Solved garlin's PowerShell scripts for updating Secure Boot CA 2023


VERBOSE: Perform operation 'Enumerate CimInstances' with following parameters, ''className' = Win32_ComputerSystem,'namespaceName' = root\cimv2'.
VERBOSE: Operation 'Enumerate CimInstances' complete.
InvalidOperation: C:\Users\Public\Public Scripts\SecureBoot-Scripts\SecureBoot-CA-2023-Latest\Update_UEFI-CA2023.ps1:1749
Line |
1749 | '*LENOVO*M700*' { $Unsafe_Model = $true }
| ~~~~~~~~~~~~~~~
| The regular expression pattern *LENOVO*M700* is not valid.
VERBOSE: Perform operation 'Enumerate CimInstances' with following parameters, ''className' = Win32_OperatingSystem,'namespaceName' = root\cimv2'.
VERBOSE: Operation 'Enumerate CimInstances' complete.
VERBOSE: Perform operation 'Enumerate CimInstances' with following parameters, ''className' = Win32_DeviceGuard,'namespaceName' = root\Microsoft\Windows\DeviceGuard'.
VERBOSE: Operation 'Enumerate CimInstances' complete.
VERBOSE: Firmware SVN (from DBX): 9.0
VERBOSE: Using specified boot manager: \\.\HarddiskVolume1\EFI\Microsoft\Boot\bootmgfw.efi
VERBOSE: Boot Manager SVN: 9.0
VERBOSE: Staged SVN: 9.0
VERBOSE: Compliance Status: Compliant (Boot Manager SVN meets staged SVN)
Successfully appended "DBUpdateOROM2023.bin" to UEFI DB.
Get-ItemPropertyValue: C:\Users\Public\Public Scripts\SecureBoot-Scripts\SecureBoot-CA-2023-Latest\Update_UEFI-CA2023.ps1:1547
Line |
1547 | … Integrity = Get-ItemPropertyValue -Path 'HKLM:\Software\Policies\Micr …
| ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
| Property HypervisorEnforcedCodeIntegrity does not exist at path HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\DeviceGuard.
Applying SBAT update for Linux.

REQUIRED ACTION
---------------
Restart Windows, for UEFI updates to take effect.

PS C:\Users\Public\Public Scripts\SecureBoot-Scripts\SecureBoot-CA-2023-Latest>

From my 2025 Asus Rog Strix G16
 

My Computer My Computer

At a glance

Windows 11 & Zorin ProIntel® Core™ Ultra 9 Processor 275HX 2.7 GHz32 gbNVIDIA® GeForce RTX™ 5060 Laptop GPU
OS
Windows 11 & Zorin Pro
Computer type
Laptop
Manufacturer/Model
Asus Rog Strix G16
CPU
Intel® Core™ Ultra 9 Processor 275HX 2.7 GHz
Motherboard
AsusteK Computer
Memory
32 gb
Graphics Card(s)
NVIDIA® GeForce RTX™ 5060 Laptop GPU
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Laptop 16 inch
Screen Resolution
2560 X 1600
Hard Drives
Boot: Samsung 9100 NVME 2 TB Microsoft Storage Controller: Standard NVM Express Driver: Microsoft 6/21/2006. No SATA/AHCI on my motherboard or in bios
Mouse
Pad
Browser
Google Chrome
Antivirus
Microsoft
Other Info
Printer: HP Color LaserJet MFP M477dw
InvalidOperation: C:\Users\Public\Public Scripts\SecureBoot-Scripts\SecureBoot-CA-2023-Latest\Update_UEFI-CA2023.ps1:1749
Line |
1749 | '*LENOVO*M700*' { $Unsafe_Model = $true }
| ~~~~~~~~~~~~~~~
| The regular expression pattern *LENOVO*M700* is not valid.
This is a known bug (but doesn't impact the script).

Get-ItemPropertyValue: C:\Users\Public\Public Scripts\SecureBoot-Scripts\SecureBoot-CA-2023-Latest\Update_UEFI-CA2023.ps1:1547
Line |
1547 | … Integrity = Get-ItemPropertyValue -Path 'HKLM:\Software\Policies\Micr …
| ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
| Property HypervisorEnforcedCodeIntegrity does not exist at path HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\DeviceGuard.
Some instances of Get-ItemPropertyValue don't ignore an error when a queried reg key doesn't exist on the system. I'll add another fix.
Thanks.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Thank you for your all your help and scripts. I've successfully updated a 2013 Dell 8700 and two 2018 Intel Nucs 8i5 & 8i7 to 2023 Windows certs. I used your CA2023 update script to obtain new certs from github. No issues with any of them. Intel Nucs have Intel Visual Bios which is the best example of a GUI bios that I've ever seen.
 

My Computer My Computer

At a glance

Windows 11 & Zorin ProIntel® Core™ Ultra 9 Processor 275HX 2.7 GHz32 gbNVIDIA® GeForce RTX™ 5060 Laptop GPU
OS
Windows 11 & Zorin Pro
Computer type
Laptop
Manufacturer/Model
Asus Rog Strix G16
CPU
Intel® Core™ Ultra 9 Processor 275HX 2.7 GHz
Motherboard
AsusteK Computer
Memory
32 gb
Graphics Card(s)
NVIDIA® GeForce RTX™ 5060 Laptop GPU
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Laptop 16 inch
Screen Resolution
2560 X 1600
Hard Drives
Boot: Samsung 9100 NVME 2 TB Microsoft Storage Controller: Standard NVM Express Driver: Microsoft 6/21/2006. No SATA/AHCI on my motherboard or in bios
Mouse
Pad
Browser
Google Chrome
Antivirus
Microsoft
Other Info
Printer: HP Color LaserJet MFP M477dw
For your information: yesterday I checked the laptop of a friend, a Lenovo E595 thinkpad (20NF0000GE), bought in Jan 2020, and happily I can say it received the new secure boot certificates automatically. Using the Garlin scripts I checked and everything was fine.

Having read this article <Microsoft admits it can't fix Windows 11 Secure Boot problems, and older PCs are hit hardest> the updates of the secure boot certificates are a true mess, and the MS and the OEM's dropped the ball completely on this one. Hence, a big thank you to Garlin for his continued support and scripts. Much appreciated.
 

My Computer My Computer

At a glance

windows 11
OS
windows 11
UPDATE: 2026-07-24

1. Check for presence and correct version of \EFI\Microsoft\Boot\boot.stl on removable media
2. Check Macrium WinRE and Hasleo WADK staging folders for the correct Windows boot manager
3. Add Samsung 300E4C/300E5C/300E7C to the unsafe list
4. Exception created when "HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\DeviceGuard" is missing

After the June 2026 CU, MS recommends a current version of boot.stl be copied to your boot media. The check script will inform you when boot.stl is missing, or the wrong version. Update-UEFI.bat -BootMedia will push the boot.stl if required.

If you're using Macrium or Hasleo backup software, "-BootMedia" will now check the boot file versions in the app's WinPE or WinRE cache folders. This provides a clue if you're about to make a new recovery USB drive that may be banned from booting. Typically it's because the cache folder has an outdated version of WinPE or WinRE.

In the different Macrium or Hasleo threads, there's some discussion about manually copying the latest version of bootmgfw.efi or bootx64.efi into the cache folders, so you don't have to wait for Macrium or Hasleo to catch up.

Fixed the dreaded "Lenovo M700" reporting bug. As I didn't have the actual model string, I had to guess what it might looked on a real M700. But I found different M700 models listed in the HighConfidenceBucket CSV's, so we can avoid some questionable regex matching.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
This is nit picking but lots of new pc's have this status. :-)

PS C:\Users\Public\Public Scripts\SecureBoot-Scripts\SecureBoot-CA-2023-Latest> .\Check_UEFI-CA2023.ps1 -Audit -Verbose
Windows 11 25H2 (26200.8894)

Secure Boot: ON
Virtualization Based Security: ON
BitLocker on (C:) OFF

BIOS Firmware
-------------
ASUSTeK COMPUTER INC. ROG Strix G16 G615LM_G615LM
Version: G615LM.338
Date: 2026-06-03

Factory Default UEFI PK Cert
----------------------------
ASUS Secure Boot PK

UEFI PK Cert
------------
ASUS Secure Boot PK

Factory Default UEFI KEK Certs
------------------------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023
ASUS Secure Boot KEK

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023
ASUS Secure Boot KEK

Factory Default UEFI DB Certs
-----------------------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft UEFI CA 2023
Windows UEFI CA 2023
ASUS Secure Boot DB

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft UEFI CA 2023
Windows UEFI CA 2023
ASUS Secure Boot DB

Factory Default UEFI DBX Certs
------------------------------
(NONE)
EFI_CERT_SHA256_GUID Signatures: 371

UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 9.0
EFI_CERT_SHA256_GUID Signatures: 447

UEFI Variables
--------------
Credential Guard: ON

EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.352, SVN 9.0

Registry: "WindowsUEFICA2023Capable" = 2
WIndows UEFI [CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

SkuSiPolicy.p7b is CURRENT.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\SkuSiPolicy.p7b
Version: 3.0.0.16


AUDIT REPORT
============

I revoked the 2011 certs to ensure that it would still run... I'm not happy with Microsoft or Asus. I'm sure I will have lots of company,

1. [Microsoft Option ROM UEFI CA 2023] is missing from UEFI DB (This is not an option when waiting for Confidence Level Under Observation
new firmware and bios. 1801 error in Event Manager.

REQUIRED ACTION
===============
To install [UEFI CA 2023] certs, run the commands: Certs are installed but in a 'not finished' state.

reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REGCert_DWORD /d 0x4800 /f
powershell Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"
 
Last edited:

My Computer My Computer

At a glance

Windows 11 & Zorin ProIntel® Core™ Ultra 9 Processor 275HX 2.7 GHz32 gbNVIDIA® GeForce RTX™ 5060 Laptop GPU
OS
Windows 11 & Zorin Pro
Computer type
Laptop
Manufacturer/Model
Asus Rog Strix G16
CPU
Intel® Core™ Ultra 9 Processor 275HX 2.7 GHz
Motherboard
AsusteK Computer
Memory
32 gb
Graphics Card(s)
NVIDIA® GeForce RTX™ 5060 Laptop GPU
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Laptop 16 inch
Screen Resolution
2560 X 1600
Hard Drives
Boot: Samsung 9100 NVME 2 TB Microsoft Storage Controller: Standard NVM Express Driver: Microsoft 6/21/2006. No SATA/AHCI on my motherboard or in bios
Mouse
Pad
Browser
Google Chrome
Antivirus
Microsoft
Other Info
Printer: HP Color LaserJet MFP M477dw
This is nit picking but lots of new pc's have this status. :-)

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft UEFI CA 2023
Windows UEFI CA 2023
ASUS Secure Boot DB
AUDIT REPORT
============
1. [Microsoft Option ROM UEFI CA 2023] is missing from UEFI DB (This is not an option when waiting for Confidence Level Under Observation
new firmware and bios. 1801 error in Event Manager.

REQUIRED ACTION
===============
To install [UEFI CA 2023] certs, run the commands: Certs are installed but in a 'not finished' state.

reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REGCert_DWORD /d 0x4800 /f
powershell Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"
This another example of "left hand of MS doesn't talk to its right hand".

Option ROM is considered optional, since your PC may not have any HW devices which have their own signed firmware. Typically that's some NVIDIA graphics card or a Thunderbolt storage controller. Does it hurt to install it? Probably not.

But TPM-WMI keeps throwing "errors" like it's supposed to be present. And if you don't have Option ROM, then Security Center doesn't give you the best possible rating. While it's optional, my opinion is to install it so Windows stops throwing these warnings. Technically they're informative messages, but everything gets categorized by TPM-WMI as a "serious problem".

Sometimes the trouble is because 0x4000 value added to AvailableUpdates is interpreted as "don't add Option ROM CA 2023" unless your BIOS already had the Option ROM 2010. And not surprisingly, some older PC's don't never had the Option ROM 2010 and so the update fails when 0x4000 is used.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
i got this. i have never used Macrium.
1784916665430.webp
 

My Computer My Computer

At a glance

Windows 11 Pro 64bit (release preview channel)i5 840016 GB DDR4RTX 3060 Ti
OS
Windows 11 Pro 64bit (release preview channel)
Computer type
PC/Desktop
Manufacturer/Model
Asus
CPU
i5 8400
Motherboard
ROG STRIX Z370-H GAMING
Memory
16 GB DDR4
Graphics Card(s)
RTX 3060 Ti
Sound Card
On Board
Monitor(s) Displays
Acer VG242Y P
Screen Resolution
1080p
Hard Drives
Intel 660p SSD
PSU
800w
Internet Speed
1000 Mbps

My Computer My Computer

At a glance

Windows 11 Pro 64bit (release preview channel)i5 840016 GB DDR4RTX 3060 Ti
OS
Windows 11 Pro 64bit (release preview channel)
Computer type
PC/Desktop
Manufacturer/Model
Asus
CPU
i5 8400
Motherboard
ROG STRIX Z370-H GAMING
Memory
16 GB DDR4
Graphics Card(s)
RTX 3060 Ti
Sound Card
On Board
Monitor(s) Displays
Acer VG242Y P
Screen Resolution
1080p
Hard Drives
Intel 660p SSD
PSU
800w
Internet Speed
1000 Mbps
You fix one bug, and forgot you duplicated it somewhere else... I'll update the ZIP file after lunch.

UPDATE: 2026-07-24
Fixed new bug when you don't have Macirum installed.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Thank you !!!
 

My Computer My Computer

At a glance

Windows 11 Pro x64 Version V23H2i7-8700KG.Skill Trident Z 3200MHz F4-3200C16D-16GTZ (...Intel UHD Graphics 630
OS
Windows 11 Pro x64 Version V23H2
Computer type
PC/Desktop
Manufacturer/Model
Custom
CPU
i7-8700K
Motherboard
Asus Maximus X Code - Z370
Memory
G.Skill Trident Z 3200MHz F4-3200C16D-16GTZ (2) 32GB
Graphics Card(s)
Intel UHD Graphics 630
Sound Card
Integrated ROG SupremeFX
Monitor(s) Displays
Asus VP279 27", Samsung BX2431 24"
Screen Resolution
1920 x 1080
Hard Drives
Samsung M.2 NVMe 960 EVO 500GB Boot,
Samsung 840 EVO 250GB (System Copy Drive),
Samsung 860 EVO 1TB (Primary Data Drive),
WD Black 500GB (Data Copy Drive)
ICY Dock 5.25 2.5/3.5 Bays MB971SP-B
PSU
Corsair RM 650i +Gold
Case
Phanteks Enthroo Primo
Cooling
Corsair Hydro H150i, 360mm Rad & Five Corsair 140mm Pro ML Case Fans
Keyboard
das Keyboard MX Brown Mechanical Switches Model DASKMKPROSIL-3G7-r1.0
Mouse
Logitech MX Master 3 Wireless & Bluetooth
Internet Speed
500Mb +
Browser
Chrome (Pri), Firefox (Sec)
Antivirus
Malwarebytes Premium, SuperAntiSpyware Pro (Licensed)
Other Info
Microsoft LifeCam HD,
APC Back-UPS Pro 1500,
Macrium (Licensed),
Microsoft 365,
Wise Disk Cleaner,
Crystal Disk Info,
Screenpresso (Licensed),
AnyDesk (Licensed),
Back
Top Bottom