Solved garlin's PowerShell scripts for updating Secure Boot CA 2023


Hello, it seems the update process was successful, but when I check I get these error lines in DBX, it seems something is broken in the script. SecureBoot-260531
Please try the test version of the script, it will print some debugging info.
 

Attachments

My Computer

System One

  • OS
    Windows 7
What happens if you copy this text into a PS window?
Code:
    try {
        $SbatLevel_Bytes = [byte[]](Get-ItemPropertyValue -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecureBoot\SBAT' -Name 'SbatLevel' -ErrorAction Stop)
    }
    catch {
        "did not work"
    }
 

My Computer

System One

  • OS
    Windows 7
What happens if you copy this text into a PS window?
Code:
    try {
        $SbatLevel_Bytes = [byte[]](Get-ItemPropertyValue -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecureBoot\SBAT' -Name 'SbatLevel' -ErrorAction Stop)
    }
    catch {
        "did not work"
    }
It shows this:

Screenshot 2026-06-06 160956.webp
 

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    HP
    CPU
    Gen 11 Core i5
    Memory
    16GB
See this is from your 05/31 release:


Screenshot 2026-06-06 161255.webp
 

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    HP
    CPU
    Gen 11 Core i5
    Memory
    16GB
Please try the test version of the script, it will print some debugging info.
Thank you for the quick response.
The error lines in PS remain, but now it shows other lines, probably more than you need.

PS: I'm using a translator, so there might be grammatical errors.


Secure Boot: ON
Virtualization Based Security: OFF
BitLocker on (C:) OFF

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

UEFI DBX Certs
--------------
(NONE)
foreach |False|
Exceção ao chamar "Substring" com "2" argumento(s): "startIndex não pode ser maior que o comprimento da cadeia de
caracteres.
Nome do parâmetro: startIndex"
No E:\Arquivados\Ferramentas\SecureBoot-260531\Check_UEFI-CA2023.ps1:771 caractere:5
+ $SVN = '{0}.{1}' -f [System.Convert]::ToUInt16($SignatureData.Sub ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : NotSpecified: (:) [], MethodInvocationException
+ FullyQualifiedErrorId : ArgumentOutOfRangeException


EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.
Required Sig: |80B4D96931BF0D02FD91A61E19D14F1DA452E66DB2408CA8604D411F92659F0A|
Required Sig: |F52F83A3FA9CFBD6920F722824DBE4034534D25B8507246B3B957DAC6E1BCE7A|
Required Sig: |C5D9D8A186E2C82D09AFAA2A6F7F2E73870D3E64F72C4E08EF67796A840F0FBD|
Required Sig: |1AEC84B84B6C65A51220A9BE7181965230210D62D6D33C48999C6B295A2B0A06|
Required Sig: |C3A99A460DA464A057C3586D83CEF5F4AE08B7103979ED8932742DF0ED530C66|
Required Sig: |58FB941AEF95A25943B3FB5F2510A0DF3FE44C58C95E0AB80487297568AB9771|
Required Sig: |5391C3A2FB112102A6AA1EDC25AE77E19F5D6F09CD09EEB2509922BFCD5992EA|
Required Sig: |D626157E1D6A718BC124AB8DA27CBB65072CA03A7B6B257DBDCBBD60F65EF3D1|
Required Sig: |D063EC28F67EBA53F1642DBF7DFF33C6A32ADD869F6013FE162E2C32F1CBE56D|
Required Sig: |29C6EB52B43C3AA18B2CD8ED6EA8607CEF3CFAE1BAFE1165755CF2E614844A44|
Required Sig: |90FBE70E69D633408D3E170C6832DBB2D209E0272527DFB63D49D29572A6F44C|
Required Sig: |106FACEACFECFD4E303B74F480A08098E2D0802B936F8EC774CE21F31686689C|
Required Sig: |174E3A0B5B43C6A607BBD3404F05341E3DCF396267CE94F8B50E2E23A9DA920C|
Required Sig: |2B99CF26422E92FE365FBF4BC30D27086C9EE14B7A6FFF44FB2F6B9001699939|
Required Sig: |2E70916786A6F773511FA7181FAB0F1D70B557C6322EA923B2A8D3B92B51AF7D|
Required Sig: |3FCE9B9FDF3EF09D5452B0F95EE481C2B7F06D743A737971558E70136ACE3E73|
Required Sig: |47CC086127E2069A86E03A6BEF2CD410F8C55A6D6BDB362168C31B2CE32A5ADF|
Required Sig: |71F2906FD222497E54A34662AB2497FCC81020770FF51368E9E3D9BFCBFD6375|
Required Sig: |82DB3BCEB4F60843CE9D97C3D187CD9B5941CD3DE8100E586F2BDA5637575F67|
Required Sig: |8AD64859F195B5F58DAFAA940B6A6167ACD67A886E8F469364177221C55945B9|
Required Sig: |8D8EA289CFE70A1C07AB7365CB28EE51EDD33CF2506DE888FBADD60EBF80481C|
Required Sig: |AEEBAE3151271273ED95AA2E671139ED31A98567303A332298F83709A9D55AA1|
Required Sig: |C409BDAC4775ADD8DB92AA22B5B718FB8C94A1462C1FE9A416B95D8A3388C2FC|
Required Sig: |C617C1A8B1EE2A811C28B5A81B4C83D7C98B5B0C27281D610207EBE692C2967F|
Required Sig: |C90F336617B8E7F983975413C997F10B73EB267FD8A10CB9E3BDBFC667ABDB8B|
Required Sig: |64575BD912789A2E14AD56F6341F52AF6BF80CF94400785975E9F04E2D64D745|
Required Sig: |45C7C8AE750ACFBB48FC37527D6412DD644DAED8913CCD8A24C94D856967DF8E|
Required Sig: |81D8FB4C9E2E7A8225656B4B8273B7CBA4B03EF2E9EB20E0A0291624ECA1BA86|
Required Sig: |B92AF298DC08049B78C77492D6551B710CD72AADA3D77BE54609E43278EF6E4D|
Required Sig: |E19DAE83C02E6F281358D4EBD11D7723B4F5EA0E357907D5443DECC5F93C1E9D|
Required Sig: |39DBC2288EF44B5F95332CB777E31103E840DBA680634AA806F5C9B100061802|
Required Sig: |32F5940CA29DD812A2C145E6FC89646628FFCC7C7A42CAE512337D8D29C40BBD|
Required Sig: |10D45FCBA396AEF3153EE8F6ECAE58AFE8476A280A2026FC71F6217DCF49BA2F|
Required Sig: |C805603C4FA038776E42F263C604B49D96840322E1922D5606A9B0BBB5BFFE6F|
Required Sig: |D8D4E6DDF6E42D74A6A536EA62FD1217E4290B145C9E5C3695A31B42EFB5F5A4|
Required Sig: |F277AF4F9BDC918AE89FA35CC1B34E34984C04AE9765322C3CB049574D36509C|
Required Sig: |68EE4632C7BE1C66C83E89DD93EAEE1294159ABF45B4C2C72D7DC7499AA2A043|
Required Sig: |148FE18F715A9FCFE1A444CE0FFF7F85869EB422330DC04B314C0F295D6DA79E|
Required Sig: |AD3BE589C0474E97DE5BB2BF33534948B76BB80376DFDC58B1FED767B5A15BFC|
Required Sig: |E051B788ECBAEDA53046C70E6AF6058F95222C046157B8C4C1B9C2CFC65F46E5|
Required Sig: |C452AB846073DF5ACE25CCA64D6B7A09D906308A1A65EB5240E3C4EBCAA9CC0C|
Required Sig: |3A91F0F9E5287FA2994C7D930B2C1A5EE14CE8E1C8304AE495ADC58CC4453C0C|
Required Sig: |1B909115A8D473E51328A87823BD621CE655DFAE54FA2BFA72FDC0298611D6B8|
Required Sig: |8C0349D708571AE5AA21C11363482332073297D868F29058916529EFC520EF70|
Required Sig: |EED7E0EFF2ED559E2A79EE361F9962AF3B1E999131E30BB7FD07546FAE0A7267|
Required Sig: |BADFF5E4F0FEA711701CA8FB22E4C43821E31E210CF52D1D4F74DD50F1D039BC|
Required Sig: |D89A11D16C488DD4FBBC541D4B07FAF8670D660994488FE54B1FBFF2704E4288|
Required Sig: |F2A16D35B554694187A70D40CA682959F4F35C2CE0EAB8FD64F7AC2AB9F5C24A|
Required Sig: |5B248E913D71853D3DA5AEDD8D9A4BC57A917126573817FB5FCB2D86A2F1C886|
Required Sig: |B93F0699598F8B20FA0DACC12CFCFC1F2568793F6E779E04795E6D7C22530F75|
Required Sig: |EAFF8C85C208BA4D5B6B8046F5D6081747D779BADA7768E649D047FF9B1F660C|
Required Sig: |C9EC350406F26E559AFFB4030DE2EBDE5435054C35A998605B8FCF04972D8D55|
Required Sig: |340DA32B58331C8E2B561BAF300CA9DFD6B91CD2270EE0E2A34958B1C6259E85|
Required Sig: |5C39F0E5E0E7FA3BE05090813B13D161ACAF48494FDE6233B452C416D29CDDBE|
Required Sig: |DD59AF56084406E38C63FBE0850F30A0CD1277462A2192590FB05BC259E61273|
Required Sig: |0FA3A29AD05130D7FE5BF4D2596563CDED1D874096AACC181069932A2E49519A|
Required Sig: |DBAF9E056D3D5B38B68553304ABC88827EBC00F80CB9C7E197CDBC5822CD316C|
Required Sig: |0CE02100F67C7EF85F4EED368F02BF7092380A3C23CA91FD7F19430D94B00C19|
Required Sig: |2B2298EAA26B9DC4A4558AE92E7BB0E4F85CF34BF848FDF636C0C11FBEC49897|
Required Sig: |3765D769C05BF98B427B3511903B2137E8A49B6F859D0AF159ED6A86786AA634|
Required Sig: |78B4EDCAABC8D9093E20E217802CAEB4F09E23A3394C4ACC6E87E8F35395310F|
Required Sig: |9954A1A99D55E8B189AB1BCA414B91F6A017191F6C40A86B6F3EF368DD860031|
Required Sig: |F1B4F6513B0D544A688D13ADC291EFA8C59F420CA5DCB23E0B5A06FA7E0D083D|
Required Sig: |F1863EC8B7F43F94AD14FB0B8B4A69497A8C65ECBC2A55E0BB420E772B8CDC91|
Required Sig: |781764102188A8B4B173D4A8F5EC94D828647156097F99357A581E624B377509|
Required Sig: |E6856F137F79992DC94FA2F43297EC32D2D9A76F7BE66114C6A13EFC3BCDF5C8|
Required Sig: |81A8B2C9751AEB1FABA7DBDE5EE9691DC0EAEE2A31C38B1491A8146756A6B770|
Required Sig: |9FA4D5023FD43ECAFF4200BA7E8D4353259D2B7E5E72B5096EFF8027D66D1043|
Required Sig: |D372C0D0F4FDC9F52E9E1F23FC56EE72414A17F350D0CEA6C26A35A6C3217A13|
Required Sig: |09F98AA90F85198C0D73F89BA77E87EC6F596C491350FB8F8BBA80A62FBB914B|
Required Sig: |147730B42F11FE493FE902B6251E97CD2B6F34D36AF59330F11D02A42F940D07|
Required Sig: |29CCA4544EA330D61591C784695C149C6B040022AC7B5B89CBD72800D10840EA|
Required Sig: |2DCF8E8D817023D1E8E1451A3D68D6EC30D9BED94CBCB87F19DDC1CC0116AC1A|
Required Sig: |3A4F74BEAFAE2B9383AD8215D233A6CF3D057FB3C7E213E897BEEF4255FAEE9D|
Required Sig: |4185821F6DAB5BA8347B78A22B5F9A0A7570CA5C93A74D478A793D83BAC49805|
Required Sig: |45876B4DD861D45B3A94800774027A5DB45A48B2A729410908B6412F8A87E95D|
Required Sig: |5890FA227121C76D90ED9E63C87E3A6533EEA0F6F0A1A23F1FC445139BC6BCDF|
Required Sig: |5D1E9ACBBB4A7D024B6852DF025970E2CED66FF622EE019CD0ED7FD841CCAD02|
Required Sig: |6DEAD13257DFC3CCC6A4B37016BA91755FE9E0EC1F415030942E5ABC47F07C88|
Required Sig: |BEF7663BE5EA4DBFD8686E24701E036F4C03FB7FCD67A6C566ED94CE09C44470|
Required Sig: |CF13A243C1CD2E3C8CEB7E70100387CECBFB830525BBF9D0B70C79ADF3E84128|
Required Sig: |DF02AAB48387A9E1D4C65228089CB6ABE196C8F4B396C7E4BBC395DE136977F6|
Required Sig: |DF91AC85A94FCD0CFB8155BD7CBEFAAC14B8C5EE7397FE2CC85984459E2EA14E|
Required Sig: |E36DFC719D2114C2E39AEA88849E2845AB326F6F7FE74E0E539B7E54D81F3631|
Required Sig: |E24B315A551671483D8B9073B32DE11B4DE1EB2EAB211AFD2D9C319FF55E08D0|
Required Sig: |B3E506340FBF6B5786973393079F24B66BA46507E35E911DB0362A2ACDE97049|
Required Sig: |7BC9CB5463CE0F011FB5085EB8BA77D1ACD283C43F4A57603CC113F22CEBC579|
Required Sig: |91971C1497BF8E5BC68439ACC48D63EBB8FAABFD764DCBE82F3BA977CAC8CF6A|
Required Sig: |BC75F910FF320F5CB5999E66BBD4034F4AE537A42FDFEF35161C5348E366E216|
Required Sig: |65F3C0A01B8402D362B9722E98F75E5E991E6C186E934F7B2B2E6BE6DEC800EC|
Required Sig: |2679650FE341F2CF1EA883460B3556AAAF77A70D6B8DC484C9301D1B746CF7B5|
Required Sig: |E7C20B3AB481EC885501ECA5293781D84B5A1AC24F88266B5270E7ECB4AA2538|
Required Sig: |47FF1B63B140B6FC04ED79131331E651DA5B2E2F170F5DAEF4153DC2FBC532B1|
Required Sig: |894D7839368F3298CC915AE8742EF330D7A26699F459478CF22C2B6BB2850166|
Required Sig: |1F16078CCE009DF62EDB9E7170E66CAAE670BCE71B8F92D38280C56AA372031D|
Required Sig: |37A480374DAF6202CE790C318A2BB8AA3797311261160A8E30558B7DEA78C7A6|
Required Sig: |408B8B3DF5ABB043521A493525023175AB1261B1DE21064D6BF247CE142153B9|
Required Sig: |540801DD345DC1C33EF431B35BF4C0E68BD319B577B9ABE1A9CFF1CBC39F548F|
Required Sig: |89F3D1F6E485C334CD059D0995E3CDFDC00571B1849854847A44DC5548E2DCFB|
Required Sig: |9F1863ED5717C394B42EF10A6607B144A65BA11FB6579DF94B8EB2F0C4CD60C1|
Required Sig: |BB1DD16D530008636F232303A7A86F3DFF969F848815C0574B12C2D787FEC93F|
Required Sig: |02E6216ACAEF6401401FA555ECBED940B1A5F2569AED92956137AE58482EF1B7|
Required Sig: |6EFEFE0B5B01478B7B944C10D3A8ACA2CCA4208888E2059F8A06CB5824D7BAB0|
Required Sig: |0DC24C75EB1AEF56B9F13AB9DE60E2ECA1C4510034E290BBB36CF60A549B234C|
Required Sig: |835881F2A5572D7059B5C8635018552892E945626F115FC9CA07ACF7BDE857A4|
Required Sig: |3ECE27CBB3EC4438CCE523B927C4F05FDC5C593A3766DB984C5E437A3FF6A16B|
Required Sig: |0C51D7906FC4931149765DA88682426B2CFE9E6AA4F27253EAB400111432E3A7|
Required Sig: |631F0857B41845362C90C6980B4B10C4B628E23DBE24B6E96C128AE3DCB0D5AC|
Required Sig: |947078F97C6196968C3AE99C9A5D58667E86882CF6C8C9D58967A496BB7AF43C|
Required Sig: |A924D3CAD6DA42B7399B96A095A06F18F6B1ABA5B873B0D5F3A0EE2173B48B6C|
Required Sig: |95049F0E4137C790B0D2767195E56F73807D123ADCF8F6E7BF2D4D991D305F89|
Required Sig: |06EB5BADD26E4FAE65F9A42358DEEF7C18E52CC05FBB7FC76776E69D1B982A14|
Required Sig: |0928F0408BF725E61D67D87138A8EEBC52962D2847F16E3587163B160E41B6AD|
Required Sig: |1D8B58C1FDB8DA8B33CCEE1E5F973AF734D90EF317E33F5DB1573C2BA088A80C|
Required Sig: |270C84B29D86F16312B06AAAE4EBB8DFF8DE7D080D825B8839FF1766274EFF47|
Required Sig: |311A2AC55B50C09B30B3CC93B994A119153EEEAC54EF892FC447BBBD96101AA1|
Required Sig: |32AD3296829BC46DCFAC5EDDCB9DBF2C1EED5C11F83B2210CF9C6E60C798D4A7|
Required Sig: |367A31E5838831AD2C074647886A6CDFF217E6B1BA910BFF85DC7A87AE9B5E98|
Required Sig: |3AE76C45CA70E9180C1559981F42622DD251BCA1FBE6B901C52EC11673B03514|
Required Sig: |3BE8E7EB348D35C1928F19C769846788991641D1F6CF09514CA10269934F7359|
Required Sig: |3E3926F0B8A15AD5A14167BB647A843C3D4321E35DBC44DCE8C837417F2D28B0|
Required Sig: |400AC66D59B7B094A9E30B01A6BD013AFF1D30570F83E7592F421DBE5FF4BA8F|
Required Sig: |4667BF250CD7C1A06B8474C613CDB1DF648A7F58736FBF57D05D6F755DAB67F4|
Required Sig: |57E6913AFACC5222BD76CDAF31F8ED88895464255374EF097A82D7F59AD39596|
Required Sig: |65B2E7CC18D903C331DF1152DF73CA0DC932D29F17997481C56F3087B2DD3147|
Required Sig: |788383A4C733BB87D2BF51673DC73E92DF15AB7D51DC715627AE77686D8D23BC|
Required Sig: |7F49CCB309323B1C7AB11C93C955B8C744F0A2B75C311F495E18906070500027|
Required Sig: |82ACBA48D5236CCFF7659AFC14594DEE902BD6082EF1A30A0B9B508628CF34F4|
Required Sig: |8D93D60C691959651476E5DC464BE12A85FA5280B6F524D4A1C3FCC9D048CFAD|
Required Sig: |9783B5EE4492E9E891C655F1F48035959DAD453C0E623AF0FE7BF2C0A57885E3|
Required Sig: |97A8C5BA11D61FEFBB5D6A05DA4E15BA472DC4C6CD4972FC1A035DE321342FE4|
Required Sig: |992820E6EC8C41DAAE4BD8AB48F58268E943A670D35CA5E2BDCD3E7C4C94A072|
Required Sig: |9C259FCB301D5FC7397ED5759963E0EF6B36E42057FD73046E6BD08B149F751C|
Required Sig: |9DD2DCB72F5E741627F2E9E03AB18503A3403CF6A904A479A4DB05D97E2250A9|
Required Sig: |BDD01126E9D85710D3FE75AF1CC1702A29F081B4F6FDF6A2B2135C0297A9CEC5|
Required Sig: |BE435DF7CD28AA2A7C8DB4FC8173475B77E5ABF392F76B7C76FA3F698CB71A9A|
Required Sig: |C3505BF3EC10A51DACE417C76B8BD10939A065D1F34E75B8A3065EE31CC69B96|
Required Sig: |CB340011AFEB0D74C4A588B36EBAA441961608E8D2FA80DCA8C13872C850796B|
Required Sig: |CC8EEC6EB9212CBF897A5ACE7E8ABEECE1079F1A6DEF0A789591CB1547F1F084|
Required Sig: |DA3560FD0C32B54C83D4F2FF869003D2089369ACF2C89608F8AFA7436BFA4655|
Required Sig: |E39891F48BBCC593B8ED86CE82CE666FC1145B9FCBFD2B07BAD0A89BF4C7BFBF|
Required Sig: |EE83A566496109A74F6AC6E410DF00BB29A290E0021516AE3B8A23288E7E2E72|
Required Sig: |F31FD461C5E99510403FC97C1DA2D8A9CBE270597D32BADF8FD66B77495F8D94|
Required Sig: |F48E6DD8718E953B60A24F2CBEA60A9521DEAE67DB25425B7D3ACE3C517DD9B7|
Required Sig: |4B8668A5D465BCDD9000AA8DFCFF42044FCBD0AECE32FC7011A83E9160E89F09|
Required Sig: |9D00AE4CD47A41C783DC48F342C076C2C16F3413F4D2DF50D181CA3BB5AD859D|
Required Sig: |0A75EA0B1D70EAA4D3F374246DB54FC7B43E7F596A353309B9C36B4FD975725E|
Required Sig: |96E4509450D380DAC362FF8E295589128A1F1CE55885D20D89C27BA2A9D00909|
Required Sig: |A4D978B7C4BDA15435D508F8B9592EC2A5ADFB12EA7BAD146A35ECB53094642F|
Required Sig: |386D695CDF2D4576E01BCACCF5E49E78DA51AF9955C0B8FA7606373B007994B3|
Required Sig: |70A1450AF2AD395569AD0AFEB1D9C125324EE90AEC39C258880134D4892D51AB|
Required Sig: |5C5805196A85E93789457017D4F9EB6828B97C41CB9BA6D3DC1FCC115F527A55|
Required Sig: |66AA13A0EDC219384D9C425D3927E6ED4A5D1940C5E7CD4DAC88F5770103F2F1|
Required Sig: |DCCC3CE1C00EE4B0B10487D372A0FA47F5C26F57A359BE7B27801E144EACBAC4|
Required Sig: |E800395DBE0E045781E8005178B4BAF5A257F06E159121A67C595F6AE22506FD|
Required Sig: |1CB4DCCAF2C812CFA7B4938E1371FE2B96910FE407216FD95428672D6C7E7316|
Required Sig: |0257FF710F2A16E489B37493C07604A7CDA96129D8A8FD68D2B6AF633904315D|
Required Sig: |495300790E6C9BF2510DABA59DB3D57E9D2B85D7D7640434EC75BAA3851C74E5|
Required Sig: |8E53EFDC15F852CEE5A6E92931BC42E6163CD30FF649CCA7E87252C3A459960B|
Required Sig: |992D359AA7A5F789D268B94C11B9485A6B1CE64362B0EDB4441CCC187C39647B|
Required Sig: |03F64A29948A88BEFFDB035E0B09A7370CCF0CD9CE6BCF8E640C2107318FAB87|
Required Sig: |05D87E15713454616F5B0ED7849AB5C1712AB84F02349478EC2A38F970C01489|
Required Sig: |08BB2289E9E91B4D20FF3F1562516AB07E979B2C6CEFE2AB70C6DFC1199F8DA5|
Required Sig: |1F179186EFDF5EF2DE018245BA0EAE8134868601BA0D35FF3D9865C1537CED93|
Required Sig: |362ED31D20B1E00392281231A96F0A0ACFDE02618953E695C9EF2EB0BAC37550|
Required Sig: |41D1EEB177C0324E17DD6557F384E532DE0CF51A019A446B01EFB351BC259D77|
Required Sig: |61CEC4A377BF5902C0FEAEE37034BF97D5BC6E0615E23A1CDFBAE6E3F5FB3CFD|
Required Sig: |6873D2F61C29BD52E954EEFF5977AA8367439997811A62FF212C948133C68D97|
Required Sig: |6DBBEAD23E8C860CF8B47F74FBFCA5204DE3E28B881313BB1D1ECCDC4747934E|
Required Sig: |72C26F827CEB92989798961BC6AE748D141E05D3EBCFB65D9041B266C920BE82|
Required Sig: |9063F5FBC5E57AB6DE6C9488146020E172B176D5AB57D4C89F0F600E17FE2DE2|
Required Sig: |91656AA4EF493B3824A0B7263248E4E2D657A5C8488D880CB65B01730932FB53|
Required Sig: |97A51A094444620DF38CD8C6512CAC909A75FD437AE1E4D22929807661238127|
Required Sig: |9BAF4F76D76BF5D6A897BFBD5F429BA14D04E08B48C3EE8D76930A828FFF3891|
Required Sig: |9ED33F0FBC180BC032F8909CA2C4AB3418EDC33A45A50D2521A3B5876AA3EA2C|
Required Sig: |B8D6B5E7857B45830E017C7BE3D856ADEB97C7290EB0665A3D473A4BEB51DCF3|
Required Sig: |BB01DA0333BB639C7E1C806DB0561DC98A5316F22FEF1090FB8D0BE46DAE499A|
Required Sig: |C2469759C1947E14F4B65F72A9F5B3AF8B6F6E727B68BB0D91385CBF42176A8A|
Required Sig: |C42D11C70CCF5E8CF3FB91FDF21D884021AD836CA68ADF2CBB7995C10BF588D4|
Required Sig: |C69D64A5B839E41BA16742527E17056A18CE3C276FD26E34901A1BC7D0E32219|
Required Sig: |D9668AB52785086786C134B5E4BDDBF72452813B6973229AB92AA1A54D201BF5|
Required Sig: |040B3BC339E9B6F9ACD828B88F3482A5C3F64E67E5A714BA1DA8A70453B34AF6|
Required Sig: |1142A0CC7C9004DFF64C5948484D6A7EC3514E176F5CA6BDEED7A093940B93CC|
Required Sig: |288878F12E8B9C6CCBF601C73D5F4E985CAC0FF3FCB0C24E4414912B3EB91F15|
Required Sig: |2EA4CB6A1F1EB1D3DCE82D54FDE26DED243BA3E18DE7C6D211902A594FE56788|
Required Sig: |40D6CAE02973789080CF4C3A9AD11B5A0A4D8BBA4438AB96E276CC784454DEE7|
Required Sig: |4F0214FCE4FA8897D0C80A46D6DAB4124726D136FC2492EFD01BFEDFA3887A9C|
Required Sig: |5C2AFE34BD8A7AEBBB439C251DFB6A424F00E535AC4DF61EC19745B6F10E893A|
Required Sig: |99D7ADA0D67E5233108DBD76702F4B168087CFC4EC65494D6CA8ABA858FEBADA|
Required Sig: |A608A87F51BDF7532B4B80FA95EADFDF1BF8B0CBB58A7D3939C9F11C12E71C85|
Required Sig: |BDD4086C019F5D388453C6D93475D39A576572BAFF75612C321B46A35A5329B1|
Required Sig: |CB994B400590B66CBF55FC663555CAF0D4F1CE267464D0452C2361E05EE1CD50|
Required Sig: |D6EE8DB782E36CAFFB4D9F8207900487DE930AABCC1D196FA455FBFD6F37273D|
Required Sig: |DDA0121DCF167DB1E2622D10F454701837AC6AF304A03EC06B3027904988C56B|
Required Sig: |E42572AFAC720F5D4A1C7AAAF802F094DACEB682F4E92783B2BB3FA00862AF7F|
Required Sig: |E6236DC1EE074C077C7A1C9B3965947430847BE125F7AEB71D91A128133AEA7F|
Required Sig: |EF87BE89A413657DE8721498552CF9E0F3C1F71BC62DFA63B9F25BBC66E86494|
Required Sig: |F5E892DD6EC4C2DEFA4A495C09219B621379B64DA3D1B2E34ADF4B5F1102BD39|
Required Sig: |D4241190CD5A369D8C344C660E24F3027FB8E7064FAB33770E93FA765FFB152E|
Required Sig: |23142E14424FB3FF4EFC75D00B63867727841ABA5005149070EE2417DF8AB799|
Required Sig: |91721AA76266B5BB2F8009F1188510A36E54AFD56E967387EA7D0B114D782089|
Required Sig: |DC8AFF7FAA9D1A00A3E32EEFBF899B3059CBB313A48B82FA9C8D931FD58FB69D|
Required Sig: |9959ED4E05E548B59F219308A45563EA85BB224C1AD96DEC0E96C0E71FFCCD81|
Required Sig: |47B31A1C7867644B2EE8093B2D5FBE21E21F77C1617A2C08812F57ACE0850E9F|
Required Sig: |FABC379DF395E6F52472B44FA5082F9F0E0DA480F05198C66814B7055B03F446|
Required Sig: |E37FF3FC0EFF20BFC1C060A4BF56885E1EFD55A8E9CE3C5F4869444CACFFAD0B|
Required Sig: |4CDAE3920A512C9C052A8B4ABA9096969B0A0197B614031E4C64A5D898CB09B9|
Required Sig: |5B89F1AA2435A03D18D9B203D17FB4FBA4F8F5076CF1F9B8D6D9B826222235C1|
Required Sig: |007F4C95125713B112093E21663E2D23E3C1AE9CE4B5DE0D58A297332336A2D8|
Required Sig: |E060DA09561AE00DCFB1769D6E8E846868A1E99A54B14AA5D0689F2840CEC6DF|
Required Sig: |48F4584DE1C5EC650C25E6C623635CE101BD82617FC400D4150F0AEE2355B4CA|
Required Sig: |AF79B14064601BC0987D4747AF1E914A228C05D622CEDA03B7A4F67014FEE767|
Required Sig: |C55BE4A2A6AC574A9D46F1E1C54CAC29D29DCD7B9040389E7157BB32C4591C4C|
Required Sig: |E9D873CBCEDE3634E0A4B3644B51E1C8A0A048272992C738513EBC96CD3E3360|
Required Sig: |66D0803E2550D9E790829AE1B5F81547CC9BFBE69B51817068ECB5DABB7A89FC|
Required Sig: |284153E7D04A9F187E5C3DBFE17B2672AD2FBDD119F27BEC789417B7919853EC|
Required Sig: |EDD2CB55726E10ABEDEC9DE8CA5DED289AD793AB3B6919D163C875FEC1209CD5|
Required Sig: |90AEC5C4995674A849C1D1384463F3B02B5AA625A5C320FC4FE7D9BB58A62398|
Required Sig: |CA65A9B2915D9A055A407BC0698936349A04E3DB691E178419FBA701AAD8DE55|
Required Sig: |1788D84AA61EDE6F2E96CFC900AD1CAB1C5BE86537F27212E8C291D6ADE3B1E9|
Required Sig: |6A0E824654B7479152058CF738A378E629483874B6DBD67E0D8C3327B2FCAC64|
Required Sig: |BB4919D8F38DBA90154F963C47BE83B665076C6EB4B230B3CEE91E4B7706CC12|
Required Sig: |15DD2FF6416858790A5241C335F675540750F611110A5D2D67B4517D08260AF9|
Required Sig: |B1BC5EF4F5C7E8F683601217650F42E7D69EFC0098C22A4989C7990B7771C277|
Required Sig: |39E7DA89CA9899B8CA2CB826D7FD910E525AC9E6784D54D8316E00650156A341|
Required Sig: |20082B6101F8D7DADE206F4FDEB367622C11F809C4CF2D215D834460179EF2DD|
Required Sig: |1E73F9DCF231163C9B99C9632B0C379B94209B068EDA8945951F125EDD6ACC9F|
Required Sig: |08D13A5AB1795D47A3830FB3E34437882514E0FFC9BCEE122227C354D29FFD1D|
Required Sig: |9E531D100AC08C28833FAD3CA5D3B863BD1323D2F118F83D9DB2B21407CA9E64|
Required Sig: |73782E2981C4EED10CA0170DD06B2ADF54B1B6E95112FC60DB610C1039E3931A|
Required Sig: |4561A888723EF5D879B44B02144125C9566D4FC7C674EE5A6E3246E6457F3DF9|
Required Sig: |DB34CFA2F5239656EFEB51537A7EACB98AEC10ED2B40209C0F50DCD3DF6B50CD|
Required Sig: |0690EADBD2302957BF7912C2851C33463C855C10AD226A11BBFDC8D69D8A14B3|
Required Sig: |FA0D9315715290276F4558DAC2368BD828789F42214F5707A932E5C518E59F80|
Required Sig: |9B4BF870DCB0610A34E441D32669DCCE2ABE5E697C67B7C4328A891397F4DB0C|
Required Sig: |F41DA7DEB9A214E653F738BBF4DC9168C606E71E8095E7D50215B0DCC2CF71A3|
Required Sig: |48BEFA8CAB6DBE7493EDE483396BB41BA9D46594606174B7FBCA3C0D17E2B6AA|
Required Sig: |6CCA75EA065B35B9AAC96999DC3A4254CDE518139169C4BD160797F8E63E29ED|
Required Sig: |109C91802D4EECA88BF607CBFA6A67449CC63F6E6E9BD0BE6B20EED263420C04|
Required Sig: |E261C78511A77E74801F273919B0852BF44A31BC0600D188C535D88BE7ABA052|
Required Sig: |D12924557C7E2714A9C77F64D6CD391FDD6509FC138CCDE16512EF226D15FA7F|
Required Sig: |6C611BD22926D8778F0A6B0A095A839D6BBC40D5AD23F55B9F8560647361FFC7|
Required Sig: |080A627E31BDC90041AD30B5604DE9EAE8C85ABDB621B5B55D25CD13ED182D06|
Required Sig: |8A6E68D85AB00FD79783BFB955CF989BD1938F02DC57E371FB07EB1FAAF55901|
Required Sig: |28412FA02802A3939A709F518798404582FF601E67EA9C542C78963F2EAE18FF|
Required Sig: |EE606FA2CD686DB7554C99C4BB37D87E64F89153EF26B4CFF41834DA74EB4C1C|
Required Sig: |136089AB3A7DC68C19F139558F0644DC57D32E9CEB79D6E54D9D6492AD2DE614|
Required Sig: |F5A5415ACA106C63AA6595D58861F8D7E87143BA9C742E2E2819E3411D685496|
Required Sig: |DECF57D609F02AB417FE4DA0D96EE4388181A3C6593083AE57C5DF05F5F918F3|
Required Sig: |1E91FC3FEE40BB2B6077F7E9A31F26C2E887CE91B41E5268EE795BE53F11329B|
Required Sig: |FF6ACFBD5962499FB8846DAF87B88320C115D7711EA645BA6742E8598E884BD8|
Required Sig: |8C1EDB6A3F46D13CC6E58F6D2C7EFD958EC079AA029478BABA9AA9F53DB9F0E3|
Required Sig: |5E41B89F7F471806E1917EFDD040953CC22F3F362E7B71423FF70E55B98ADB13|
Required Sig: |8CE986614E7037218A61DB51B876341898817741ADE85156CF54BD1CD17999A6|
Required Sig: |D9247336AC0D12CABF04DFD88227D1E640C0DC59739BD5B3CA17DF90B3331C3B|
Required Sig: |ECB789C173E1FA4E604FF45A57A45B2868D8ACB1CE616D8AEEF08D5E252CCD6F|
Required Sig: |4AA5F09F5022EEFBEE350D0DED72654D21A9E77DEEC49FEFB45994708BE11703|
Required Sig: |ACD9B08302C0FA9C87D14920BEEE724B92144774DC095A22EE5D8F023E80D677|
Required Sig: |7AC0BD56947B20B82303E2F47D4876540989872EC39D08DAF5635240B5EE7E9F|
Required Sig: |2D59C29B059FE54A4F218BE5B1F37723BE29BA47CCDDF07FDEE604ECC57B3F62|
Required Sig: |E427068FBA7A44C96515C47E9871798284A06397D4C8687DFDAFD0738026DDBB|
Required Sig: |CDB7C90D3AB8833D5324F5D8516D41FA990B9CA721FE643FFFAEF9057D9F9E48|
Required Sig: |C54A4060B3A76FA045B7B60EAEBC8389780376BA3EF1F63D417BA1B55BE3A093|
Required Sig: |CBFA2A86144EB21D65A6B17245BAD4F73058436C7292BE56DC6EBAB29DA61606|
Required Sig: |9D7E7174C281C6526B44C632BAA8C3320ADD0C77DC90778CC148938829F45E5E|
Required Sig: |9B1F35052CFC5FB06DAB5E8F7B47F081DA28D722DB59ADE253B9E38AB5A19847|
Required Sig: |E3C5E55E84371D3F2FBCA2241EF0711FF80876EBF71BAB07D8E6E45AAA8B45AF|
Required Sig: |EE093913ABBD3D4CB85EA31375179A8B55A298353C03AFE5055AA4E8EBD10EC2|
Required Sig: |B4E1880425F7857B741B921D04FD9276130927CF90A427C454B970E7A28EB88B|
Required Sig: |CDA0B4A59390B36E1B654850428CBB5B4C7B5E4349E87ACDE97FB5437D64D9FC|
Required Sig: |C87EFD057497F90321D62A69B311912BE8EF8A045FE9C5E6BD5C8C1A41D6B295|
Required Sig: |9E19DD645235341A555DA6C065594543AE1E3918ECD37DF22DFEBE91E71C3A59|
Required Sig: |63F67824FDA998798964FF33B87441857DA92F3A8EE3E04166EEC315E6600FD1|
Required Sig: |0BC4F078388D41AB039F87AE84CF8D39302CCBDD70C4ADE02263EBFCE6DEF0F5|
Required Sig: |E2AEC271B9596A461EB6D54D8B1785E4E4C615CFAD5F4504BCC0A329433A9747|
Required Sig: |6B4328EBCBE46ED9118FF2D4472DE329D70BA83016DF7A6F50F8AF923883BC54|
Required Sig: |E14C88DC48339C0555686849A4E3F8986D558E65C4FC863A1A4F1D40478BD47C|
Required Sig: |D013BA511AEE89BA3285D1CAC0C9F4F21EF4810873C2EBBFFE7712BF0BE8CED3|


REQUIRED ACTION
===============
To REVOKE the [PCA 2011] cert, run the commands:

reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x282 /f
powershell Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

PS C:\Windows\system32>
 

My Computer

System One

  • OS
    Windows 10
    Computer type
    PC/Desktop
    Manufacturer/Model
    MSI/Z97M-G43(MS-7924)
    CPU
    i7-4790K@ 4000MHz
    Motherboard
    MSI Z97M-G43
    Memory
    32GB DDR3 @1600MHZ
    Graphics Card(s)
    XFX RS RX 480 8GB
    Sound Card
    Onboard
    Monitor(s) Displays
    Samsung
    Screen Resolution
    1920x1080
    Hard Drives
    2xSSD 1TB, 2x HDD 1TB
    PSU
    OCZ 700W
    Case
    Corsair Carbide
    Cooling
    Corsair 120mm
    Keyboard
    Philips Mecanic Blue Keys
    Mouse
    Generic
    Internet Speed
    500Mb
    Browser
    Chrome
    Antivirus
    Defender
foreach |False|
Exceção ao chamar "Substring" com "2" argumento(s): "startIndex não pode ser maior que o comprimento da cadeia de
caracteres.
Nome do parâmetro: startIndex"
No E:\Arquivados\Ferramentas\SecureBoot-260531\Check_UEFI-CA2023.ps1:771 caractere:5
+ $SVN = '{0}.{1}' -f [System.Convert]::ToUInt16($SignatureData.Sub ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : NotSpecified: (:) [], MethodInvocationException
+ FullyQualifiedErrorId : ArgumentOutOfRangeException
Thanks. I needed this part.
 

My Computer

System One

  • OS
    Windows 7
May 2026 Preview. Wonder if MS removed that entire reg subtree by design, or mistake.
Like I said, your 05/31 script runs just fine, just tested it, but not the ones you posted earlier.
 

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    HP
    CPU
    Gen 11 Core i5
    Memory
    16GB
Thanks. I needed this part.
I ran the new script and it doesn't seem to have changed the result.

Secure Boot: ON
Virtualization Based Security: OFF
BitLocker on (C:) OFF

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

UEFI DBX Certs
--------------

(NONE)
Exception when calling "Substring" with "2" argument(s): "startIndex cannot be greater than the length of the string.

Parameter name: startIndex"

No E:\Arquivados\Ferramentas\SecureBoot-260531\Check_UEFI-CA2023.ps1:771 character:5
+ $SVN = '{0}.{1}' -f [System.Convert]::ToUInt16($SignatureData.Sub ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : NotSpecified: (:) [], MethodInvocationException
+ FullyQualifiedErrorId : ArgumentOutOfRangeException

Windows BootMgr SVN .

EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.
Required Sig: |80B4D96931BF0D02FD91A61E19D14F1DA452E66DB2408CA8604D411F92659F0A|

Required Sig: |F52F83A3FA9CFBD6920F722824DBE40....

I asked Gemini for help and he gave me this instruction:
function Get-SignatureDataSVN {
param (
[Parameter(Mandatory)]

[string]$SignatureData

)

# IF THE STRING IS EMPTY OR SHORTER THAN THE REQUIRED LENGTH, RETURNS ZERO AND EXITS

if ([string]::IsNullOrEmpty($SignatureData) -or $SignatureData.Length -lt 42) {

return "0.0"

}

# secureboot_objects/scripts/utility_functions.py at main · microsoft/secureboot_objects

$SVN = '{0}.{1}' -f [System.Convert]::ToUInt16($SignatureData.Substring(40,2) + $SignatureData.Substring(38,2), 16), [System.Convert]::ToUInt16($SignatureData.Substring(36,2) + $SignatureData.Substring(34,2), 16)

return $SVN

}

I changed the script on the mentioned line using NotepadPP. Now I get: The output is error-free and like this, but I hope it's correct.

Secure Boot: ON
Virtualization Based Security: OFF
BitLocker on (C:) OFF

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

UEFI DBX Certs
--------------
(NONE)
Windows BootMgr SVN 0.0

EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.


REQUIRED ACTION
===============
To REVOKE the [PCA 2011] cert, run the commands:

reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x282 /f
powershell Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

PS C:\Windows\system32>
 

My Computer

System One

  • OS
    Windows 10
    Computer type
    PC/Desktop
    Manufacturer/Model
    MSI/Z97M-G43(MS-7924)
    CPU
    i7-4790K@ 4000MHz
    Motherboard
    MSI Z97M-G43
    Memory
    32GB DDR3 @1600MHZ
    Graphics Card(s)
    XFX RS RX 480 8GB
    Sound Card
    Onboard
    Monitor(s) Displays
    Samsung
    Screen Resolution
    1920x1080
    Hard Drives
    2xSSD 1TB, 2x HDD 1TB
    PSU
    OCZ 700W
    Case
    Corsair Carbide
    Cooling
    Corsair 120mm
    Keyboard
    Philips Mecanic Blue Keys
    Mouse
    Generic
    Internet Speed
    500Mb
    Browser
    Chrome
    Antivirus
    Defender
I asked Gemini for help and he gave me this instruction:
The real issue is finding what is passing a non-string value to the function. This code has been in place for months and has never failed before. Which points to something different about your UEFI data.

Try this version.
 

Attachments

My Computer

System One

  • OS
    Windows 7
This is what shows on mine with this script:



Secure Boot: ON
Virtualization Based Security: ON
BitLocker on (C:) ON

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
foreach |01612B139DD5598843AB1C185C3CB2EB92000007000000000000000000000000|
foreach |01612B139DD5598843AB1C185C3CB2EB92000002000000000000000000000000|
foreach |01612B139DD5598843AB1C185C3CB2EB92000008000000000000000000000000|
Windows BootMgr SVN 8.0
Get-ItemPropertyValue : Cannot find path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecureBoot\SBAT' because it does not
exist.
At C:\Users\Ralfy\Downloads\Check_UEFI-CA2023.ps1:890 char:37
+ ... = [byte[]](Get-ItemPropertyValue -Path 'HKLM:\SYSTEM\CurrentControlS ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : ObjectNotFound: (HKLM:\SYSTEM\Cu...SecureBoot\SBAT:String) [Get-ItemPropertyValue], Item
NotFoundException
+ FullyQualifiedErrorId : PathNotFound,Microsoft.PowerShell.Commands.GetItemPropertyValueCommand


EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

SkuSiPolicy.p7b is CURRENT.
Get-DBXUpdateSVN |01612B139DD5598843AB1C185C3CB2EB92000008000000000000000000000000|


STATUS REPORT
-------------
Registry: "UEFICA2023Status" = Updated

SUCCESS: UPDATES ARE FINISHED.
UEFI CA 2023 certs are present, PCA 2011 cert is revoked.
 

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    HP
    CPU
    Gen 11 Core i5
    Memory
    16GB
Back
Top Bottom