Solved garlin's PowerShell scripts for updating Secure Boot CA 2023


hello,
after last Tuesday monthly update, i´m getting continuos "event error TPM-WMI 1796" about the impossibility of SBAT update due to device not ready...
maybe it´s because i´ve not made the revocation of the Microsoft Windows Production PCA 2011 yet?
any advice, please
thank you in advance,
fernando
**************************************************************************************************

(NONE)
EFI_CERT_SHA256_GUID Signatures: 77

UEFI DBX Certs
--------------
(NONE)
Windows BootMgr SVN is MISSING.
EFI_CERT_SHA256_GUID Signatures: 445

UEFI Variables
--------------
SBAT (Linux only): sbat,1,2024010900 / shim,4 / grub,3 / grub.debian,4
snap !
 

My Computer My Computer

At a glance

Win11
OS
Win11

My Computer My Computer

At a glance

windows 10 Enterprise IoT LTSCIntel(R) Core(TM) i5-6400 CPU @ 2.70GHz16GBIntel HD Graphics 530 (integrated on Motherbo...
OS
windows 10 Enterprise IoT LTSC
Computer type
PC/Desktop
Manufacturer/Model
ASUS/ K31CD
CPU
Intel(R) Core(TM) i5-6400 CPU @ 2.70GHz
Memory
16GB
Graphics Card(s)
Intel HD Graphics 530 (integrated on Motherboard)
Other Info
BIOS: American Megatrends Inc.
v. 1102 (12-2018)
Or leave it disabled only while recovering.

Or maybe the backup vendors will take my suggestion and self-monitor when Windows changes the boot file, and auto-prompt you to insert your USB drive for a quick refresh. It's free advice...

I also back up my EFI partition as well, so I have to reapply the change to bootmanager after a restore from a backup that has a different SVN, unless I do not restore the EFI partition.
 

My Computers My Computers

  • At a glance

    Windows 11 ProIntel Core i9 14900K 5800/4500 P/E96GB (2x48) G.skill Ripjaws 6800Asus ROG Strix 4070 Ti OC
    OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY Photoshop/Audio/Game/tinker
    CPU
    Intel Core i9 14900K 5800/4500 P/E
    Motherboard
    Asus ROG Maximus Z790 Dark Hero
    Memory
    96GB (2x48) G.skill Ripjaws 6800
    Graphics Card(s)
    Asus ROG Strix 4070 Ti OC
    Sound Card
    B&W 606 S3 speakers; Audiolabs 7000a integrated amp; RSL 10S Mk2 sub
    Monitor(s) Displays
    Eizo CG2730 ColorEdge, ViewSonic VP2768
    Screen Resolution
    2560 x 1440 x 2
    Hard Drives
    nvme: WDC SN850X 4TB, SN850 1TB, SK-Hynix 2 TB P41
    Spinners: Sabrent USB-C DS-SC5B 5-bay docking station, 6TB WDC Black, 6TB Ironwolf Pro 2x 2TB WDC Black
    PSU
    850W Seasonic Vertex PX-850
    Case
    FD North XL Mesh, Black Walnut
    Cooling
    EK Nucleus black 360 AIO w/Phanteks T30 fans; 2 Noctua NF-A14 Chromax ; T30 for memory
    Keyboard
    Keychron Q3 Max TKL w/GMK Redsuns Red Samuri keycaps
    Mouse
    Logitech G305 wireless gaming
    Internet Speed
    575 Mb/s down | 25 Mb/s up
    Browser
    Firefox
    Antivirus
    Defender, Macrium Reflect X
    Other Info
    Phangkey Amaterasu V2 Desk Mat
  • At a glance

    Apple M1
    Computer type
    Laptop
    Manufacturer/Model
    💻 Apple 13" Macbook Pro 2020 (m1)
    CPU
    Apple M1
    Screen Resolution
    2560x1600
    Browser
    Firefox
Hi Garlin. Just wondering is the Check_DBXUpdate.bin.ps1in post Post #3739 the same file that you released in today's update 2026-09-10

Regards,
James.
 

My Computers My Computers

  • At a glance

    Windows 11 ProIntel Core i5-12600K 3.7 GHz 10-Core ProcessorCorsair Vengeance LPX 64 GB (2 x 32 GB) DDR4-...Integrated Intel UHD Graphics 770
    OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self built PC by me.
    CPU
    Intel Core i5-12600K 3.7 GHz 10-Core Processor
    Motherboard
    Gigabyte B760M H DDR4 Micro ATX LGA1700 Motherboard
    Memory
    Corsair Vengeance LPX 64 GB (2 x 32 GB) DDR4-3200 CL16 Memory
    Graphics Card(s)
    Integrated Intel UHD Graphics 770
    Sound Card
    Realtek
    Monitor(s) Displays
    LG
    Hard Drives
    Samsung 990 Pro 1 TB M.2-2280 PCIe 4.0 X4 NVME Solid State Drive
    Samsung 990 Pro 2 TB M.2-2280 PCIe 4.0 X4 NVME Solid State Drive
    PSU
    NZXT 850w ATX 3.1 Gold Fully Modular Power Supply
    Case
    Thermaltake Versa H25 ATX Mid Tower Case
    Cooling
    CPU Cooler Thermalright Assassin Spirit 120 EVO ARGB (ARGB Disabled) - Case Fans BlackThermalright TL-C12C-S X3 66.17 CFM 120 mm Fans 3-Pack (ARGB disabled)
    Internet Speed
    1 Gbps
    Other Info
    I hate ARGB.
  • At a glance

    Windows 11 Pro
    Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo ThinkBook 14 G2 ITL
Basically if the SVN changes (for September, it jumps to 11.0) in both the DBX and EFI locations, then you're good.

@KevTech has some Macrium X tips posted in this thread. Use the search function (-> "This thread") to find the earlier posts.
This is from my wife's Lenovo M83 desktop after doing the update. Why do I not see SVN 11.0 in the EFI section?

PowerShell 7.6.6
Secure Boot: ON
Virtualization Based Security: OFF
BitLocker on (C:) OFF

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
MosbyKey [2025.12.22]
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 11.0

EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.

Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.


STATUS REPORT
-------------
Registry: "UEFICA2023Status" = Updated

SUCCESS: UPDATES ARE FINISHED.
UEFI CA 2023 certs are present, PCA 2011 cert is revoked.

PS C:\Windows\System32>

*************************************************************************

OOPS! NEVERMIND, I FORGOT TO RUN -VERBOSE. IT LOOKS GOOD NOW.

*************************************************************************

Windows 11 25H2 (26200.9445)
Secure Boot: ON
Virtualization Based Security: OFF
BitLocker on (C:) OFF

BIOS Firmware
-------------
LENOVO 10AL000GUS
Version: FBKTE0AUS
Date: 2021-12-22

Factory Default UEFI PK Cert
----------------------------
(NONE)

UEFI PK Cert
------------
Mosby Generated PK [2025.12.22]

Factory Default UEFI KEK Certs
------------------------------
(NONE)

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023

Factory Default UEFI DB Certs
-----------------------------
(NONE)

UEFI DB Certs
-------------
MosbyKey [2025.12.22]
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

Factory Default UEFI DBX Certs
------------------------------
(NONE)
EFI_CERT_SHA256_GUID Signatures: 0

UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 11.0
EFI_CERT_SHA256_GUID Signatures: 455

UEFI Variables
--------------
Credential Guard: ON
SBAT (Linux only): sbat,1,2025051000 / shim,4 / grub,5 / grub.proxmox,2

EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.367, SVN 11.0

Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.


STATUS REPORT
-------------
Registry: "UEFICA2023Status" = Updated

SUCCESS: UPDATES ARE FINISHED.
UEFI CA 2023 certs are present, PCA 2011 cert is revoked.

PS C:\SecureBoot\SecureBoot-CA-2023-Updates_v2026-09-10>
 
Last edited:

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2i7-8565U16GBIntel UHD Graphics 620
    OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo T490 (2020 Hardware)
    CPU
    i7-8565U
    Motherboard
    20N20028US
    Memory
    16GB
    Graphics Card(s)
    Intel UHD Graphics 620
    Sound Card
    Realtec Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 970 PRO 512GB NVMe
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Supported hardware, upgraded from Windows 10 Pro to Windows 11 Pro version 24H2 on 06/01/2025 using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/07/2025. Secure boot enabled. Secure Boot CA 2023 updated.
  • At a glance

    Windows 11 Pro 25H2i7-4770 (with SSE4.2, and POPCNT)16GBIntel HD Graphics 4600
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Lenovo ThinkCentre M83 (2014 Hardware)
    CPU
    i7-4770 (with SSE4.2, and POPCNT)
    Motherboard
    10AL000GUS
    Memory
    16GB
    Graphics card(s)
    Intel HD Graphics 4600
    Sound Card
    Realtec High Definition Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 860 PRO 1TB SATA
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Unsupported hardware, upgraded from Windows 10 Pro (TPM 1.2 & unsupported CPU, but does have SSE4.2, and POPCNT) to Windows 11 Pro version 24H2 on 06/15/2025. Added Registry Key HKEY_LOCAL_MACHINE\SYSTEM\Setup\MoSetup – AllowUpgradesWithUnsupportedTPMOrCPU=1 to allow installation using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/08/2025. Secure boot enabled. Secure Boot CA 2023 updated.
Hi Garlin. Just wondering is the Check_DBXUpdate.bin.ps1in post Post #3739 the same file that you released in today's update 2026-09-10

Regards,
James.
Yes they are
The only differences are line 3 and line 62 which states the version that went from 2026.09.09 to 2026.09.10

FYI: WinMerge, great free tool for comparing files...
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
FYI to all, Current MCT ISO is build 26200.9445 (September 2026)
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
hello,
after last Tuesday monthly update, i´m getting continuos "event error TPM-WMI 1796" about the impossibility of SBAT update due to device not ready...
maybe it´s because i´ve not made the revocation of the Microsoft Windows Production PCA 2011 yet?
SBAT is a Secure Boot variable used by Linux, it's their version of a SVN.

Windows doesn't care about it. But the Secure Boot update task is programmed to write it on all PC's, regardless of whether you have Linux.

On some PC's, SBAT cannot be written due to a reported BIOS issue. Since the task cannot verify the SBAT, it will continuously retry and throw TPM-WMI events. You can instruct Windows to stop trying to update the SBAT by running:
Code:
reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\SBAT /v OptOut /d 1 /t REG_DWORD
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Yes they are
The only differences are line 3 and line 62 which states the version that went from 2026.09.09 to 2026.09.10

FYI: WinMerge, great free tool for comparing files...
Hey thanks so much!!

I ran the script in post 3739 on my dads pc helping him over the phone and it was a success. But because he is in his late 70's we have to go through how to download, unzip and open powershell which can take 45 minutes.

I tried to compare the files using virus total and that didn't help. Next time I will try WinMerge.

Thanks again :)
 

My Computers My Computers

  • At a glance

    Windows 11 ProIntel Core i5-12600K 3.7 GHz 10-Core ProcessorCorsair Vengeance LPX 64 GB (2 x 32 GB) DDR4-...Integrated Intel UHD Graphics 770
    OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self built PC by me.
    CPU
    Intel Core i5-12600K 3.7 GHz 10-Core Processor
    Motherboard
    Gigabyte B760M H DDR4 Micro ATX LGA1700 Motherboard
    Memory
    Corsair Vengeance LPX 64 GB (2 x 32 GB) DDR4-3200 CL16 Memory
    Graphics Card(s)
    Integrated Intel UHD Graphics 770
    Sound Card
    Realtek
    Monitor(s) Displays
    LG
    Hard Drives
    Samsung 990 Pro 1 TB M.2-2280 PCIe 4.0 X4 NVME Solid State Drive
    Samsung 990 Pro 2 TB M.2-2280 PCIe 4.0 X4 NVME Solid State Drive
    PSU
    NZXT 850w ATX 3.1 Gold Fully Modular Power Supply
    Case
    Thermaltake Versa H25 ATX Mid Tower Case
    Cooling
    CPU Cooler Thermalright Assassin Spirit 120 EVO ARGB (ARGB Disabled) - Case Fans BlackThermalright TL-C12C-S X3 66.17 CFM 120 mm Fans 3-Pack (ARGB disabled)
    Internet Speed
    1 Gbps
    Other Info
    I hate ARGB.
  • At a glance

    Windows 11 Pro
    Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo ThinkBook 14 G2 ITL
Hey thanks so much!!

I ran the script in post 3739 on my dads pc helping him over the phone and it was a success. But because he is in his late 70's we have to go through how to download, unzip and open powershell which can take 45 minutes.

I tried to compare the files using virus total and that didn't help. Next time I will try WinMerge.

Thanks again :)
Won't go deeper here in this thread, but take a look at AnyDesk free remote control for providing support.
Free for personal use...
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
SBAT is a Secure Boot variable used by Linux, it's their version of a SVN.

Windows doesn't care about it. But the Secure Boot update task is programmed to write it on all PC's, regardless of whether you have Linux.

On some PC's, SBAT cannot be written due to a reported BIOS issue. Since the task cannot verify the SBAT, it will continuously retry and throw TPM-WMI events. You can instruct Windows to stop trying to update the SBAT by running:
Code:
reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\SBAT /v OptOut /d 1 /t REG_DWORD
thank you very much, garlin
best regards,
fernando
 

My Computer My Computer

At a glance

windows 10 Enterprise IoT LTSCIntel(R) Core(TM) i5-6400 CPU @ 2.70GHz16GBIntel HD Graphics 530 (integrated on Motherbo...
OS
windows 10 Enterprise IoT LTSC
Computer type
PC/Desktop
Manufacturer/Model
ASUS/ K31CD
CPU
Intel(R) Core(TM) i5-6400 CPU @ 2.70GHz
Memory
16GB
Graphics Card(s)
Intel HD Graphics 530 (integrated on Motherboard)
Other Info
BIOS: American Megatrends Inc.
v. 1102 (12-2018)

Latest Support Threads

Back
Top Bottom