test-Path "C:" is valid.
Read 5195 directory items

Hidden folders:

Mode Name
---- ----
d--h-- GroupPolicy

Test-Path "C:\WINDOWS" is valid.
Read 124 directory items

Hidden folders:
d--h-- ELAMBKUP
d--hs- Installer
d--h-- LanguageOverlayCache

Test-Path "C:\WINDOWS\System32" is valid.
Read 5195 directory items

Hidden folders:
d--h-- GroupPolicy

Test-Path "C:\WINDOWS\System32\SecureBootUpdates" is valid.
Read 11 directory items

Hidden folders:

Relative path is .\C:\WINDOWS\System32\SecureBootUpdates


PS D:\UTILS95\UEFISecureBootVariables-garlin>
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Lenovo
I have Windows 11 recovery and Marium Reflect 8.0 Free boot sticks for both of my PCs. Is there a way to check the Secure Boot certificates on them now that I have updated both of my PCs? I have not yet revoked the 2011 certs on either PC. What will happen to boot sticks when Microsoft finally does revoke them?
Run Check_UEFI-CA2023.ps1 -BootMedia to check the eligibility of your USB boot drives.

If you want to update your USB drives, then run Update_UEFI-CA2023.ps1 -BootMedia
 

My Computer

System One

  • OS
    Windows 7
Hi @garlin -

Okay this is my System One, where am I please? Thank you.


Screenshot 2026-01-20 121724.webp
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 25H2 26200.8457
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Tower Plus EBT2250, DOB: 06/15/2025
    CPU
    Intel® Core™ Ultra 7 265 1.8GHz to 5.3GHz (Arrow Lake)
    Motherboard
    Dell Inc. 02D3NT A00 (U3E1)
    Memory
    SK Hynix 32GB DDR5 5600 Desktop RAM UDIMM Non-ECC PC5-5600B
    Graphics Card(s)
    Dell NVIDIA® GeForce RTX™ 4060 8GB GDDR6 & (iGPU) Integrated Intel® UHD Graphics
    Sound Card
    Chipset Realtek High-Definition Audio with Dolby Atmos
    Monitor(s) Displays
    Dell Ultra Sharp U2515H 25-Inch Screen LED-Lit
    Screen Resolution
    2560 X 1440
    Hard Drives
    Samsung (NVMe PM9C1a 1024GB) M.2 PCIe NVMe Solid State Drive (OS), with Samsung Piccolo (S4LY022) 6-Core 4 Channel Controller.

    Samsung T7 500GB SSD, USB-C External Drive
    PSU
    Dell 460W
    Case
    Dell Tower Plus EBT 2250
    Cooling
    Fan
    Keyboard
    Dell Wired Keyboard - KB216
    Mouse
    Logitech M510
    Internet Speed
    Intel Killer E3100G 2.5 Gigabit Ethernet Controller
    Browser
    Microsoft Edge
    Antivirus
    Microsoft Windows Security
    Other Info
    The Samsung NVMe PM9C1a 1024GB SSD does not use a Phison NAND controller. Instead, it uses Samsung's in-house developed Piccolo (S4LY022) 6-Core 4 Channel Controller. The PM9C1a utilizes a controller built using Samsung's 5-nanometer process and seventh-generation V-NAND technology. 🤔
  • Operating System
    Windows 11 Pro 25H2 26200.8457
    Computer type
    Laptop
    Manufacturer/Model
    Dell Inspiron 15 7000 (7591) 2-in-1, DOB: 11/30/2019
    CPU
    10th Generation Intel Core i7-10510U Processor (8MB Cache, up to 4.9 GHz) Comet Lake
    Motherboard
    Dell 0NNW5N
    Memory
    16GB DDR4 RAM
    Graphics card(s)
    NVIDIA® GeForce® MX250 with 2GB GDDR5 graphics memory
    Sound Card
    Chipset Realtek ALC3254 🤔🤣
    Monitor(s) Displays
    Dell 15.6-inch UHD Truelife Touch Narrow Border WVA Display with Active Pen support
    Screen Resolution
    3840 x 2160
    Hard Drives
    Intel NVME 512GB SSD with 32GB Intel Optane Memory, M.2 80mm PCIe 3.0 RAID

    SanDisk 256GB Extreme microSDXC UHS-I Memory Card
    PSU
    Dell 4-Cell Battery, 68 Whr (Integrated), 90 Watt AC Adapter
    Case
    Dell Inspiron 15 7000 2-in-1 (7591)
    Cooling
    Standard Dell Case Fan & Havit HV-F2056 USB Powered (3 Fans) Laptop Cooling Pad.
    Keyboard
    Dell
    Mouse
    Logitech Wireless Mouse M650L
    Internet Speed
    Wireless/Wired connectivity (WiFi 6 - 802.11 ax)
    Browser
    Microsoft Edge
    Antivirus
    Microsoft Windows Security
    Other Info
    From Dell: 512GB NVME Solid State Drive accelerated by 32GB Intel Optane Memory are the fastest as compared to NAND SSDs. Intel Optane H10 with SSD offers speedy storage and accelerates opening your programs.
Hello @garlin!
When you have a moment, could you help me interpret these outputs?I still don't understand why it says Windows UEFI CA 2023 is banned and if I should be worried about it?
Anyway, I tried running UEFI-Ca 2023 ps1 -revoque as suggested, and the output I got is what you can see in the screenshot.
This means your PC doesn't have a vendor-provided KEK CA 2023 update (which means MS cannot automatically do the update for you). It can only be updated by either:
- Manual update from the UEFI menu
- Clearing out the current UEFI certs using "Setup Mode"

The script has copied the KEK CA 2023 as a certificate file to the EFI partition, in case your PC supports a manual update. Since the script can't tell what your BIOS supports, you have to check your BIOS if a manual update is provided (usually called "key management").

If you don't see that option in BIOS (because it doesn't exist), then you'll have to try the "Setup Mode" in UEFI.

(I'm one of thesupposedly lucky users who has a cert KEK CA 2023 in the secure boo updates folder), and according to a script you provided, it reassured me because it said Microsoft would take care of updating it), I don't know if that's relevant to this issue...
Unfortunately if the vendor didn't provide MS an update, Windows cannot take of it. The UEFI security model is a partnership between your PC vendor and MS. The PC vendor's Platform Key verifies the MS KEK as valid. The MS KEK verifies the other certs as valid. If the vendor doesn't bless the MS KEK, then UEFI doesn't trust the KEK. This is the gaping hole in the Secure Boot update problem.

It requires the vendor to do their half of the work. Some vendors have decided to abandon older PC's. But if you have the option to invoke a "Setup Mode", then the UEFI can clear out the certs and allow itself to be reprogrammed. In this case, the update script can provide an entirely MS-based cert collection (including a custom Platform Key that MS provides just for this scenario), and install it.

Please check if you see any options for either key management (where it says you can install KEK keys), or Setup/Custom mode.
 

My Computer

System One

  • OS
    Windows 7
How did you manage to get it to work? When I tried I got a not recognized error.
It's believed the "reg add" for SkuSiPolicy (0x20), doesn't work for the scheduled task.

You'll need to copy it manually, or use the latest version of the update script:
Code:
Update_UEFI-CA2023.ps1 -SkuSiPolicy
 

My Computer

System One

  • OS
    Windows 7
Is this something else to fix?
In your case, the CA 2011 certs have not been revoked. So the last two update files are not applied yet.

Code:
Update_UEFI-CA2023.ps1 -Revoke
 

My Computer

System One

  • OS
    Windows 7
I checked 2 boot sticks that I have for my Lenovo T490 laptop - RECOVERY and MACRIUM. Here are the results. What can or should I do about the Macrium Reflect 8.0 Free boot stick? Should I just use Macrium to create a new boot stick or should this one still boot? It was created back in December and I can't honestly remember if I had completed the cert update or not. I guess I'll try to boot from it after I post this reply to see what happens.

EFI Files
---------
Disk 0: Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.

Registry: WindowsUEFICA2023Capable = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

Bootable Media
--------------
USB Drive D: "RECOVERY"

Boot File [Windows UEFI CA 2023] is ALLOWED.

STATUS REPORT
-------------
Registry: UEFICA2023Status = Updated

SUCCESS: NO UPDATES ARE REQUIRED.

PS C:\SecureBoot\SecureBoot-CA-2023-Updates_v2026-01-18>

**************************************************

EFI Files
---------
Disk 0: Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.

Registry: WindowsUEFICA2023Capable = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

Bootable Media
--------------
USB Drive D: "MACRIUMT490"

Boot File [Production PCA 2011] is BANNED.

STATUS REPORT
-------------
Registry: UEFICA2023Status = Updated

SUCCESS: NO UPDATES ARE REQUIRED.

PS C:\SecureBoot\SecureBoot-CA-2023-Updates_v2026-01-18>
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo T490 (2020 Hardware)
    CPU
    i7-8565U
    Motherboard
    20N20028US
    Memory
    16GB
    Graphics Card(s)
    Intel UHD Graphics 620
    Sound Card
    Realtec Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 970 PRO 512GB NVMe
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Supported hardware, upgraded from Windows 10 Pro to Windows 11 Pro version 24H2 on 06/01/2025 using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/07/2025. Secure boot enabled.
  • Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Lenovo ThinkCentre M83 (2014 Hardware)
    CPU
    i7-4770 (with SSE4.2, and POPCNT)
    Motherboard
    10AL000GUS
    Memory
    16GB
    Graphics card(s)
    Intel HD Graphics 4600
    Sound Card
    Realtec High Definition Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 860 PRO 1TB SATA
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Unsupported hardware, upgraded from Windows 10 Pro (TPM 1.2 & unsupported CPU, but does have SSE4.2, and POPCNT) to Windows 11 Pro version 24H2 on 06/15/2025. Added Registry Key HKEY_LOCAL_MACHINE\SYSTEM\Setup\MoSetup – AllowUpgradesWithUnsupportedTPMOrCPU=1 to allow installation using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/08/2025. Secure boot enabled.
I also have a Red "x" under Default UEFI KEK (KEK 2K CA 2023) with cjee21's script. I thought it was unreliable, but it's actually a matter of interpretation of this script.

I hope that the fact that KEK 2K CA 2023 isn't the default certificate in the firmware won't hinder the transition to 2023 certificates.
That is correct. You can ignore this case if the following conditions are true:

1. Vendor has already signed the KEK CA 2023 for MS, but not bothered to release a new firmware. MS will have a copy of the signed KEK to push out.​
2. Your BIOS supports manually enrollment of KEK keys. So if you provide the KEK CA 2023 in .der file format, it can be enrolled by the UEFI using the menu options. The update script will attempt to copy the file to EFI, just in case this option is available.​
3. Your BIOS supports Setup Mode, where you decide it's better to replace the vendor PK with the generic "Windows OEM Devices PK" which allows KEK CA 2023 to be installed, since MS signed its own KEK. This is the nuclear option if you have an abandoned BIOS. Mosby does the same actions, but it creates a custom PK for you.​
The update script will do the same work, but without requiring a separate USB drive and do it entirely from Windows.​
 

My Computer

System One

  • OS
    Windows 7
Relative path is .\C:\WINDOWS\System32\SecureBootUpdates
This is "wrong".
I checked 2 boot sticks that I have for my Lenovo T490 laptop - RECOVERY and MACRIUM. Here are the results. What can or should I do about the Macrium Reflect 8.0 Free boot stick? Should I just use Macrium to create a new boot stick or should this one still boot? It was created back in December and I can't honestly remember if I had completed the cert update or not. I guess I'll try to boot from it after I post this reply to see what happens.

Bootable Media
--------------
USB Drive D: "RECOVERY"

Boot File [Windows UEFI CA 2023] is ALLOWED.
This one is good.

Bootable Media
--------------
USB Drive D: "MACRIUMT490"

Boot File [Production PCA 2011] is BANNED.
This one needs to be updated. Leave it plugged, and run Update_UEFI-CA2023.ps1 -BootMedia
 

My Computer

System One

  • OS
    Windows 7

My Computers

System One System Two

  • OS
    Windows 11 Pro 25H2 26200.8457
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Tower Plus EBT2250, DOB: 06/15/2025
    CPU
    Intel® Core™ Ultra 7 265 1.8GHz to 5.3GHz (Arrow Lake)
    Motherboard
    Dell Inc. 02D3NT A00 (U3E1)
    Memory
    SK Hynix 32GB DDR5 5600 Desktop RAM UDIMM Non-ECC PC5-5600B
    Graphics Card(s)
    Dell NVIDIA® GeForce RTX™ 4060 8GB GDDR6 & (iGPU) Integrated Intel® UHD Graphics
    Sound Card
    Chipset Realtek High-Definition Audio with Dolby Atmos
    Monitor(s) Displays
    Dell Ultra Sharp U2515H 25-Inch Screen LED-Lit
    Screen Resolution
    2560 X 1440
    Hard Drives
    Samsung (NVMe PM9C1a 1024GB) M.2 PCIe NVMe Solid State Drive (OS), with Samsung Piccolo (S4LY022) 6-Core 4 Channel Controller.

    Samsung T7 500GB SSD, USB-C External Drive
    PSU
    Dell 460W
    Case
    Dell Tower Plus EBT 2250
    Cooling
    Fan
    Keyboard
    Dell Wired Keyboard - KB216
    Mouse
    Logitech M510
    Internet Speed
    Intel Killer E3100G 2.5 Gigabit Ethernet Controller
    Browser
    Microsoft Edge
    Antivirus
    Microsoft Windows Security
    Other Info
    The Samsung NVMe PM9C1a 1024GB SSD does not use a Phison NAND controller. Instead, it uses Samsung's in-house developed Piccolo (S4LY022) 6-Core 4 Channel Controller. The PM9C1a utilizes a controller built using Samsung's 5-nanometer process and seventh-generation V-NAND technology. 🤔
  • Operating System
    Windows 11 Pro 25H2 26200.8457
    Computer type
    Laptop
    Manufacturer/Model
    Dell Inspiron 15 7000 (7591) 2-in-1, DOB: 11/30/2019
    CPU
    10th Generation Intel Core i7-10510U Processor (8MB Cache, up to 4.9 GHz) Comet Lake
    Motherboard
    Dell 0NNW5N
    Memory
    16GB DDR4 RAM
    Graphics card(s)
    NVIDIA® GeForce® MX250 with 2GB GDDR5 graphics memory
    Sound Card
    Chipset Realtek ALC3254 🤔🤣
    Monitor(s) Displays
    Dell 15.6-inch UHD Truelife Touch Narrow Border WVA Display with Active Pen support
    Screen Resolution
    3840 x 2160
    Hard Drives
    Intel NVME 512GB SSD with 32GB Intel Optane Memory, M.2 80mm PCIe 3.0 RAID

    SanDisk 256GB Extreme microSDXC UHS-I Memory Card
    PSU
    Dell 4-Cell Battery, 68 Whr (Integrated), 90 Watt AC Adapter
    Case
    Dell Inspiron 15 7000 2-in-1 (7591)
    Cooling
    Standard Dell Case Fan & Havit HV-F2056 USB Powered (3 Fans) Laptop Cooling Pad.
    Keyboard
    Dell
    Mouse
    Logitech Wireless Mouse M650L
    Internet Speed
    Wireless/Wired connectivity (WiFi 6 - 802.11 ax)
    Browser
    Microsoft Edge
    Antivirus
    Microsoft Windows Security
    Other Info
    From Dell: 512GB NVME Solid State Drive accelerated by 32GB Intel Optane Memory are the fastest as compared to NAND SSDs. Intel Optane H10 with SSD offers speedy storage and accelerates opening your programs.
This one needs to be updated. Leave it plugged, and run Update_UEFI-CA2023.ps1 -BootMedia
Got it. Will do. (y) We sure are keeping you busy. ;-)
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo T490 (2020 Hardware)
    CPU
    i7-8565U
    Motherboard
    20N20028US
    Memory
    16GB
    Graphics Card(s)
    Intel UHD Graphics 620
    Sound Card
    Realtec Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 970 PRO 512GB NVMe
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Supported hardware, upgraded from Windows 10 Pro to Windows 11 Pro version 24H2 on 06/01/2025 using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/07/2025. Secure boot enabled.
  • Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Lenovo ThinkCentre M83 (2014 Hardware)
    CPU
    i7-4770 (with SSE4.2, and POPCNT)
    Motherboard
    10AL000GUS
    Memory
    16GB
    Graphics card(s)
    Intel HD Graphics 4600
    Sound Card
    Realtec High Definition Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 860 PRO 1TB SATA
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Unsupported hardware, upgraded from Windows 10 Pro (TPM 1.2 & unsupported CPU, but does have SSE4.2, and POPCNT) to Windows 11 Pro version 24H2 on 06/15/2025. Added Registry Key HKEY_LOCAL_MACHINE\SYSTEM\Setup\MoSetup – AllowUpgradesWithUnsupportedTPMOrCPU=1 to allow installation using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/08/2025. Secure boot enabled.
Run Check_UEFI-CA2023.ps1 -BootMedia to check the eligibility of your USB boot drives.

If you want to update your USB drives, then run Update_UEFI-CA2023.ps1 -BootMedia

Thanks for the suport.
Results per your instructions...
==========================================================
1st RUN:

D:\UTILS95\BR>D:\UTILS95\UEFISecureBootVariables-garlin\Check-UEFI.cmd -BootMedia
Checking for Elevation...
OK

Running powershell-{C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe}
Major Minor Build Revision
----- ----- ----- --------
5 1 26100 7462

Secure Boot: ON
Virtualization Based Security: ON
BitLocker on (C:) OFF

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

UEFI DBX Certs
--------------
(NONE)

EFI Files
---------
Disk 0: Windows Boot Manager [Windows UEFI CA 2023] is BANNED.

Registry: WindowsUEFICA2023Capable = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

Disk 0: SkuSiPolicy.p7b (for VBS) is CURRENT.

Bootable Media
--------------
USB Drive F: "SD128gb31"
Boot File [Windows UEFI CA 2023] is BANNED.
USB Drive H: "RESCUEM93P2"
Boot File [Windows UEFI CA 2023] is BANNED.
DVD Drive Z:


REQUIRED ACTION
===============

Run the command:
Update_UEFI-CA2023.ps1 -Revoke

Finish the UEFI steps to manually add the [KEK CA 2023] cert, if the script provided instructions.

=========================================================================
2nd Run:

D:\UTILS95\BR>D:\UTILS95\UEFISecureBootVariables-garlin\Update-UEFI.cmd -BootMedia
Checking for Elevation...
OK

Running powershell-{C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe}

Major Minor Build Revision
----- ----- ----- --------
5 1 26100 7462

REQUIRED ACTION
---------------
Please follow the README_UEFI.TXT instructions, for installing the [KEK CA 2023] cert from BIOS.

Restart Windows, for UEFI updates to take effect.

Done.

 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Lenovo

Latest Support Threads

Back
Top Bottom