So, it looks like I need to search for another graphics card. The big questions now is: which one and will it work on this computer? The K2200 is one without need for a power cable. Hence no power supply in this computer that can give me power for a modern graphics card. By the looks of it, a new computer may be a better investment.
*******************************************************************************
hello,
-it seems i am in a pretty similar f**d situation; i have an ASUS pc from 2016 with a NVIDIA GeForce GT 720 graphic card with BIOS v 80.28.80.00.09 [UEFI] and driver v30.0.14.7514 (GeForce 475.14) from 2024 June------
-after make the update of the Secure Boot 2023 certs (thanks again to garlin), now comes this issue with the graphic card when the revocation comes (if i understand correctly..)
-i guess one possible and radical "solution" to keep using the pc, would be disable the Secure Boot in the BIOS with its inherent consequences; am i right?
best regards,
fernando
----------------------
PS C:\windows\system32> C:\Users\fbm\Desktop\Check_UEFI-CA2023.ps1 -Verbose
Windows 10 21H2 (19044.7548)
Secure Boot: ON
Virtualization Based Security: OFF
BitLocker on (C:) OFF
BIOS Firmware
-------------
ASUSTeK COMPUTER INC. M32CD_A_F_K20CD_K31CD
Version: 1102
Date: 2018-04-12
Factory Default UEFI PK Cert
----------------------------
ASUSTeK MotherBoard PK Certificate
UEFI PK Cert
------------
Windows OEM Devices PK
Factory Default UEFI KEK Certs
------------------------------
Microsoft Corporation KEK CA 2011
Canonical Ltd. Master Certificate Authority
ASUSTeK MotherBoard KEK Certificate
UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023
Factory Default UEFI DB Certs
-----------------------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Canonical Ltd. Master Certificate Authority
ASUSTeK MotherBoard SW Key Certificate
ASUSTeK Notebook SW Key Certificate
UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023
Factory Default UEFI DBX Certs
------------------------------
(NONE)
EFI_CERT_SHA256_GUID Signatures: 77
UEFI DBX Certs
--------------
(NONE)
Windows BootMgr SVN is MISSING.
EFI_CERT_SHA256_GUID Signatures: 445
UEFI Variables
--------------
SBAT (Linux only): sbat,1,2024010900 / shim,4 / grub,3 / grub.debian,4
EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\\.\HarddiskVolume6\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.342, SVN 9.0
Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.
REQUIRED ACTION
===============
To REVOKE the [PCA 2011] cert, run the commands:
reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x280 /f
powershell Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"