Solved garlin's PowerShell scripts for updating Secure Boot CA 2023


When you have no keys present, the UEFI considers that as Setup mode and Secure Boot by definition is disabled. You can't enforce Secure Boot when no certs exist. As soon as you install a working set of keys, then enforcement can begin again. Since my update script fills all of the missing certs in one pass (when you're in Setup Mode), you don't have switch Secure Boot modes.

But it's generally good to temporarily do that, in case some unexpected error happens.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
@garlin, I can't remember if you previously explained it, if you did, sorry to ask again.
A part from OEM DBX entries which MS has no control over, will MS overtime remove obsolete/unrequired DBX entries ?
On the same topic, have you ever seen OEMs cleaning up obsolete/unrequired DBX entries ?
 

My Computers My Computers

  • At a glance

    Windows 1132GB
    OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell 3910
    Memory
    32GB
  • At a glance

    Windows 1116GB
    Operating System
    Windows 11
    Computer type
    Tablet
    Manufacturer/Model
    Surface Pro 9
    Memory
    16GB
Just as an FYI - I tried several different procedures I found on the internet to rollback the T490 BIOS from version 1.85 to 1.84 and none of them worked. That was the main thing that pushed me to the Mosby route to redo the certificates. I didn't stop to think that @garlin 's update script would do the same thing.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2i7-8565U16GBIntel UHD Graphics 620
    OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo T490 (2020 Hardware)
    CPU
    i7-8565U
    Motherboard
    20N20028US
    Memory
    16GB
    Graphics Card(s)
    Intel UHD Graphics 620
    Sound Card
    Realtec Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 970 PRO 512GB NVMe
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Supported hardware, upgraded from Windows 10 Pro to Windows 11 Pro version 24H2 on 06/01/2025 using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/07/2025. Secure boot enabled. Secure Boot CA 2023 updated.
  • At a glance

    Windows 11 Pro 25H2i7-4770 (with SSE4.2, and POPCNT)16GBIntel HD Graphics 4600
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Lenovo ThinkCentre M83 (2014 Hardware)
    CPU
    i7-4770 (with SSE4.2, and POPCNT)
    Motherboard
    10AL000GUS
    Memory
    16GB
    Graphics card(s)
    Intel HD Graphics 4600
    Sound Card
    Realtec High Definition Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 860 PRO 1TB SATA
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Unsupported hardware, upgraded from Windows 10 Pro (TPM 1.2 & unsupported CPU, but does have SSE4.2, and POPCNT) to Windows 11 Pro version 24H2 on 06/15/2025. Added Registry Key HKEY_LOCAL_MACHINE\SYSTEM\Setup\MoSetup – AllowUpgradesWithUnsupportedTPMOrCPU=1 to allow installation using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/08/2025. Secure boot enabled. Secure Boot CA 2023 updated.
@garlin, I can't remember if you previously explained it, if you did, sorry to ask again.
A part from OEM DBX entries which MS has no control over, will MS overtime remove obsolete/unrequired DBX entries ?
On the same topic, have you ever seen OEMs cleaning up obsolete/unrequired DBX entries ?
The inherent problem is a host OS cannot (according the UEFI spec) delete an existing key from a Secure Boot variable. The supported actions are to either replace the entire contents of a variable, or to append a new entry.

Window cannot scan the existing DBX list and delete the 151 (or really 154) entries on a live system. They're not going to write a tool to collect the current DBX list, trim it down, and then rewrite the shorter list back to the DBX. But in order to perform that task, they need to have a copy of your PK to authenticate the new list (which they don't have any way).

So the answer is no. Neither MS or your PC vendor will help you in this regard. Now most OEM's stopped collecting new EFI signatures for the factory defaults years ago, because it was clear MS was taking the lead to perform this at the Windows level with dbxupdate.bin. This is why most factory defaults tend to have under 200 DBX entries. There's no point duplicating this work when MS is supposed to track newer entries.

But... some OEM's have decided to embrace the latest DBX list as it's currently published. Like the one with 430 factory defaults. It's up to the OEM.

If you want to remove the obsoleted entries, that's up to the user. The UEFI Forum, which serves as the standards group for the industry, doesn't have a mandate covering cleanup because it's never happened before. MS was trying to help users on older PC's with BIOS restrictions on Secure Boot variable space, and now that's created a gray area.

For an average user to reset their keys may be a challenging task if they're not familiar with their Secure Boot menu options, or your OEM has a terrible BIOS which makes it really confusing. So nobody in the industry is willing to tell you to reset any keys. That's an unwanted support nightmare with confused users.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7

Latest Support Threads

Back
Top Bottom