Solved garlin's PowerShell scripts for updating Secure Boot CA 2023


OK, still learning: how do I update the BANNED file in the G: Hasleo drive

PS C:\Windows\System32> powershell -nop -ep bypass -f C:\temp17\check_bootmedia.ps1 -verbose
Windows 11 25H2 (26200.9168)

Secure Boot: ON
Virtualization Based Security: ON

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 9.0

EFI Files
---------
SkuSiPolicy.p7b is CURRENT.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b
Version: 3.0.0.17

FileRule MinimumFileVersion MaximumFileVersion
-------- ------------------ ------------------
ID_FILEATTRIB_F_0044 0.0.0.0 10.0.14393.9399
ID_FILEATTRIB_F_0042 10.0.14400.0 10.0.17763.9099
ID_FILEATTRIB_F_0040 10.0.18000.0 10.0.19041.7639
ID_FILEATTRIB_F_0041 10.0.19100.0 10.0.20348.5479
ID_FILEATTRIB_F_0046 10.0.20400.0 10.0.22621.7494
ID_FILEATTRIB_F_0049 10.0.23000.0 10.0.26100.9140
ID_FILEATTRIB_F_0045 10.0.26100.32000 10.0.26100.33249
ID_FILEATTRIB_F_0048 10.0.26172.0 10.0.26172.33249
ID_FILEATTRIB_F_0047 10.0.27000.0 10.0.28000.2684
ID_FILEATTRIB_F_0043 10.0.29426.0 65535.65535.65535.65535



Hasleo 5.9.2.1
--------------
WinPE Boot Manager [Windows UEFI CA 2023] is BANNED.
C:\Program Files\Hasleo\Hasleo Backup Suite\bin\WADK\Boot\EFI_EX\bootmgfw.efi
File Version: 26100.30227, SVN 7.0

Bootable Media
--------------

DVD Drive E: "My Passport"

USB Drive G: "HASLEOBS"
Boot File [Windows UEFI CA 2023] is ALLOWED.
G:\EFI\Boot\bootx64.efi
File Version: 28000.352, SVN 9.0

boot.wim:1 (WinRE 26100.1)
Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\Windows\Boot\EFI_EX\bootmgfw_EX.efi
File Version: 28000.352, SVN 9.0

\Windows\System32\winload.efi is BANNED.
File Version: 26100.8971


PS C:\Windows\System32>
 

My Computer My Computer

At a glance

Windows 11 Intel i5 10400 HD630 graphics chipi5-1040012 gbHD630 chipset
OS
Windows 11 Intel i5 10400 HD630 graphics chip
Computer type
PC/Desktop
Manufacturer/Model
HP
CPU
i5-10400
Memory
12 gb
Graphics Card(s)
HD630 chipset
Monitor(s) Displays
LG 24inch
Hard Drives
SSD, external usb drive 1tb for files/backups
Keyboard
wireless Logi
Mouse
ms 4000 wireless mouse
Internet Speed
10meg
Browser
Firefox
Antivirus
Defender
Other Info
Win11 Home 25h2 26200.9168 08/11/2026
OK, still learning: how do I update the BANNED file in the G: Hasleo drive
You can use Garlin's update script for the USB drive
Code:
powershell -nop -ep bypass -f C:\temp17\Update_UEFI-CA2023.ps1 -bootmedia
I don't think Garlin's script fixes the staging of Hasleo/Macrium, or at least in the version he shared so far...
So to fix the Hasleo staging you need to copy the files yourself

The following is for Macrium, can someone share the exact path for Hasleo...
copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi $MacriumStagingFolder\macrium\WinREFiles\media\EFI\Boot\bootx64.efi
copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi $MacriumStagingFolder\macrium\WinREFiles\media\EFI\Microsoft\Boot\bootmgfw.efi


Based on Garlin's post #3057, it's this command for Hasleo
Code:
copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi "C:\Program Files\Hasleo\Hasleo Backup Suite\bin\WADK\Boot\EFI_EX\bootmgfw.efi"
 
Last edited:

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
ok, ran the bootmedia update and it stated : SUCCESS: NO UPDATES ARE REQUIRED.

but... on the end of USB I still see:

USB Drive G: "HASLEOBS"
Boot File [Windows UEFI CA 2023] is ALLOWED.
G:\EFI\Boot\bootx64.efi
File Version: 28000.352, SVN 9.0

boot.wim:1 (WinRE 26100.1)
Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\Windows\Boot\EFI_EX\bootmgfw_EX.efi
File Version: 28000.352, SVN 9.0

\Windows\System32\winload.efi is BANNED.
File Version: 26100.8971

That windload.efi is BANNED showing an older build ID: perhaps that's normal ? 26100 is I believe windows 24h2 does not seem right since I'm on 25H2 latest build updated just today: 26200.9168
 

My Computer My Computer

At a glance

Windows 11 Intel i5 10400 HD630 graphics chipi5-1040012 gbHD630 chipset
OS
Windows 11 Intel i5 10400 HD630 graphics chip
Computer type
PC/Desktop
Manufacturer/Model
HP
CPU
i5-10400
Memory
12 gb
Graphics Card(s)
HD630 chipset
Monitor(s) Displays
LG 24inch
Hard Drives
SSD, external usb drive 1tb for files/backups
Keyboard
wireless Logi
Mouse
ms 4000 wireless mouse
Internet Speed
10meg
Browser
Firefox
Antivirus
Defender
Other Info
Win11 Home 25h2 26200.9168 08/11/2026
New SkuSiPolicy and WinRE, all boot media updated.

Code:
C:\Windows\System32>powershell -ep bypass -f D:\Scripts\BlockedOrNot.ps1
Windows 11 25H2 (26200.9168)
VBS: ON

Policy File: "\\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b", Version 3.0.0.17

VolumeName  Filename                        FileVersion Status
----------  --------                        ----------- ------
BOOT2023PCA J:\sources\boot.wim             26100.9168  ALLOWED
MACRIUMHOME L:\sources\boot.wim             26100.9168  ALLOWED
            C:\Windows\System32\winload.efi 26100.9168  ALLOWED
            Disk 0 Partition 4 Winre.wim    26100.9168  ALLOWED

C:\Windows\System32>


Code:
EFI Files
---------
    SkuSiPolicy.p7b is CURRENT.
        \\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b
        Version: 3.0.0.17

    NOT RECOMMENDED for dual-boot setups.

Macrium v8.1.8853
-----------------
    WinRE Boot Manager [Windows UEFI CA 2023] is ALLOWED.
        c:\boot\macrium\WinREFiles\media\EFI\Microsoft\Boot\bootmgfw.efi
        File Version: 28000.352, SVN 9.0

Bootable Media
--------------

USB Drive J: "BOOT2023PCA"
    Boot File [Windows UEFI CA 2023] is ALLOWED.
        J:\EFI\Boot\bootx64.efi
        File Version: 28000.352, SVN 9.0

    boot.wim:2 (WinRE 26100.9168)
        Boot Manager [Windows UEFI CA 2023] is ALLOWED.
            \Windows\Boot\EFI_EX\bootmgfw_EX.efi
            File Version: 28000.352, SVN 9.0

        \Windows\System32\winload.efi is ALLOWED.
            File Version: 10.0.26100.9168

    Please wait while install SWM is analyzed.

    install.swm:1 (W11 25H2 26200.9168)
        Boot Manager [Windows UEFI CA 2023] is ALLOWED.
            \Windows\Boot\EFI_EX\bootmgfw_EX.efi
            File Version: 28000.352, SVN 9.0

        \Windows\System32\winload.efi is ALLOWED.
            File Version: 10.0.26100.9168

    J:\EFI\Microsoft\Boot\boot.stl [5/18/2026 07:44] is CURRENT.

USB Drive L: "MACRIUMHOME"
    Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
        L:\EFI\Microsoft\Boot\bootmgfw.efi
        File Version: 28000.352, SVN 9.0

    boot.wim:1 (WinRE 26100.1)
        Boot Manager [Windows UEFI CA 2023] is ALLOWED.
            \Windows\Boot\EFI_EX\bootmgfw_EX.efi
            File Version: 28000.352, SVN 9.0

        \Windows\System32\winload.efi is ALLOWED.
            File Version: 10.0.26100.9168

    L:\EFI\Microsoft\Boot\boot.stl [5/18/2026 07:44] is CURRENT.


PS D:\Scripts\SecureBoot-CA-2023-Updates.v2026.08.03>
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 26200.8973Intel® Core™ i7-14700KG.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5ASUS GeForce RTX 4070 Super 12GB
    OS
    Win 11 Pro 25H2 26200.8973
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel® Core™ i7-14700K
    Motherboard
    ASUS TUF Z690-PLUS WIFI (BIOS 4505)
    Memory
    G.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5
    Graphics Card(s)
    ASUS GeForce RTX 4070 Super 12GB
    Sound Card
    Sound Blaster AE-5 Plus
    Monitor(s) Displays
    ASUS TUF Gaming 27" 2K HDR Gaming
    Screen Resolution
    2560 x 1440
    Hard Drives
    Samsung 990 Pro 1TB NVMe (Win 11 25H2)
    SK hynix P41 500GB NVMe
    SK hynix P41 2TB NVMe (x3)
    Crucial P3 Plus 4TB
    PSU
    Corsair RM850x Shift
    Case
    Antec Dark Phantom DP502 FLUX
    Cooling
    Corsair Nautilus 360 RS AIO
    Keyboard
    Logitech MK 320
    Mouse
    Razer Basilisk V3
    Internet Speed
    750Mbs
    Browser
    Firefox
    Antivirus
    Winows Security
    Other Info
    MR 8.1 Home
  • At a glance

    Win 11 Pro 25H2 26200.8973Intel Core i5-1140064 GB DDR4MSI GeForce RTX 3060 Ventus 2X 12GB
    Operating System
    Win 11 Pro 25H2 26200.8973
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel Core i5-11400
    Motherboard
    Asus TUF Gaming Z590 Plus WiFi (BIOS 2803)
    Memory
    64 GB DDR4
    Graphics card(s)
    MSI GeForce RTX 3060 Ventus 2X 12GB
    Sound Card
    SoundBlaster Audigy Fx V2
    Monitor(s) Displays
    Samsung F27T350
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 980 Pro 1TB
    Samsung 970 EVO Plus 2TB
    Samsung 870 EVO 500GB SSD
    PSU
    Corsair HX750
    Case
    Cougar MX330-G Window
    Cooling
    Thermalright Frozen Edge 240 Black AIO
    Internet Speed
    350Mbps
    Browser
    Firefox
    Antivirus
    Windows Security
  • System Three
    Win 11 Pro 25H2 26200.8973
    ASUS PRIME Z370-P II BIOS 3004 7/12/21
    Intel Core i7-8700 CPU @ 3.20GHz
    32GB DDR4 RAM (4x8)
    iGPU Intel UHD Graphics 630
    Cooler Master Hyper 212
    Mid-Tower Desktop
I ran :
PS C:\Windows\System32> powershell -nop -ep bypass -f C:\temp15\blockedornot.ps1
Windows 11 25H2 (26200.9168)
VBS: ON

Policy File: "\\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b" is ENFORCED
Version: 3.0.0.17

Filename FileVersion Status
-------- ----------- ------
C:\Windows\System32\winload.efi 26100.9168 ALLOWED
\harddisk0\partition4\Recovery\WindowsRE\Winre.wim 26100.9168 ALLOWED
G:\sources\boot.wim 26100.8971 BLOCKED BY 'FILEATTRIB_F_0049'

how to fix/update boot.wim
 

My Computer My Computer

At a glance

Windows 11 Intel i5 10400 HD630 graphics chipi5-1040012 gbHD630 chipset
OS
Windows 11 Intel i5 10400 HD630 graphics chip
Computer type
PC/Desktop
Manufacturer/Model
HP
CPU
i5-10400
Memory
12 gb
Graphics Card(s)
HD630 chipset
Monitor(s) Displays
LG 24inch
Hard Drives
SSD, external usb drive 1tb for files/backups
Keyboard
wireless Logi
Mouse
ms 4000 wireless mouse
Internet Speed
10meg
Browser
Firefox
Antivirus
Defender
Other Info
Win11 Home 25h2 26200.9168 08/11/2026

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 26200.8973Intel® Core™ i7-14700KG.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5ASUS GeForce RTX 4070 Super 12GB
    OS
    Win 11 Pro 25H2 26200.8973
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel® Core™ i7-14700K
    Motherboard
    ASUS TUF Z690-PLUS WIFI (BIOS 4505)
    Memory
    G.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5
    Graphics Card(s)
    ASUS GeForce RTX 4070 Super 12GB
    Sound Card
    Sound Blaster AE-5 Plus
    Monitor(s) Displays
    ASUS TUF Gaming 27" 2K HDR Gaming
    Screen Resolution
    2560 x 1440
    Hard Drives
    Samsung 990 Pro 1TB NVMe (Win 11 25H2)
    SK hynix P41 500GB NVMe
    SK hynix P41 2TB NVMe (x3)
    Crucial P3 Plus 4TB
    PSU
    Corsair RM850x Shift
    Case
    Antec Dark Phantom DP502 FLUX
    Cooling
    Corsair Nautilus 360 RS AIO
    Keyboard
    Logitech MK 320
    Mouse
    Razer Basilisk V3
    Internet Speed
    750Mbs
    Browser
    Firefox
    Antivirus
    Winows Security
    Other Info
    MR 8.1 Home
  • At a glance

    Win 11 Pro 25H2 26200.8973Intel Core i5-1140064 GB DDR4MSI GeForce RTX 3060 Ventus 2X 12GB
    Operating System
    Win 11 Pro 25H2 26200.8973
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel Core i5-11400
    Motherboard
    Asus TUF Gaming Z590 Plus WiFi (BIOS 2803)
    Memory
    64 GB DDR4
    Graphics card(s)
    MSI GeForce RTX 3060 Ventus 2X 12GB
    Sound Card
    SoundBlaster Audigy Fx V2
    Monitor(s) Displays
    Samsung F27T350
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 980 Pro 1TB
    Samsung 970 EVO Plus 2TB
    Samsung 870 EVO 500GB SSD
    PSU
    Corsair HX750
    Case
    Cougar MX330-G Window
    Cooling
    Thermalright Frozen Edge 240 Black AIO
    Internet Speed
    350Mbps
    Browser
    Firefox
    Antivirus
    Windows Security
  • System Three
    Win 11 Pro 25H2 26200.8973
    ASUS PRIME Z370-P II BIOS 3004 7/12/21
    Intel Core i7-8700 CPU @ 3.20GHz
    32GB DDR4 RAM (4x8)
    iGPU Intel UHD Graphics 630
    Cooler Master Hyper 212
    Mid-Tower Desktop
Try:

.\Update_UEFI-CA2023.ps1 -bootmedia
Thanks tried that, and for fun ran it again stated : SUCCESS: NO UPDATES ARE REQUIRED.

I've done 2 restarts with no change, still flagging the wim.file

I have to leave for a couple hours. check later
 

My Computer My Computer

At a glance

Windows 11 Intel i5 10400 HD630 graphics chipi5-1040012 gbHD630 chipset
OS
Windows 11 Intel i5 10400 HD630 graphics chip
Computer type
PC/Desktop
Manufacturer/Model
HP
CPU
i5-10400
Memory
12 gb
Graphics Card(s)
HD630 chipset
Monitor(s) Displays
LG 24inch
Hard Drives
SSD, external usb drive 1tb for files/backups
Keyboard
wireless Logi
Mouse
ms 4000 wireless mouse
Internet Speed
10meg
Browser
Firefox
Antivirus
Defender
Other Info
Win11 Home 25h2 26200.9168 08/11/2026

Latest Support Threads

Back
Top Bottom