Solved garlin's PowerShell scripts for updating Secure Boot CA 2023


I've had a paid copy since it's been available. I will also request them to add the 2023 certs to their build process.
I have a 4-pack sub for 1/2 off for life. While I know the workarounds to make the rescue media and the rescue media cache compliant with the Windows UEFI CA 2023 certs, Macrium, at the very least, should give us the option to build winre boot media with the CA 2023 certs. Many users out there are afraid, or don't have the technical know-how to keep manually updating rescue media with the CA 2023 certs

This needs to be done before the expiration of the Windows PCA 2011 cert in October at the latest. Their actions will determine if I renew my 4-pack subscription or not.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2AMD Ryzen 9 7940HS32 GBRadeon 780M Graphics
    OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Geekom AX7 Pro
    CPU
    AMD Ryzen 9 7940HS
    Memory
    32 GB
    Graphics Card(s)
    Radeon 780M Graphics
    Monitor(s) Displays
    Dell S2425H 24"
    Screen Resolution
    1920 x 1080
    Hard Drives
    2 TB NVMe SSD
    Internet Speed
    100 Mbs
    Browser
    Microsoft Edge / Firefox
    Antivirus
    F-Secure Security Suite
    Other Info
    All secure boot certificates updated to CA 2023
    Windows Production PCA 2011 certificate has been revoked.
  • At a glance

    Windows 11 Pro 25H212th Gen Intel Core i7-12700 processor (12-Co...16 GBIntel(R) UHD Graphics 770 with shared graphic...
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Inspiron 3910
    CPU
    12th Gen Intel Core i7-12700 processor (12-Core, 25M Cache, 2.1GHz to 4.8GHz)
    Motherboard
    Dell 0KHP4K
    Memory
    16 GB
    Graphics card(s)
    Intel(R) UHD Graphics 770 with shared graphics memory
    Monitor(s) Displays
    Dell 27" Monitor S2721DS,
    Screen Resolution
    QHD 2560 x 1440 @ 75 Hz
    Hard Drives
    1TB M.2, PCIe NVMe, SSD
    Internet Speed
    100 Mbps
    Browser
    Edge
    Antivirus
    F-Secure Security Suite
    Other Info
    All secure boot certificates updated to CA 2023
    Windows Production PCA 2011 certificate has been revoked.
  • HP Laptop 15-fd0xxx
    OS: Windows 11 Home 25H2
    Processor: 13th Gen Intel(R) Core(TM) i7-1355U (1.70 GHz), 10 Cores, 12 Logical Processors
    BIOS Version: AMI F.26 4/22/2026
    RAM: 16 GB
    SSD: 1 TB
    Screen Resolution: 1920 x 1080
    All secure boot certificates updated to CA 2023 by factory.
********************************************************************************
Scott said:

A third option is to switch to integrated graphics, which your CPU supports.

************************************************
thank you, anchamp65 and Scott
yes, it seems you are right; i will try that when possible and report the result,
fernando


I doubt you have an input HDMI port on your motherboard, that's an output from the embedded motherboard GPU.
**************
hello, gunrunnerjohn
indeed, i think you´re right; i will try that HDMI port-------- thank you,
fernando

i removed the NVIDIA PCIe graphics card and now i´m using the integrated Intel HD530 graphics (as you rightfully told me to do as a possibility) with new drivers installed by the system itself..
so now, i, hopefully, will able to keep using an "officially Unsupported PC" with the 2023 Secure Boot certificates (thanks again to garlin)
best regards,
fernando
 

My Computer My Computer

At a glance

windows 10 Enterprise IoT LTSCIntel(R) Core(TM) i5-6400 CPU @ 2.70GHz16GBIntel HD Graphics 530 (integrated on Motherbo...
OS
windows 10 Enterprise IoT LTSC
Computer type
PC/Desktop
Manufacturer/Model
ASUS/ K31CD
CPU
Intel(R) Core(TM) i5-6400 CPU @ 2.70GHz
Memory
16GB
Graphics Card(s)
Intel HD Graphics 530 (integrated on Motherboard)
Other Info
BIOS: American Megatrends Inc.
v. 1102 (12-2018)
So it looks like for now they have no plans to address this and if we want to get it added have to suggest in the productboard
Hasleo has already added this functionality to WinRE and WinPE rescue media.
That's funny, because it's what I suggested them to do 3 months ago
And it was based on recommendations from Garlin

1786123720731.webp
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
i removed the NVIDIA PCIe graphics card and now i´m using the integrated Intel HD530 graphics (as you rightfully told me to do as a possibility) with new drivers installed by the system itself..
so now, i, hopefully, will able to keep using an "officially Unsupported PC" with the 2023 Secure Boot certificates (thanks again to garlin)
best regards,
fernando
Good for you !
So you will decide when to retire that computer, and not MS or Nvidia ;-)
 
Last edited:

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Re: post #3,121 (above). Thanks for the fast fix...

Macrium 8.0
-----------
WinRE Boot Manager [Production PCA 2011] is BANNED.
c:\boot\macrium\WinREFiles\media\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.352, SVN 9.0

Bootable Media
--------------

USB Drive F: "RESCUE"
Windows Boot Manager [Production PCA 2011] is BANNED.
F:\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.352, SVN 9.0

F:\EFI\Microsoft\Boot\boot.stl [Mon 05/18/2026 11:44 AM] is CURRENT.

boot.wim:1 (WinRE 26100.1)
Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\Windows\Boot\EFI_EX\bootmgfw_EX.efi
File Version: 28000.352, SVN 9.0

\Windows\System32\winload.efi is ALLOWED.
File Version: 26100.8875

--------------
Will I have to repeat this process with every subsequent MS monthly CUM update?

Thanks.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
Lenovo
Will I have to repeat this process with every subsequent MS monthly CUM update?
It depends on whether the Window boot manager or winload.efi are replaced in the Monthly Update.

There is no pre-determined schedule, since security fixes are unplanned. Sometimes you can get a few months of quiet, and nothing changes in respect to Secure Boot updates or boot media changes.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
I think I've worked out the recent string of problems.

1. Everyone reports (or least I believe that) PANTS.ps1 works perfectly. The latest Check_BootMedia.ps1 uses the exact same method, but it merges the drive list with the old method for finding mounted CDROM "devices".

I found an online post where someone mentioned Get-Volume can return a "null" value for the DriveLetter. Except it's not as $null, but the character representation of "null" or "`0". A true null (or $null) is not a value, it's the absence of any value. But DriveLetter represents a real value, so the "`0" value is passed along.

So the normal check for not having an assigned drive letter can break in certain circumstances...

2. From re-reading the MS instructions on boot.stl, I think they mean "boot.stl is required when doing a Windows install", and not for when boot.wim is being used purely as a hosting platform. It only makes sense to check for the presence or same version of boot.stl only when an install WIM/ESD is found on the drive.

Macrium or Hasleo boot drives wouldn't need it then, and copying boot.stl to them should have no negative effects. I'm changing boot.stl check to only run on drives with install images.

3. The same thing applies to "Update_UEFI-CA2023.ps1 -BootMedia". No copying boot.stl unless there's an install WIM present.
 

Attachments

Last edited:

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
BINGO !

Code:
       ID_FILEATTRIB_F_0045 10.0.29426.0       65535.65535.65535.65535



Bootable Media
--------------

USB Drive F: "MACLAPC2023"
    Windows Boot Manager [Windows UEFI CA 2023] is BANNED.
        F:\EFI\Microsoft\Boot\bootmgfw.efi
        File Version: 28000.322, SVN 8.0

    boot.wim:1 (WinRE 26100.1)
        Boot Manager [Windows UEFI CA 2023] is BANNED.
            \Windows\Boot\EFI_EX\bootmgfw_EX.efi
            File Version: 28000.322, SVN 8.0

        \Windows\System32\winload.efi is BANNED.
            File Version: 26100.8235


PS C:\Users\jwdav>
 

My Computer My Computer

At a glance

Win11 24H2 IOT LTSC / Win11 Pro 25H2AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600GF5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB ...internal
OS
Win11 24H2 IOT LTSC / Win11 Pro 25H2
Computer type
PC/Desktop
Manufacturer/Model
Gigabyte x2 / Asus = Home builds
CPU
AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600G
Motherboard
Gigabyte B650 AORUS ELITE AX V2 / ASUS TUF GAMING B650-PLUS / B650 GAMING X AX V2
Memory
F5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB LD5BU016G-R6000GDLA 32GB / Kingston FURY Beast 32 GB DDR5-5600
Graphics Card(s)
internal
Sound Card
Realtek
Monitor(s) Displays
BenQ 27 L EW2780
Screen Resolution
1920x1080
Hard Drives
Many M.2's (WD)
PSU
be quiet! Pure Power 13 M 550W
Case
Chieftec HC-10B-OP
Cooling
Gelid Solutions Tranquillo 5, many Noctua's 12x12
Keyboard
Microsoft
Mouse
Cherry
Internet Speed
500 mbs
Browser
Vivaldi
Antivirus
Eset
Other Info
PC builder / repair / Trouble-shooter etc.
I forgot to put a flash-drive in:
Code:
Bootable Media
--------------
Check-DriveVolume : Cannot bind argument to parameter 'DriveLetter' because it is an empty string.
At E:\Z_c2023\Check_BootMedia.ps1:2347 char:48
+                 Check-DriveVolume -DriveLetter $Drive
+                                                ~~~~~~
    + CategoryInfo          : InvalidData: (:) [Check-DriveVolume], ParameterBindingValidationException
    + FullyQualifiedErrorId : ParameterArgumentValidationErrorEmptyStringNotAllowed,Check-DriveVolume

But after my "blond" moment it was ok;
Code:
Bootable Media
--------------

USB Drive F: "ATUFMAC0726"
    Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
        F:\EFI\Microsoft\Boot\bootmgfw.efi
        File Version: 28000.352, SVN 9.0

    boot.wim:1 (WinRE 26100.1)
        Boot Manager [Windows UEFI CA 2023] is ALLOWED.
            \Windows\Boot\EFI_EX\bootmgfw_EX.efi
            File Version: 28000.352, SVN 9.0

        \Windows\System32\winload.efi is ALLOWED.
            File Version: 26100.8875
 

My Computer My Computer

At a glance

Win11 24H2 IOT LTSC / Win11 Pro 25H2AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600GF5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB ...internal
OS
Win11 24H2 IOT LTSC / Win11 Pro 25H2
Computer type
PC/Desktop
Manufacturer/Model
Gigabyte x2 / Asus = Home builds
CPU
AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600G
Motherboard
Gigabyte B650 AORUS ELITE AX V2 / ASUS TUF GAMING B650-PLUS / B650 GAMING X AX V2
Memory
F5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB LD5BU016G-R6000GDLA 32GB / Kingston FURY Beast 32 GB DDR5-5600
Graphics Card(s)
internal
Sound Card
Realtek
Monitor(s) Displays
BenQ 27 L EW2780
Screen Resolution
1920x1080
Hard Drives
Many M.2's (WD)
PSU
be quiet! Pure Power 13 M 550W
Case
Chieftec HC-10B-OP
Cooling
Gelid Solutions Tranquillo 5, many Noctua's 12x12
Keyboard
Microsoft
Mouse
Cherry
Internet Speed
500 mbs
Browser
Vivaldi
Antivirus
Eset
Other Info
PC builder / repair / Trouble-shooter etc.
I think I've worked out the recent string of problems.
Still works for me !
And I understand what you explained about the boot.stl
Thanks for looking into it and explaining the reasoning behind it.

So I changed my (y) to a 1786141407810.webp

Thanks again Garlin !!!
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Seems to work for me, but I was using it to check an install usb made with rufus. This is what the script reported on the Rufus_Boot partition:

USB Drive E: "RUFUS_BOOT"
Boot File [Microsoft Corporation UEFI CA 2011] is BANNED.
E:\EFI\Boot\bootx64.efi
[THIRD-PARTY] EFI File

In the past scripts, it would show that partition as allowed. The Microsoft Corporation UEFI CA 2011 cert is not revoked on this system, but the Windows Production PCA 2011 cert has been revoked.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2AMD Ryzen 9 7940HS32 GBRadeon 780M Graphics
    OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Geekom AX7 Pro
    CPU
    AMD Ryzen 9 7940HS
    Memory
    32 GB
    Graphics Card(s)
    Radeon 780M Graphics
    Monitor(s) Displays
    Dell S2425H 24"
    Screen Resolution
    1920 x 1080
    Hard Drives
    2 TB NVMe SSD
    Internet Speed
    100 Mbs
    Browser
    Microsoft Edge / Firefox
    Antivirus
    F-Secure Security Suite
    Other Info
    All secure boot certificates updated to CA 2023
    Windows Production PCA 2011 certificate has been revoked.
  • At a glance

    Windows 11 Pro 25H212th Gen Intel Core i7-12700 processor (12-Co...16 GBIntel(R) UHD Graphics 770 with shared graphic...
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Inspiron 3910
    CPU
    12th Gen Intel Core i7-12700 processor (12-Core, 25M Cache, 2.1GHz to 4.8GHz)
    Motherboard
    Dell 0KHP4K
    Memory
    16 GB
    Graphics card(s)
    Intel(R) UHD Graphics 770 with shared graphics memory
    Monitor(s) Displays
    Dell 27" Monitor S2721DS,
    Screen Resolution
    QHD 2560 x 1440 @ 75 Hz
    Hard Drives
    1TB M.2, PCIe NVMe, SSD
    Internet Speed
    100 Mbps
    Browser
    Edge
    Antivirus
    F-Secure Security Suite
    Other Info
    All secure boot certificates updated to CA 2023
    Windows Production PCA 2011 certificate has been revoked.
  • HP Laptop 15-fd0xxx
    OS: Windows 11 Home 25H2
    Processor: 13th Gen Intel(R) Core(TM) i7-1355U (1.70 GHz), 10 Cores, 12 Logical Processors
    BIOS Version: AMI F.26 4/22/2026
    RAM: 16 GB
    SSD: 1 TB
    Screen Resolution: 1920 x 1080
    All secure boot certificates updated to CA 2023 by factory.
Build anther PC beginning of the month and made an install USB with MCT. It didnt boot up as I have seen before so I just dropped secure boot before install and finalizing, Turned Secere boot back on then used your script to update the PC to c2023 and revoke etc.
But was curious what your latest Check_BootMedia.ps1 would show me ....
Code:
Bootable Media
--------------

DVD Drive F: "ESD-USB"
    Boot File [Production PCA 2011] is BANNED.
        F:\EFI\Boot\bootx64.efi
        File Version: 28000.352, SVN 9.0

    boot.wim:2 (WinPE 26100.8875)
        Boot Manager [Windows UEFI CA 2023] is ALLOWED.
            \Windows\Boot\EFI_EX\bootmgfw_EX.efi
            File Version: 28000.352, SVN 9.0

        \Windows\System32\winload.efi is ALLOWED.
            File Version: 26100.8875

    Please wait while install SWM is analyzed.

ERROR: wimlib unable to open F:\sources\install.swm

        Skipping over the next 5 images.

Not woried about it as I am getting used to the Microsoft crap that dont make sence, but fixes / workarounds keep our brains stimulated :cool:
 

My Computer My Computer

At a glance

Win11 24H2 IOT LTSC / Win11 Pro 25H2AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600GF5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB ...internal
OS
Win11 24H2 IOT LTSC / Win11 Pro 25H2
Computer type
PC/Desktop
Manufacturer/Model
Gigabyte x2 / Asus = Home builds
CPU
AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600G
Motherboard
Gigabyte B650 AORUS ELITE AX V2 / ASUS TUF GAMING B650-PLUS / B650 GAMING X AX V2
Memory
F5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB LD5BU016G-R6000GDLA 32GB / Kingston FURY Beast 32 GB DDR5-5600
Graphics Card(s)
internal
Sound Card
Realtek
Monitor(s) Displays
BenQ 27 L EW2780
Screen Resolution
1920x1080
Hard Drives
Many M.2's (WD)
PSU
be quiet! Pure Power 13 M 550W
Case
Chieftec HC-10B-OP
Cooling
Gelid Solutions Tranquillo 5, many Noctua's 12x12
Keyboard
Microsoft
Mouse
Cherry
Internet Speed
500 mbs
Browser
Vivaldi
Antivirus
Eset
Other Info
PC builder / repair / Trouble-shooter etc.
Seems to work for me, but I was using it to check an install usb made with rufus. This is what the script reported on the Rufus_Boot partition:

USB Drive E: "RUFUS_BOOT"
Boot File [Microsoft Corporation UEFI CA 2011] is BANNED.
E:\EFI\Boot\bootx64.efi
[THIRD-PARTY] EFI File

In the past scripts, it would show that partition as allowed. The Microsoft Corporation UEFI CA 2011 cert is not revoked on this system, but the Windows Production PCA 2011 cert has been revoked.

What's the output of:
Code:
(Get-Item E:\EFI\boot\bootx64.efi).VersionInfo.FileVersionRaw
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Please wait while install SWM is analyzed.

ERROR: wimlib unable to open F:\sources\install.swm

Skipping over the next 5 images.[/CODE]

Not woried about it as I am getting used to the Microsoft crap that dont make sence, but fixes / workarounds keep our brains stimulated :cool:

Please run:
Code:
Check_BootMedia.ps1 F:\sources\install.swm
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
What's the output of:
Code:
(Get-Item E:\EFI\boot\bootx64.efi).VersionInfo.FileVersionRaw
(Get-Item E:\EFI\boot\bootx64.efi).VersionInfo.FileVersionRaw

Major Minor Build Revision
----- ----- ----- --------
0 0 0 0

That's what it shows. The usb boots fine on the Rufus_Boot partition. I do realize that the expired cert still works as long as it hasn't been revoked. If Rufus were to make a new NTFS helper driver, the new cert would need to be signed with the MS UEFI CA 2023 cert.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2AMD Ryzen 9 7940HS32 GBRadeon 780M Graphics
    OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Geekom AX7 Pro
    CPU
    AMD Ryzen 9 7940HS
    Memory
    32 GB
    Graphics Card(s)
    Radeon 780M Graphics
    Monitor(s) Displays
    Dell S2425H 24"
    Screen Resolution
    1920 x 1080
    Hard Drives
    2 TB NVMe SSD
    Internet Speed
    100 Mbs
    Browser
    Microsoft Edge / Firefox
    Antivirus
    F-Secure Security Suite
    Other Info
    All secure boot certificates updated to CA 2023
    Windows Production PCA 2011 certificate has been revoked.
  • At a glance

    Windows 11 Pro 25H212th Gen Intel Core i7-12700 processor (12-Co...16 GBIntel(R) UHD Graphics 770 with shared graphic...
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Inspiron 3910
    CPU
    12th Gen Intel Core i7-12700 processor (12-Core, 25M Cache, 2.1GHz to 4.8GHz)
    Motherboard
    Dell 0KHP4K
    Memory
    16 GB
    Graphics card(s)
    Intel(R) UHD Graphics 770 with shared graphics memory
    Monitor(s) Displays
    Dell 27" Monitor S2721DS,
    Screen Resolution
    QHD 2560 x 1440 @ 75 Hz
    Hard Drives
    1TB M.2, PCIe NVMe, SSD
    Internet Speed
    100 Mbps
    Browser
    Edge
    Antivirus
    F-Secure Security Suite
    Other Info
    All secure boot certificates updated to CA 2023
    Windows Production PCA 2011 certificate has been revoked.
  • HP Laptop 15-fd0xxx
    OS: Windows 11 Home 25H2
    Processor: 13th Gen Intel(R) Core(TM) i7-1355U (1.70 GHz), 10 Cores, 12 Logical Processors
    BIOS Version: AMI F.26 4/22/2026
    RAM: 16 GB
    SSD: 1 TB
    Screen Resolution: 1920 x 1080
    All secure boot certificates updated to CA 2023 by factory.
Code:
powershell -nop -ep bypass -f E:\Z_c2023\Check_BootMedia.ps1 F:\sources\install.swm

Image Files
-----------
    Please wait while install SWM is analyzed.

ERROR: wimlib unable to open F:\sources\install.swm
 

My Computer My Computer

At a glance

Win11 24H2 IOT LTSC / Win11 Pro 25H2AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600GF5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB ...internal
OS
Win11 24H2 IOT LTSC / Win11 Pro 25H2
Computer type
PC/Desktop
Manufacturer/Model
Gigabyte x2 / Asus = Home builds
CPU
AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600G
Motherboard
Gigabyte B650 AORUS ELITE AX V2 / ASUS TUF GAMING B650-PLUS / B650 GAMING X AX V2
Memory
F5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB LD5BU016G-R6000GDLA 32GB / Kingston FURY Beast 32 GB DDR5-5600
Graphics Card(s)
internal
Sound Card
Realtek
Monitor(s) Displays
BenQ 27 L EW2780
Screen Resolution
1920x1080
Hard Drives
Many M.2's (WD)
PSU
be quiet! Pure Power 13 M 550W
Case
Chieftec HC-10B-OP
Cooling
Gelid Solutions Tranquillo 5, many Noctua's 12x12
Keyboard
Microsoft
Mouse
Cherry
Internet Speed
500 mbs
Browser
Vivaldi
Antivirus
Eset
Other Info
PC builder / repair / Trouble-shooter etc.
swim.webp
 

My Computer My Computer

At a glance

Win11 24H2 IOT LTSC / Win11 Pro 25H2AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600GF5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB ...internal
OS
Win11 24H2 IOT LTSC / Win11 Pro 25H2
Computer type
PC/Desktop
Manufacturer/Model
Gigabyte x2 / Asus = Home builds
CPU
AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600G
Motherboard
Gigabyte B650 AORUS ELITE AX V2 / ASUS TUF GAMING B650-PLUS / B650 GAMING X AX V2
Memory
F5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB LD5BU016G-R6000GDLA 32GB / Kingston FURY Beast 32 GB DDR5-5600
Graphics Card(s)
internal
Sound Card
Realtek
Monitor(s) Displays
BenQ 27 L EW2780
Screen Resolution
1920x1080
Hard Drives
Many M.2's (WD)
PSU
be quiet! Pure Power 13 M 550W
Case
Chieftec HC-10B-OP
Cooling
Gelid Solutions Tranquillo 5, many Noctua's 12x12
Keyboard
Microsoft
Mouse
Cherry
Internet Speed
500 mbs
Browser
Vivaldi
Antivirus
Eset
Other Info
PC builder / repair / Trouble-shooter etc.
(Get-Item E:\EFI\boot\bootx64.efi).VersionInfo.FileVersionRaw

Major Minor Build Revision
----- ----- ----- --------
0 0 0 0

That's what it shows. The usb boots fine on the Rufus_Boot partition. I do realize that the expired cert still works as long as it hasn't been revoked. If Rufus were to make a new NTFS helper driver, the new cert would need to be signed with the MS UEFI CA 2023 cert.
What Rufus options did you use to build this drive? I believe you have a non-MS boot file (so it has no Windows-specific version data inside).

Can you make a ZIP file of E:\EFI\boot\bootx64.efi and attach it? I need an example to make sure the code gets fixed correctly.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
This is what is get with above script
Code:
PS C:\Users\jwdav> (Get-Item F:\EFI\boot\bootx64.efi).VersionInfo.FileVersionRaw

Major  Minor  Build  Revision
-----  -----  -----  --------
10     0      28000  352
 

My Computer My Computer

At a glance

Win11 24H2 IOT LTSC / Win11 Pro 25H2AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600GF5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB ...internal
OS
Win11 24H2 IOT LTSC / Win11 Pro 25H2
Computer type
PC/Desktop
Manufacturer/Model
Gigabyte x2 / Asus = Home builds
CPU
AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600G
Motherboard
Gigabyte B650 AORUS ELITE AX V2 / ASUS TUF GAMING B650-PLUS / B650 GAMING X AX V2
Memory
F5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB LD5BU016G-R6000GDLA 32GB / Kingston FURY Beast 32 GB DDR5-5600
Graphics Card(s)
internal
Sound Card
Realtek
Monitor(s) Displays
BenQ 27 L EW2780
Screen Resolution
1920x1080
Hard Drives
Many M.2's (WD)
PSU
be quiet! Pure Power 13 M 550W
Case
Chieftec HC-10B-OP
Cooling
Gelid Solutions Tranquillo 5, many Noctua's 12x12
Keyboard
Microsoft
Mouse
Cherry
Internet Speed
500 mbs
Browser
Vivaldi
Antivirus
Eset
Other Info
PC builder / repair / Trouble-shooter etc.
Code:
powershell -nop -ep bypass -f E:\Z_c2023\Check_BootMedia.ps1 F:\sources\install.swm

Image Files
-----------
    Please wait while install SWM is analyzed.

ERROR: wimlib unable to open F:\sources\install.swm
Oops, embarrassing copy/paste. Dropped the code into the wrong part of if-then-else.
 

Attachments

My Computer My Computer

At a glance

Windows 7
OS
Windows 7

Latest Support Threads

Back
Top Bottom