Solved garlin's PowerShell scripts for updating Secure Boot CA 2023


@wabbit I fixed your Rufus issue (same problem as Ventoy).

While the signing cert passed the sanity check, it failed the SVN test (since 3rd-party boot loaders have SVN = 0.0). I had to put special handling for non-Windows boot loaders.

Code:
USB Drive D: "ESD-ISO"
    Boot File [Microsoft Corporation UEFI CA 2011] is ALLOWED.
        D:\EFI\Boot\bootx64.efi
        [THIRD-PARTY] EFI File
I think we got it this time:

USB Drive E: "RUFUS_BOOT"
Boot File [Microsoft Corporation UEFI CA 2011] is ALLOWED.
E:\EFI\Boot\bootx64.efi
[THIRD-PARTY] EFI File
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2AMD Ryzen 9 7940HS32 GBRadeon 780M Graphics
    OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Geekom AX7 Pro
    CPU
    AMD Ryzen 9 7940HS
    Memory
    32 GB
    Graphics Card(s)
    Radeon 780M Graphics
    Monitor(s) Displays
    Dell S2425H 24"
    Screen Resolution
    1920 x 1080
    Hard Drives
    2 TB NVMe SSD
    Internet Speed
    100 Mbs
    Browser
    Microsoft Edge / Firefox
    Antivirus
    F-Secure Security Suite
    Other Info
    All secure boot certificates updated to CA 2023
    Windows Production PCA 2011 certificate has been revoked.
  • At a glance

    Windows 11 Pro 25H212th Gen Intel Core i7-12700 processor (12-Co...16 GBIntel(R) UHD Graphics 770 with shared graphic...
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Inspiron 3910
    CPU
    12th Gen Intel Core i7-12700 processor (12-Core, 25M Cache, 2.1GHz to 4.8GHz)
    Motherboard
    Dell 0KHP4K
    Memory
    16 GB
    Graphics card(s)
    Intel(R) UHD Graphics 770 with shared graphics memory
    Monitor(s) Displays
    Dell 27" Monitor S2721DS,
    Screen Resolution
    QHD 2560 x 1440 @ 75 Hz
    Hard Drives
    1TB M.2, PCIe NVMe, SSD
    Internet Speed
    100 Mbps
    Browser
    Edge
    Antivirus
    F-Secure Security Suite
    Other Info
    All secure boot certificates updated to CA 2023
    Windows Production PCA 2011 certificate has been revoked.
  • HP Laptop 15-fd0xxx
    OS: Windows 11 Home 25H2
    Processor: 13th Gen Intel(R) Core(TM) i7-1355U (1.70 GHz), 10 Cores, 12 Logical Processors
    BIOS Version: AMI F.26 4/22/2026
    RAM: 16 GB
    SSD: 1 TB
    Screen Resolution: 1920 x 1080
    All secure boot certificates updated to CA 2023 by factory.

My Computers My Computers

  • At a glance

    Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
And this is what I get, when I check a normal recovery drive USB-Stick, made with the recovery drive tool of windows 11 on my HP Z440 workstation, and using the check_media.ps1 in post 3,199:
PS C:\Users\admin\Downloads\SecureBoot-CA-2023-Updates.v2026.08.08> .\Check-Bootmedia.bat -Verbose
PowerShell 7.6.4
Windows 11 25H2 (26200.8973)

Secure Boot: ON
Virtualization Based Security: ON

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 9.0

EFI Files
---------
[OPTIONAL] SkuSiPolicy.p7b (for VBS) is MISSING.

Bootable Media
--------------

USB Drive J: "REINER-SCT"

USB Drive I: "RECOVERY"
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
I:\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.352, SVN 9.0

boot.wim:1 (WinRE 26100.1)
Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\Windows\Boot\EFI_EX\bootmgfw_EX.efi
File Version: 28000.352, SVN 9.0

\Windows\System32\winload.efi is ALLOWED.
File Version: 26100.8875


PS C:\Users\admin\Downloads\SecureBoot-CA-2023-Updates.v2026.08.08>


And the rufus-made, install windows 11 USB-stick gives this:

PS C:\Users\admin\Downloads\SecureBoot-CA-2023-Updates.v2026.08.08> .\Check-Bootmedia.bat -Verbose
PowerShell 7.6.4
Windows 11 25H2 (26200.8973)

Secure Boot: ON
Virtualization Based Security: ON

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 9.0

EFI Files
---------
[OPTIONAL] SkuSiPolicy.p7b (for VBS) is MISSING.

Bootable Media
--------------

USB Drive K: "Win11_25H2_EngUS_x64_18July2026"
Boot File [Windows UEFI CA 2023] is ALLOWED.
K:\EFI\Boot\bootx64.efi
File Version: 28000.352, SVN 9.0

boot.wim:2 (WinPE 26100.8873)
Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\Windows\Boot\EFI_EX\bootmgfw_EX.efi
File Version: 28000.352, SVN 9.0

\Windows\System32\winload.efi is ALLOWED.
File Version: 26100.8870

K:\EFI\Microsoft\Boot\boot.stl [18/05/2026 19:44] is CURRENT.

install.esd:1 (W11 25H2 26200.8873)
Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\Windows\Boot\EFI_EX\bootmgfw_EX.efi
File Version: 28000.352, SVN 9.0

\Windows\System32\winload.efi is ALLOWED.
File Version: 26100.8870

Skipping over the next 6 images.

USB Drive J: "REINER-SCT"

USB Drive I: "RUFUS_BOOT"
Boot File [Microsoft Corporation UEFI CA 2011] is ALLOWED.
I:\EFI\Boot\bootx64.efi
[THIRD-PARTY] EFI File


PS C:\Users\admin\Downloads\SecureBoot-CA-2023-Updates.v2026.08.08>
 

My Computer My Computer

At a glance

windows 11
OS
windows 11
The results from the latest Check_BootMedia.ps1 are all good with HBS USB & Ventoy, but not with an old Rufus created Win11 USB as drive F:

Bootable Media
--------------
Check-DriveVolume : Cannot bind argument to parameter 'DriveLetter' because it is an empty string.
At E:\Garlin\Check_BootMedia.ps1:2352 char:52
+ Check-DriveVolume -DriveLetter $Drive
+ ~~~~~~
+ CategoryInfo : InvalidData: (:) [Check-DriveVolume], ParameterBindingValidationException
+ FullyQualifiedErrorId : ParameterArgumentValidationErrorEmptyStringNotAllowed,Check-DriveVolume
 

My Computer My Computer

At a glance

Windows 11 ProIntel Core Ultra16GBIntel(R) Arc Graphics
OS
Windows 11 Pro
Computer type
Laptop
Manufacturer/Model
ASUS Zenbook 14 OLED
CPU
Intel Core Ultra
Memory
16GB
Graphics Card(s)
Intel(R) Arc Graphics
Sound Card
Realtek High Definition Audio(SST)
Screen Resolution
2880 x 1800
Hard Drives
500 GB NVMe SSD
Internet Speed
1,500Mbps
Browser
Firefox, Edge
Antivirus
Windows Defender
That's what I get on audit:

"UEFICA2023Status" = Updated SUCCESS: UPDATES ARE FINISHED. UEFI CA 2023 certs are present, PCA 2011 cert is revoked

However, get-tpm command still returns me RestartPending: True.

Also, in Event Viewer I get the same error SubmitV2Attestation: Bad Request
{"Message":"V2 Protocol AIK certificate requests with P-256 ECC public keys are not supported. Public key algorithm: 1.2.840.10045.2.1, Key length: 256."}


I guess there's nothing more I can do on my side? According to provided scripts and audit it's all fine. In BIOS I set SecureBoot to Standard (instead of Custom which was there for some reason). I get zero other issues upon check-up.
 

My Computer My Computer

At a glance

Windows 11 24H2i7-1070032 GBNVIDIA RTX 3070
OS
Windows 11 24H2
Computer type
PC/Desktop
Manufacturer/Model
Zotac ZBOX-ECM73070C
CPU
i7-10700
Memory
32 GB
Graphics Card(s)
NVIDIA RTX 3070
PSU
500W
However, get-tpm command still returns me RestartPending: True.

Also, in Event Viewer I get the same error SubmitV2Attestation: Bad Request
{"Message":"V2 Protocol AIK certificate requests with P-256 ECC public keys are not supported. Public key algorithm: 1.2.840.10045.2.1, Key length: 256."}


I guess there's nothing more I can do on my side? According to provided scripts and audit it's all fine. In BIOS I set SecureBoot to Standard (instead of Custom which was there for some reason). I get zero other issues upon check-up.
TPM errors are unrelated to Secure Boot certs. Windows will post Secure Boot events through the TPM-WMI logging channel, because there isn't a separate channel for itself.

I suspect you're also getting the Event 87 SCEP errors which started after last month's update. This is an ongoing issue that a lot of users are reporting, which will probably require a BIOS or Windows fix.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Correction, he can probably recite it by memory !
The shared article in question is a technical guide for OEM's. It contains no practical instructions for end-users. Some Secure Boot references mostly talk about what the keys are, how they're suppose to work, but don't actually go into the actual deployment or verification.

The only handy feature about the page is MS provides download links for the cert files, in case you want to do manual enrollment.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
TPM errors are unrelated to Secure Boot certs. Windows will post Secure Boot events through the TPM-WMI logging channel, because there isn't a separate channel for itself.

I suspect you're also getting the Event 87 SCEP errors which started after last month's update. This is an ongoing issue that a lot of users are reporting, which will probably require a BIOS or Windows fix.
Yes you're right, i get this errors as users are reporting. However I thought it was related to old certificate revoke or smth. Since I used suggested tools to fix all issues but still got this errors, I thought it's still something on my side. But I guess I will just wait for Microsoft to fix this.
 

My Computer My Computer

At a glance

Windows 11 24H2i7-1070032 GBNVIDIA RTX 3070
OS
Windows 11 24H2
Computer type
PC/Desktop
Manufacturer/Model
Zotac ZBOX-ECM73070C
CPU
i7-10700
Memory
32 GB
Graphics Card(s)
NVIDIA RTX 3070
PSU
500W
The shared article in question is a technical guide for OEM's. It contains no practical instructions for end-users. Some Secure Boot references mostly talk about what the keys are, how they're suppose to work, but don't actually go into the actual deployment or verification.

The only handy feature about the page is MS provides download links for the cert files, in case you want to do manual enrollment.
It was obviously a joke, I have no intention of getting into building my own certificates.
And if I need any info or guidance on Secure Boot certificates, I use this web site: Complete Guide on Secure Boot
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Just for the reference. On my second PC which doesn't have a proper BIOS update from manufacturer, I got an audit report that i need to "manually update BIOS" due to DO_NOT_TRUST issue.

However, upon checking event viewer and registry my keys were succesfully registered and the status is "Updated", Capable =2 and etc. Meaning my PC is performing proper secure boot. Yet the script tells me to update... Hm...
 

My Computer My Computer

At a glance

Windows 11 24H2i7-1070032 GBNVIDIA RTX 3070
OS
Windows 11 24H2
Computer type
PC/Desktop
Manufacturer/Model
Zotac ZBOX-ECM73070C
CPU
i7-10700
Memory
32 GB
Graphics Card(s)
NVIDIA RTX 3070
PSU
500W
BIOS'es shipped with "DO NOT TRUST" Platform Keys work perfectly fine, in the sense that they accept all Secure Boot updates.

But the general community of Windows and BIOS security experts consider these PC's as highly susceptible to outside attack, because they all share the exact same PK instead of having the OEM create their own unique PK. When an OEM licenses a BIOS from a provider (AMI, Insyde, etc.), they're provided with a reference build for training purposes.

Thus the example code says "DO NOT TRUST". It's only intended for internal testing, and never for production code. But guess what? OEM's are idiots and people shipped the same PK in their released firmware. So if you figure out how to break the PK, or suspect one of the many OEM had an internal hack where the private signing key was leaked, then attackers can defeat the "DO NOT TRUST" PK.

What's the simple solution? For someone to actually follow "how to make your own PK" procedure and use that instead of just copying the reference example everyone else received. That's the whole basis of Secure Boot security, every vendor has an unique PK. And within some vendors, like Dell, HP or Lenovo, they may have several generations of PK's that are not the same across their different PC product lines.


TLDR: "DO NOT TRUST" works fine in a CA 2023 environment. But nobody in the security world trusts it can't be hacked. So if you care about those things, then you replace the "DO NOT TRUST". Some vendors like Dell went back, and re-released BIOS with a different PK. Others never bothered.

To replace this default PK, you can temporarily disable Secure Boot and delete all keys. Run the update script, and it will replace all of your keys with a MS reference example. [But wait, aren't they all the same keys from one source? Yes, but nobody thinks the Windows OEM PK has been hacked].

It's optional. But my script checks for "DO NOT TRUST" as a public service warning.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Great! Thanks for explanation. I will keep it in mind.
 

My Computer My Computer

At a glance

Windows 11 24H2i7-1070032 GBNVIDIA RTX 3070
OS
Windows 11 24H2
Computer type
PC/Desktop
Manufacturer/Model
Zotac ZBOX-ECM73070C
CPU
i7-10700
Memory
32 GB
Graphics Card(s)
NVIDIA RTX 3070
PSU
500W
This is an ongoing issue that a lot of users are reporting, which will probably require a BIOS or Windows fix.
Not the BIOS, I would have to flash 4 of them and there all up to date, it's def. Microsoft borked up last month
 

My Computer My Computer

At a glance

Win11 24H2 IOT LTSC / Win11 Pro 25H2AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600GF5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB ...internal
OS
Win11 24H2 IOT LTSC / Win11 Pro 25H2
Computer type
PC/Desktop
Manufacturer/Model
Gigabyte x2 / Asus = Home builds
CPU
AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600G
Motherboard
Gigabyte B650 AORUS ELITE AX V2 / ASUS TUF GAMING B650-PLUS / B650 GAMING X AX V2
Memory
F5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB LD5BU016G-R6000GDLA 32GB / Kingston FURY Beast 32 GB DDR5-5600
Graphics Card(s)
internal
Sound Card
Realtek
Monitor(s) Displays
BenQ 27 L EW2780
Screen Resolution
1920x1080
Hard Drives
Many M.2's (WD)
PSU
be quiet! Pure Power 13 M 550W
Case
Chieftec HC-10B-OP
Cooling
Gelid Solutions Tranquillo 5, many Noctua's 12x12
Keyboard
Microsoft
Mouse
Cherry
Internet Speed
500 mbs
Browser
Vivaldi
Antivirus
Eset
Other Info
PC builder / repair / Trouble-shooter etc.
@garlin I guess I need more education " I suspect you're also getting the Event 87 SCEP errors which started after last month's update. This is an ongoing issue that a lot of users are reporting, which will probably require a BIOS or Windows fix"

Where in the Event Viewer are you all seeing this Event "87" I don't see it in System or "application" in Windows logs section
 

My Computer My Computer

At a glance

Windows 11 Intel i5 10400 HD630 graphics chipi5-1040012 gbHD630 chipset
OS
Windows 11 Intel i5 10400 HD630 graphics chip
Computer type
PC/Desktop
Manufacturer/Model
HP
CPU
i5-10400
Memory
12 gb
Graphics Card(s)
HD630 chipset
Monitor(s) Displays
LG 24inch
Hard Drives
SSD, external usb drive 1tb for files/backups
Keyboard
wireless Logi
Mouse
ms 4000 wireless mouse
Internet Speed
10meg
Browser
Firefox
Antivirus
Defender
Other Info
Win11 Home 25h2 26200.8973 07/28/2026
Windows Key + R, type compmgmt.msc (press Ctrl + Shift + Enter to run with full admin rights)

Look under you Event Viewer / Custom Views / Administrative Events for Event 87
 

My Computer My Computer

At a glance

Win11 24H2 IOT LTSC / Win11 Pro 25H2AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600GF5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB ...internal
OS
Win11 24H2 IOT LTSC / Win11 Pro 25H2
Computer type
PC/Desktop
Manufacturer/Model
Gigabyte x2 / Asus = Home builds
CPU
AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600G
Motherboard
Gigabyte B650 AORUS ELITE AX V2 / ASUS TUF GAMING B650-PLUS / B650 GAMING X AX V2
Memory
F5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB LD5BU016G-R6000GDLA 32GB / Kingston FURY Beast 32 GB DDR5-5600
Graphics Card(s)
internal
Sound Card
Realtek
Monitor(s) Displays
BenQ 27 L EW2780
Screen Resolution
1920x1080
Hard Drives
Many M.2's (WD)
PSU
be quiet! Pure Power 13 M 550W
Case
Chieftec HC-10B-OP
Cooling
Gelid Solutions Tranquillo 5, many Noctua's 12x12
Keyboard
Microsoft
Mouse
Cherry
Internet Speed
500 mbs
Browser
Vivaldi
Antivirus
Eset
Other Info
PC builder / repair / Trouble-shooter etc.
There's a few threads on ElevenForum where users are complaining about it. Other forums are reporting it too.
SCEP Errors Too Many Requests Code 87

In the TPM, there's a set of HW security keys. Windows will sometimes try to connect to an outside Certificate Authority to confirm a key's validity (whether it should be revoked). After July, many users see Event ID 87 errors, reporting their PC is unable to get a working response from MS.

To date, I haven't heard a solid technical explanation for what's happening. There's only a handful of industry experts or security researchers that know how the TPM internals really work. And they're not sharing any clues on what's going on.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Windows Key + R, type compmgmt.msc (press Ctrl + Shift + Enter to run with full admin rights)

Look under you Event Viewer / Custom Views / Administrative Events for Event 87
Thanks, that is where I was looking but guess I'm lucky I'm not seeing '87' , strange thing is being able to 'filter custom view / task' is grayed out.
 

My Computer My Computer

At a glance

Windows 11 Intel i5 10400 HD630 graphics chipi5-1040012 gbHD630 chipset
OS
Windows 11 Intel i5 10400 HD630 graphics chip
Computer type
PC/Desktop
Manufacturer/Model
HP
CPU
i5-10400
Memory
12 gb
Graphics Card(s)
HD630 chipset
Monitor(s) Displays
LG 24inch
Hard Drives
SSD, external usb drive 1tb for files/backups
Keyboard
wireless Logi
Mouse
ms 4000 wireless mouse
Internet Speed
10meg
Browser
Firefox
Antivirus
Defender
Other Info
Win11 Home 25h2 26200.8973 07/28/2026
@TheVisitor Could you post a screen shot of that, not sure what you are seeing
 

My Computer My Computer

At a glance

Win11 24H2 IOT LTSC / Win11 Pro 25H2AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600GF5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB ...internal
OS
Win11 24H2 IOT LTSC / Win11 Pro 25H2
Computer type
PC/Desktop
Manufacturer/Model
Gigabyte x2 / Asus = Home builds
CPU
AMD Ryzen 7 8700G / Ryzen 7 8700G / Ryzen 8600G
Motherboard
Gigabyte B650 AORUS ELITE AX V2 / ASUS TUF GAMING B650-PLUS / B650 GAMING X AX V2
Memory
F5-6000J3636F16GX2-FX5 32GB / Lexar Ares RGB LD5BU016G-R6000GDLA 32GB / Kingston FURY Beast 32 GB DDR5-5600
Graphics Card(s)
internal
Sound Card
Realtek
Monitor(s) Displays
BenQ 27 L EW2780
Screen Resolution
1920x1080
Hard Drives
Many M.2's (WD)
PSU
be quiet! Pure Power 13 M 550W
Case
Chieftec HC-10B-OP
Cooling
Gelid Solutions Tranquillo 5, many Noctua's 12x12
Keyboard
Microsoft
Mouse
Cherry
Internet Speed
500 mbs
Browser
Vivaldi
Antivirus
Eset
Other Info
PC builder / repair / Trouble-shooter etc.
Back
Top Bottom