Hello.
I'm sorry to add more confusion, but I'm getting a very similar output to
@TheVisitor, with one difference: in
Efi files, I get this:
Disk 0: Windows Boot Manager [Windows UEFI CA 2023] is BANNED.
In Audit, I also get "secure boot is disabled".
On the other hand, the script doesn't seem to detect the factory PK UEFI and UEFI PK Certs, which I think I have, as per the screenshot I'm also attaching.
I also have the combined Kek Cert 2023 and SkuSiPolicy.p7b in the secure boot folder, but they haven't been applied yet, perhaps awaiting processing by Microsoft.
And when I try to run the update script, I get the error:
Downloading "edk2-x64-secureboot-binaries.zip" from GitHub.
incorrect authentication data: 0xC0000022
I hope I haven't been too confusing.
Results:
Audit:
Secure Boot: ON
Virtualization Based Security: ON
BitLocker on (C:) OFF
UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023
UEFI DBX Certs
--------------
Microsoft Windows PCA 2010
Windows BootMgr SVN 7.0
EFI Files
---------
Disk 0: Windows Boot Manager [Windows UEFI CA 2023] is BANNED.
Registry: WindowsUEFICA2023Capable = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.
Disk 0: SkuSiPolicy.p7b (for VBS) is NOT PRESENT.
AUDIT REPORT
============
1. Secure Boot is DISABLED
2. [Microsoft Corporation KEK 2K CA 2023] is missing from UEFI KEK
3. [Production PCA 2011] is missing from UEFI DBX
4. SkuSiPolicy.p7b (for VBS) is missing
REQUIRED ACTION
===============
Run the command:
Update_UEFI-CA2023.ps1 -Revoke
Finish the UEFI steps to manually add the [KEK CA 2023] cert, if the script provided instructions.
PS C:\WINDOWS\system32>
Verbose:
Windows 11 25H2 (26200.7462)
Secure Boot: ON
Virtualization Based Security: ON
BitLocker on (C:) OFF
BIOS Firmware
-------------
Dell Inc. XPS 13 9360
Version: 2.21.0
Date: 2022-06-02
Factory Default UEFI PK Cert
----------------------------
(NONE)
UEFI PK Cert
------------
(NONE)
Manual update of [KEK CA 2023] is REQUIRED.
Factory Default UEFI KEK Certs
------------------------------
Microsoft Corporation KEK CA 2011
UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Factory Default UEFI DB Certs
-----------------------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023
Factory Default UEFI DBX Certs
------------------------------
Microsoft Windows PCA 2010
EFI_CERT_SHA256_GUID Signatures: 77
UEFI DBX Certs
--------------
Microsoft Windows PCA 2010
Windows BootMgr SVN 7.0
EFI_CERT_SHA256_GUID Signatures: 486
EFI Files
---------
Disk 0: Windows Boot Manager [Windows UEFI CA 2023] is BANNED.
bootmgfw.efi File version: 26100.30227
Registry: WindowsUEFICA2023Capable = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.
Disk 0: SkuSiPolicy.p7b (for VBS) is NOT PRESENT.
REQUIRED ACTION
===============
Run the command:
Update_UEFI-CA2023.ps1 -Revoke
Finish the UEFI steps to manually add the [KEK CA 2023] cert, if the script provided instructions.
PS C:\WINDOWS\system32>
Thanks
