Solved garlin's PowerShell scripts for updating Secure Boot CA 2023


These days, there shouldn't be too many surprises except for late stragglers.

I imagine the real wave of panic will happen not on October 13, 2026 (which is a Patch Tuesday), but November 10, 2026. That is the first Patch Tuesday where MS can drop a boot manager which can only be signed by CA 2023, since PCA 2011 has already expired. October is the last chance under the old cert to have two signed versions.

After that you're stuck with presumably disabling Secure Boot mode. Those desperate users are probably the leftovers with the unsupported BIOS'es which are more likely to get bricked because of an unseen HW limitation.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 26200.9168Intel® Core™ i7-14700KG.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5ASUS GeForce RTX 4070 Super 12GB
    OS
    Win 11 Pro 25H2 26200.9168
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel® Core™ i7-14700K
    Motherboard
    ASUS TUF Z690-PLUS WIFI (BIOS 4505)
    Memory
    G.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5
    Graphics Card(s)
    ASUS GeForce RTX 4070 Super 12GB
    Sound Card
    Sound Blaster AE-5 Plus
    Monitor(s) Displays
    ASUS TUF Gaming 27" 2K HDR Gaming
    Screen Resolution
    2560 x 1440
    Hard Drives
    Samsung 990 Pro 1TB NVMe (Win 11 25H2)
    SK hynix P41 500GB NVMe
    SK hynix P41 2TB NVMe (x3)
    Crucial P3 Plus 4TB
    PSU
    Corsair RM850x Shift
    Case
    Antec Dark Phantom DP502 FLUX
    Cooling
    Corsair Nautilus 360 RS AIO
    Keyboard
    Logitech MK 320
    Mouse
    Razer Basilisk V3
    Internet Speed
    750Mbs
    Browser
    Firefox
    Antivirus
    Winows Security
    Other Info
    MR 8.1 Home
  • At a glance

    Win 11 Pro 25H2 26200.9168Intel Core i5-1140064 GB DDR4MSI GeForce RTX 3060 Ventus 2X 12GB
    Operating System
    Win 11 Pro 25H2 26200.9168
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel Core i5-11400
    Motherboard
    Asus TUF Gaming Z590 Plus WiFi (BIOS 2803)
    Memory
    64 GB DDR4
    Graphics card(s)
    MSI GeForce RTX 3060 Ventus 2X 12GB
    Sound Card
    SoundBlaster Audigy Fx V2
    Monitor(s) Displays
    Samsung F27T350
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 980 Pro 1TB
    Samsung 970 EVO Plus 2TB
    Samsung 870 EVO 500GB SSD
    PSU
    Corsair HX750
    Case
    Cougar MX330-G Window
    Cooling
    Thermalright Frozen Edge 240 Black AIO
    Internet Speed
    350Mbps
    Browser
    Firefox
    Antivirus
    Windows Security
  • System Three
    Win 11 Pro 25H2 26200.9168
    ASUS PRIME Z370-P II BIOS 3004 7/12/21
    Intel Core i7-8700 CPU @ 3.20GHz
    32GB DDR4 RAM (4x8)
    iGPU Intel UHD Graphics 630
    Cooler Master Hyper 212
    Mid-Tower Desktop
Microsoft late to the party as usual... Why not build the utility into the operating system before June? The average user has never heard of Powershell.
 
Last edited:

My Computers My Computers

  • At a glance

    Windows 11 & Zorin ProIntel® Core™ Ultra 9 Processor 275HX 2.7 GHz32 gbNVIDIA® GeForce RTX™ 5060 Laptop GPU
    OS
    Windows 11 & Zorin Pro
    Computer type
    Laptop
    Manufacturer/Model
    Asus Rog Strix G16
    CPU
    Intel® Core™ Ultra 9 Processor 275HX 2.7 GHz
    Motherboard
    AsusteK Computer
    Memory
    32 gb
    Graphics Card(s)
    NVIDIA® GeForce RTX™ 5060 Laptop GPU
    Sound Card
    Realtek High Definition Audio
    Monitor(s) Displays
    Laptop 16 inch
    Screen Resolution
    2560 X 1600
    Hard Drives
    Boot: Samsung 9100 NVME 2 TB Microsoft Storage Controller: Standard NVM Express Driver: Microsoft 6/21/2006. No SATA/AHCI on my motherboard or in bios
    Mouse
    Pad
    Browser
    Google Chrome
    Antivirus
    Microsoft
    Other Info
    Printer: HP Color LaserJet MFP M477dw
  • At a glance

    Windows 11 Pro, Zorin ProIntel Nuc 8i7, Intel Nuc 8i5Intel internal
    Operating System
    Windows 11 Pro, Zorin Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel
    CPU
    Intel Nuc 8i7, Intel Nuc 8i5
    Motherboard
    Intel
    Graphics card(s)
    Intel internal
    Monitor(s) Displays
    Dell U27
    Hard Drives
    Samsung 990 Pro
    Keyboard
    Dell USB
    Mouse
    Dell USB
    Antivirus
    Windows Defender
  • Dell 8500 Windows 10 Pro extended, Dell 8700 Windows 10 Pro extended , Hp Pavilion Linux
That's the script I use, always with the most recent ISO with updated boot files from UUPdump.

Skip the MS script and edit your ConvertConfig.ini, before running uup_download_windows.cmd.
It's been there for a while, but nobody tells you that.
Code:
UpdtBootFiles=1
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Microsoft late to the party as usual... Why not build the utility into the operating system before June? The average user has never heard of Poweshell.
The script is provided for IT pro's, who do their own updating of ISO's

Everyone else is supposed to use MCT to create ISO's or USB drives. MCT still doesn't have a positive method of confirming it's going to copy the newer boot files. Compare that to Rufus, which has a prominent check box in the options.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Skip the MS script and edit your ConvertConfig.ini, before running uup_download_windows.cmd.
It's been there for a while, but nobody tells you that.
Code:
UpdtBootFiles=1

Yes, that's exactly what I do. But why skip the script?
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 26200.9168Intel® Core™ i7-14700KG.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5ASUS GeForce RTX 4070 Super 12GB
    OS
    Win 11 Pro 25H2 26200.9168
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel® Core™ i7-14700K
    Motherboard
    ASUS TUF Z690-PLUS WIFI (BIOS 4505)
    Memory
    G.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5
    Graphics Card(s)
    ASUS GeForce RTX 4070 Super 12GB
    Sound Card
    Sound Blaster AE-5 Plus
    Monitor(s) Displays
    ASUS TUF Gaming 27" 2K HDR Gaming
    Screen Resolution
    2560 x 1440
    Hard Drives
    Samsung 990 Pro 1TB NVMe (Win 11 25H2)
    SK hynix P41 500GB NVMe
    SK hynix P41 2TB NVMe (x3)
    Crucial P3 Plus 4TB
    PSU
    Corsair RM850x Shift
    Case
    Antec Dark Phantom DP502 FLUX
    Cooling
    Corsair Nautilus 360 RS AIO
    Keyboard
    Logitech MK 320
    Mouse
    Razer Basilisk V3
    Internet Speed
    750Mbs
    Browser
    Firefox
    Antivirus
    Winows Security
    Other Info
    MR 8.1 Home
  • At a glance

    Win 11 Pro 25H2 26200.9168Intel Core i5-1140064 GB DDR4MSI GeForce RTX 3060 Ventus 2X 12GB
    Operating System
    Win 11 Pro 25H2 26200.9168
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel Core i5-11400
    Motherboard
    Asus TUF Gaming Z590 Plus WiFi (BIOS 2803)
    Memory
    64 GB DDR4
    Graphics card(s)
    MSI GeForce RTX 3060 Ventus 2X 12GB
    Sound Card
    SoundBlaster Audigy Fx V2
    Monitor(s) Displays
    Samsung F27T350
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 980 Pro 1TB
    Samsung 970 EVO Plus 2TB
    Samsung 870 EVO 500GB SSD
    PSU
    Corsair HX750
    Case
    Cougar MX330-G Window
    Cooling
    Thermalright Frozen Edge 240 Black AIO
    Internet Speed
    350Mbps
    Browser
    Firefox
    Antivirus
    Windows Security
  • System Three
    Win 11 Pro 25H2 26200.9168
    ASUS PRIME Z370-P II BIOS 3004 7/12/21
    Intel Core i7-8700 CPU @ 3.20GHz
    32GB DDR4 RAM (4x8)
    iGPU Intel UHD Graphics 630
    Cooler Master Hyper 212
    Mid-Tower Desktop
All the MS script does is add the same CA 2023 files to the ISO's boot folders. The rest is overhead fluff with mounting/unmounting boot.wim, and allowing you to create an USB using oscdimg.exe.

If you didn't know about the UpdtBootFiles option, you would need another tool to do the same task.

Anything like Make2023BootableMedia.ps1, Rufus with the CA 2023 option, or "Update_UEFI-CA2023.ps1 -BootMedia". You could do the same with bcdboot yourself, except you have to clean up since bcdboot wants to modify the local BCD file (to insert a newly added boot entry).
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
I have a couple of success stories to share.

AceMagic S1, Windows 11 Pro. Hardest part on this one was removing and re-adding the Hello PIN. Had to use the Forgot My PIN option.

check-uefi -verbose -audit
Windows PowerShell
Copyright (C) Microsoft Corporation. All rights reserved.

Windows 11 26H2 (26340.9233)

Secure Boot: ON
Virtualization Based Security: ON
BitLocker on (C:) OFF

BIOS Firmware
-------------
Default string Default string
Version: 5.26
Date: 2023-09-26

Factory Default UEFI PK Cert
----------------------------
DO NOT TRUST - AMI Test PK

UEFI PK Cert
------------
Windows OEM Devices PK

Factory Default UEFI KEK Certs
------------------------------
Microsoft Corporation KEK CA 2011

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023

Factory Default UEFI DB Certs
-----------------------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

Factory Default UEFI DBX Certs
------------------------------
(NONE)
EFI_CERT_SHA256_GUID Signatures: 217

UEFI DBX Certs
--------------
(NONE)
Windows BootMgr SVN is MISSING.
EFI_CERT_SHA256_GUID Signatures: 443

UEFI Variables
--------------
Credential Guard: ON

EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.355, SVN 9.0

Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

[OPTIONAL] SkuSiPolicy.p7b (for VBS) is MISSING.

AUDIT REPORT
============
1. Cannot confirm if W11 26H2 (26340.9233) has the latest files
2. [Production PCA 2011] is missing from UEFI DBX
3. DBX Updates are missing from UEFI DBX
4. Windows BootMgr SVN is missing from UEFI DBX

[OPTIONAL] SkuSiPolicy.p7b (for VBS) is missing from EFI

REQUIRED ACTION
===============

To REVOKE the [PCA 2011] cert, run the commands:

reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x282 /f
powershell Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

Panasonic 3E tablet, Windows 10 (x86). Nearly gave up on this one. Check-UEFI got stuck with the error that you'd discovered from others running the 32-bit version of PowerShell and there are no 64-bit options. Put it in Setup mode and ran Update anyway. CA2023 KEK was delivered but enabling SB produced violation error. There are 3 options at the bottom of BIOS SB page, Authenticate Signatures, Delete Signatures, and View Signature Info. Authenticate allowed me to turn SB back on.

check-uefi -verbose -audit
Windows PowerShell
Copyright (C) Microsoft Corporation. All rights reserved.

Try the new cross-platform PowerShell Meet Katmai's fishing giants

Windows 10 22H2 (19045.7663)

Secure Boot: ON
Virtualization Based Security: OFF (Audit Report runs as ON)
BitLocker on (C:) OFF

BIOS Firmware
-------------
3E Education PC by 3E
Version: PHBYT10A.86A.0031.2014.1216.1446
Date: 2014-12-15

Factory Default UEFI PK Cert
----------------------------
ECS

UEFI PK Cert
------------
Windows OEM Devices PK

Factory Default UEFI KEK Certs
------------------------------
Microsoft Corporation KEK CA 2011
ECS

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023
ECS

Factory Default UEFI DB Certs
-----------------------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
ECS

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023
ECS

Factory Default UEFI DBX Certs
------------------------------
(NONE)
EFI_CERT_SHA256_GUID Signatures: 0

UEFI DBX Certs
--------------
(NONE)
Windows BootMgr SVN is MISSING.
EFI_CERT_SHA256_GUID Signatures: 94

UEFI Variables
--------------
SBAT (Linux only): sbat,1,2024010900 / shim,4 / grub,3 / grub.debian,4

EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.342, SVN 9.0

Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

[OPTIONAL] SkuSiPolicy.p7b (for VBS) is MISSING.
& : The term 'C:\WINDOWS\SysNative\bcdedit' is not recognized as the name of a cmdlet, function, script file, or
operable program. Check the spelling of the name, or if a path was included, verify that the path is correct and try
again.
At C:\DownLoad\SecureBoot-CA-2023-Updates.v2026.08.21\Check_UEFI-CA2023.ps1:1640 char:20
+ if ((& "$env:SystemRoot\SysNative\bcdedit" | Select-Strin ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : ObjectNotFound: (C:\WINDOWS\SysNative\bcdedit:String) [], CommandNotFoundException
+ FullyQualifiedErrorId : CommandNotFoundException

DBX update file "C:\WINDOWS\SysNative\SecureBootUpdates\dbxupdate.bin" not found.check-uefi -verbose -audit
Windows PowerShell
Copyright (C) Microsoft Corporation. All rights reserved.

Try the new cross-platform PowerShell Meet Katmai's fishing giants

Windows 10 22H2 (19045.7663)

Secure Boot: ON
Virtualization Based Security: OFF (Audit Report runs as ON)
BitLocker on (C:) OFF

BIOS Firmware
-------------
3E Education PC by 3E
Version: PHBYT10A.86A.0031.2014.1216.1446
Date: 2014-12-15

Factory Default UEFI PK Cert
----------------------------
ECS

UEFI PK Cert
------------
Windows OEM Devices PK

Factory Default UEFI KEK Certs
------------------------------
Microsoft Corporation KEK CA 2011
ECS

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023
ECS

Factory Default UEFI DB Certs
-----------------------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
ECS

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023
ECS

Factory Default UEFI DBX Certs
------------------------------
(NONE)
EFI_CERT_SHA256_GUID Signatures: 0

UEFI DBX Certs
--------------
(NONE)
Windows BootMgr SVN is MISSING.
EFI_CERT_SHA256_GUID Signatures: 94

UEFI Variables
--------------
SBAT (Linux only): sbat,1,2024010900 / shim,4 / grub,3 / grub.debian,4

EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.342, SVN 9.0

Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

[OPTIONAL] SkuSiPolicy.p7b (for VBS) is MISSING.
& : The term 'C:\WINDOWS\SysNative\bcdedit' is not recognized as the name of a cmdlet, function, script file, or
operable program. Check the spelling of the name, or if a path was included, verify that the path is correct and try
again.
At C:\DownLoad\SecureBoot-CA-2023-Updates.v2026.08.21\Check_UEFI-CA2023.ps1:1640 char:20
+ if ((& "$env:SystemRoot\SysNative\bcdedit" | Select-Strin ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : ObjectNotFound: (C:\WINDOWS\SysNative\bcdedit:String) [], CommandNotFoundException
+ FullyQualifiedErrorId : CommandNotFoundException

DBX update file "C:\WINDOWS\SysNative\SecureBootUpdates\dbxupdate.bin" not found.

Thanks, and I hope this is useful info for someone else.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
PC/Desktop

Latest Support Threads

Back
Top Bottom