Solved garlin's PowerShell scripts for updating Secure Boot CA 2023


That means September's Monthly Update provided a newer version of the SVN in the update files, but this value has not been pushed to the UEFI (or you haven't rebooted since the Monthly Update was installed).

1. Run as Admin:
Code:
reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x200 /f
powershell Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

2. Restart Windows.
Thank you, solved.
 

My Computer My Computer

At a glance

Windows 11 Home x64 Build 26200.9550 (25H2)Intel® Core™ i7-4750HQ CPU @ 2.00GHz16 GBIntel HD 5200 Integrated Graphics (128 MB); N...
OS
Windows 11 Home x64 Build 26200.9550 (25H2)
Computer type
Laptop
Manufacturer/Model
ASUSTeK COMPUTER INC./N751JX
CPU
Intel® Core™ i7-4750HQ CPU @ 2.00GHz
Motherboard
ASUSTeK Computer INC., BIOS version AMI N751JX.211
Memory
16 GB
Graphics Card(s)
Intel HD 5200 Integrated Graphics (128 MB); NVIDIA GeForce GTX 950M (2 GB);
Sound Card
Realtek High Definition Audio
Internet Speed
250 Mbps
Antivirus
Safe Online (F-Secure)
I wrote a blog post today that includes a PS script to repair a freshly-built Macrium Reflect X Rescue Media UFD to workable condition. Check it out at: Fixing Macrium Rescue Disk - Ed Tittel.
Hope some readers find this helpful,
--Ed--
 

My Computers My Computers

  • At a glance

    Windows 11i7-8650U (8th Gen/Kaby Lake)16 GBIntel UHD Graphics 620
    OS
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo X380 Yoga
    CPU
    i7-8650U (8th Gen/Kaby Lake)
    Motherboard
    20LH000MUS (U3E1)
    Memory
    16 GB
    Graphics Card(s)
    Intel UHD Graphics 620
    Sound Card
    Integrated Conexant SmartAudio HD
    Monitor(s) Displays
    FlexView Display
    Screen Resolution
    1920x1080
    Hard Drives
    Toshiba 1 TB PCIe x3 NVMe SSD
    external 5TB Seagate USB-C attached HDD
    PSU
    Lenovo integrated 65W power brick
    Case
    Laptop
    Cooling
    Laptop
    Keyboard
    Integrated Lenovo ThinkPad keyboard
    Mouse
    touchscreen, touchpad
    Internet Speed
    GbE (Spectrum/Charter)
    Browser
    all of em
    Antivirus
    Defender
    Other Info
    Purchased early 2019 as Windows Insider test PC
  • At a glance

    Windows 11Ryzen 5800X128 GB (4x32 DDR5-5600)NVIDIA 3070Ti
    Operating System
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 5800X
    Motherboard
    Asrock B550 Extreme4
    Memory
    128 GB (4x32 DDR5-5600)
    Graphics card(s)
    NVIDIA 3070Ti
    Sound Card
    built-in
    Monitor(s) Displays
    2xDell 2707
    Screen Resolution
    1980x1200
    Hard Drives
    2XNVMe, multiple HDDs from 3 to 12 TB
    PSU
    Seasonic 650
    Case
    NZXT Flo 6
    Cooling
    dual-fan air cooler
    Keyboard
    Logitech Wave
    Mouse
    Logitech Logi
    Internet Speed
    GbE
    Browser
    all of 'em
    Antivirus
    Defender
    Other Info
    temperamental UEFI
I wrote a blog post today that includes a PS script to repair a freshly-built Macrium Reflect X Rescue Media UFD to workable condition. Check it out at: Fixing Macrium Rescue Disk - Ed Tittel.
Hope some readers find this helpful,
--Ed--
is this for PE version of Macrium Reflect X Rescue Media or WinRE version? Gonna re create mine either later tonight or early tomorrow, then create a second flash drive for Gaming Laptop tomorrow as well

I don't care if its PE or WinRE version as long as the Rescue Media works right when needed without dealing with security violations or refusing to boot issues

just want a Rescue media that works properly when needed
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8894AMD Ryzen 7700X32GB DDR 5 RGB 5600MhzRadeon 7800XT
    OS
    Windows 11 Pro 25H2 26200.8894
    Computer type
    PC/Desktop
    Manufacturer/Model
    PreBuilt
    CPU
    AMD Ryzen 7700X
    Motherboard
    MSI B650 VC WIfi Rev 1.0
    Memory
    32GB DDR 5 RGB 5600Mhz
    Graphics Card(s)
    Radeon 7800XT
    Sound Card
    Onboard Audio
    Monitor(s) Displays
    Asus VG245H
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 990 Pro 1TB Boot NVMe
    Samsung 990 Pro 2TB Game NVMe



    External
    Western Digital Elements 500GB
    Western Digital My Passport 2TB Blue
    Western Digital My Passport 2TB Red
    Toshiba 2TB in External Enclosure
    Seagate 8TB in External Enclosure
    Seagate 1TB Portable USB 3 External Drive
    Western Digital My Book 8TB (Primary Backup drive)
    Western Digital Black 4TB In External Enclosure
    PSU
    Seasonic Focus GX 750 Watt Power Supply
    Case
    Lian Li Lan Cool 216 ARGB Airflow
    Cooling
    2 160MM Front, 1 140MM Rear Exhaust
    Keyboard
    Logitech G513
    Mouse
    Logitech G502 X
    Internet Speed
    Gigabit 1100Mb/35 Upload
    Browser
    MS Edge Chromium and Bing Search
    Antivirus
    Windows Defender, Malwarebytes Premium
    Other Info
    UEFI, Secure Boot, TPM 2.0, Macrium Reflect X
  • At a glance

    Windows 11 Pro 25H2 26200.8894Ryzen 7 7735HS16GB DDR 5AMD Radeon™ 680M & Radeon 7700S
    Operating System
    Windows 11 Pro 25H2 26200.8894
    Computer type
    Laptop
    Manufacturer/Model
    Asus TUF A16 Advantage Edition FA617NT.A16.R7700
    CPU
    Ryzen 7 7735HS
    Motherboard
    OEM Asus Motherboard
    Memory
    16GB DDR 5
    Graphics card(s)
    AMD Radeon™ 680M & Radeon 7700S
    Sound Card
    Onboard
    Monitor(s) Displays
    16inch FHD 165hz
    Screen Resolution
    1920x1080
    Hard Drives
    512GB NVMe Boot Drive
    Samsung 990 Evo Plus 1TB Game NVMe
    PSU
    Laptop PSU
    Case
    Laptop Case
    Cooling
    OEM Cooling
    Keyboard
    OEM Laptop Keyboard
    Mouse
    Touchpad & G502 Hero
    Internet Speed
    Gigabit 1100 Download/35 Upload
    Browser
    MS Edge with Bing search
    Antivirus
    Windows Defender & Malwarebytes Premium
    Other Info
    Macrium Reflect X
Ed's article references ADK, so it's based on a WinPE image. WinRE for the win!
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
I wrote a blog post today that includes a PS script to repair a freshly-built Macrium Reflect X Rescue Media UFD to workable condition. Check it out at: Fixing Macrium Rescue Disk - Ed Tittel.
Hope some readers find this helpful,
--Ed--
Excellent tutorial. Question, if one only has PS version 7 can one install the PS 5.1 version from someplace?
 

My Computers My Computers

  • At a glance

    Windows 11 Home, ver 25H2 build 26200.8894Intel Core i5 5200U @ 2.20GH4 GBIntel HD Graphics 5500 on board
    OS
    Windows 11 Home, ver 25H2 build 26200.8894
    Computer type
    Laptop
    Manufacturer/Model
    Hewlett-Packard Spectre 13-4001 x360 convertable
    CPU
    Intel Core i5 5200U @ 2.20GH
    Motherboard
    Hewlett-Packard 802D
    Memory
    4 GB
    Graphics Card(s)
    Intel HD Graphics 5500 on board
    Sound Card
    Intel Smart Sound Technology (Intel SST)
    Hard Drives
    Micron 256GB M.2 2280 NGFF SSD MTFDDAV256TBN, (SATA 6.0 Gb/s)
    Keyboard
    Model # G01KB
    Antivirus
    Microsoft Defender
    Other Info
    born on date: 25 Feb 2016
  • At a glance

    Win 11 Home 25H2 build 26200.8894Intel Core i7 4th Gen 4790 (3.60GHz), Haswell...Samsung 16 GB DDR3 (8GB in 2 modules)NVIDIA GeForce GTX 760, 3GB, and on-board Int...
    Operating System
    Win 11 Home 25H2 build 26200.8894
    Computer type
    PC/Desktop
    Manufacturer/Model
    Asus Desktop model M32AD-US019S (DOM: 6/9/2014 )
    CPU
    Intel Core i7 4th Gen 4790 (3.60GHz), Haswell 22nm Technology, SOCKET 1150
    Motherboard
    H81M-E/M51AD/DP_MB
    Memory
    Samsung 16 GB DDR3 (8GB in 2 modules)
    Graphics card(s)
    NVIDIA GeForce GTX 760, 3GB, and on-board Intel HD Graphics 4600 Rev 6
    Monitor(s) Displays
    HP EliteDisplay E241i LED; HP EliteDisplay E243
    Hard Drives
    Samsung 500GB SSD, 870 EVO (SATA 6.0 )
    Micron 250GB SSD, CT250MX500
    Toshiba HDD, 3GB (original drive w/PC)
    Case
    ASUS
    Keyboard
    ASUS-------------------------
    Antivirus
    MS Defender
    Other Info
    purchased 8/28/2015 from Newegg.
  • HEWLETT PACKARD
    HP OmniBook X Flip NGAI (Next Gen AI),
    Model: 16-as0023dx
    PT# B5UH1UA#ABA Product #: B5UH1UA
    delivered and setup 7/25/25
    16" 2K Touch-Screen Laptop
    Intel Core Ultra 7 256V '24 Series 2 - CPU
    Boost Clock Frequency 4.8 gigahertz; Neural Processing Unit (NPU) Yes;
    16GB Memory, LPDDR5X
    1TB SSD PCIe 4.0
    Graphics: Intel Arc 140V
    1 x HDMI 2.1
    1 x Thunderbolt 4
    2K Touch-Screen display, LED, IPS; 1920 x 1200 (Full HD+)
    USB Ports: 1 x USB-C 3.1, 2 x USB-A 3.1
    Wi-Fi 6E

    DELL
    Model:I7591-7483BLK-PUS 2-in-1 (7000 Series)
    purchased new 12/3/2019,
    15.6 inch 2-IN-1;
    4K Ultra HD Touch-Screen, 3840 x 2160,
    Intel Core i7 10510U CPU 1.80GHz,
    16GB RAM DDR4 SDRAM 2400 megahert (2 slots),
    dedicated graphics Nvidia GeForce MX250 2 GB Graphics,
    PCIe 512GB Intel SSD + 32GB Optane Memory (Intel Optane Memory H10 with solid-state storage),
    wireless-AX & Bluetooth
    Battery: 68wh, Type 4VGMP 4 cell
I wrote a blog post today that includes a PS script to repair a freshly-built Macrium Reflect X Rescue Media UFD to workable condition. Check it out at: Fixing Macrium Rescue Disk - Ed Tittel.
Hope some readers find this helpful,
--Ed--
Example:

wrong (your script)

(Get-Item "$env:SystemRoot\Boot\EFI_EX\bootmgfw_EX.efi").VersionInfo.FileVersion
10.0.28000.342 (WinBuild.160101.0800)

right

$wr = (Get-Item "$env:SystemRoot\Boot\EFI_EX\bootmgfw_EX.efi").VersionInfo.FileVersionRaw
"{0}.{1}" -f $wr.Build, $wr.Revision
28000.367

342 vs 367
 

My Computer My Computer

At a glance

Windows 11AMD32 GBRadeon Vega
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
Gigabyte
CPU
AMD
Motherboard
Gigabyte
Memory
32 GB
Graphics Card(s)
Radeon Vega
thanks for support, used revoke and got these (y)


went to one of my Asus desktop machines this morning and the revoke command wasn't accepted - tried over and again rebooted - it just doesn't like it. Need to run verbose version - but machines are in different locations, will post back with that progress tomorrow

ummm, not sure I understand what's happening on two Asus machines a H310 and a Z370 board both display same issues and odd certs I never noticed before

win 11 somehow has secure boot off - but the other machine running win 10 using Z370 chipset has it on - both report the same issues

Windows 11 25H2 (26200.9457)
Secure Boot: OFF
Virtualization Based Security: ON
BitLocker on (C:) OFF

BIOS Firmware
-------------
System manufacturer System Product Name
Version: 2209
Date: 2022-06-14
------------
ASUSTeK MotherBoard PK Certificate

Factory Default UEFI KEK Certs
------------------------------
Microsoft Corporation KEK CA 2011
Canonical Ltd. Master Certificate Authority
ASUSTeK MotherBoard KEK Certificate

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023
Canonical Ltd. Master Certificate Authority
ASUSTeK MotherBoard KEK Certificate

Factory Default UEFI DB Certs
-----------------------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Canonical Ltd. Master Certificate Authority
ASUSTeK MotherBoard SW Key Certificate
ASUSTeK Notebook SW Key Certificate

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023
Canonical Ltd. Master Certificate Authority
ASUSTeK MotherBoard SW Key Certificate
ASUSTeK Notebook SW Key Certificate

Factory Default UEFI DBX Certs
------------------------------
(NONE)
EFI_CERT_SHA256_GUID Signatures: 77

UEFI DBX Certs
--------------
(NONE)
Windows BootMgr SVN is MISSING.
EFI_CERT_SHA256_GUID Signatures: 497

UEFI Variables
--------------
Credential Guard: ON
SBAT (Linux only): sbat,1,2024010900 / shim,4 / grub,3 / grub.debian,4

EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.367, SVN 11.0

Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

[OPTIONAL] SkuSiPolicy.p7b (for VBS) is MISSING.

STATUS REPORT
-------------
Registry: "UEFICA2023Status" = Updated


REQUIRED ACTION
===============

To REVOKE the [PCA 2011] cert, run the commands:

reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x280 /f
powershell Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

tried UEFI update again

VERBOSE: Perform operation 'Enumerate CimInstances' with following parameters, ''namespaceName' =
root\Microsoft\Windows\DeviceGuard,'className' = Win32_DeviceGuard'.
VERBOSE: Operation 'Enumerate CimInstances' complete.
VERBOSE: Perform operation 'Enumerate CimInstances' with following parameters, ''namespaceName' =
root\cimv2,'className' = Win32_ComputerSystem'.
VERBOSE: Operation 'Enumerate CimInstances' complete.
VERBOSE: No bootmgfw.efi SVN found in DBX
VERBOSE: Using specified boot manager: \\.\HarddiskVolume1\EFI\Microsoft\Boot\bootmgfw.efi
VERBOSE: Boot Manager SVN: 11.0
VERBOSE: Staged SVN: 11.0
VERBOSE: Compliance Status: Not compliant (Staged SVN does not match firmware SVN)
VERBOSE: Exporting function 'Get-ScheduledTask'.
VERBOSE: Exporting function 'Unregister-ScheduledTask'.
VERBOSE: Exporting function 'Disable-ScheduledTask'.
VERBOSE: Exporting function 'Enable-ScheduledTask'.
VERBOSE: Exporting function 'Export-ScheduledTask'.
VERBOSE: Exporting function 'Get-ScheduledTaskInfo'.
VERBOSE: Exporting function 'New-ScheduledTask'.
VERBOSE: Exporting function 'New-ScheduledTaskAction'.
VERBOSE: Exporting function 'New-ScheduledTaskPrincipal'.
VERBOSE: Exporting function 'New-ScheduledTaskSettingsSet'.
VERBOSE: Exporting function 'New-ScheduledTaskTrigger'.
VERBOSE: Exporting function 'Register-ScheduledTask'.
VERBOSE: Exporting function 'Set-ScheduledTask'.
VERBOSE: Exporting function 'Start-ScheduledTask'.
VERBOSE: Exporting function 'Stop-ScheduledTask'.
VERBOSE: Exporting function 'Get-ClusteredScheduledTask'.
VERBOSE: Exporting function 'Register-ClusteredScheduledTask'.
VERBOSE: Exporting function 'Set-ClusteredScheduledTask'.
VERBOSE: Exporting function 'Unregister-ClusteredScheduledTask'.
SUCCESS: NO UPDATES ARE REQUIRED.

DBX

SUCCESS: Matched 291/291 EFI signatures from "dbxupdate.bin"
FAILED: Missing 3/3 SVN signatures from "DBXUpdate2024.bin"
Missing [01612B139DD5598843AB1C185C3CB2EB92000005000000000000000000000000] bootmgfw.efi SVN 5.0
Missing [019D2EF8E827E15841A4884C18ABE2F284000003000000000000000000000000] cdboot.efi SVN 3.0
Missing [01C2CA99C9FE7F6F4981279E2A8A535976000003000000000000000000000000] wdsmgfw.efi SVN 3.0
FAILED: Missing 3/3 SVN signatures from "DBXUpdateSVN.bin"
Missing [01612B139DD5598843AB1C185C3CB2EB9200000B000000000000000000000000] bootmgfw.efi SVN 11.0
Missing [019D2EF8E827E15841A4884C18ABE2F284000003000000000000000000000000] cdboot.efi SVN 3.0
Missing [01C2CA99C9FE7F6F4981279E2A8A535976000003000000000000000000000000] wdsmgfw.efi SVN 3.0

PS C:\WINDOWS\system32>
 

My Computer My Computer

At a glance

Win11
OS
Win11
PS 5 comes pre-installed on Windows 10 and 11. You run the powershell.exe program to use it, instead of pwsh.exe (or launch from Winkey-X into Windows Terminal, which is my usual practice). Thanks to corrections on the script from other readers (I have made the change, and posted a new OneDrive share link). Glad it worked for me!
--Ed--
psver.webp
 
Last edited:

My Computers My Computers

  • At a glance

    Windows 11i7-8650U (8th Gen/Kaby Lake)16 GBIntel UHD Graphics 620
    OS
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo X380 Yoga
    CPU
    i7-8650U (8th Gen/Kaby Lake)
    Motherboard
    20LH000MUS (U3E1)
    Memory
    16 GB
    Graphics Card(s)
    Intel UHD Graphics 620
    Sound Card
    Integrated Conexant SmartAudio HD
    Monitor(s) Displays
    FlexView Display
    Screen Resolution
    1920x1080
    Hard Drives
    Toshiba 1 TB PCIe x3 NVMe SSD
    external 5TB Seagate USB-C attached HDD
    PSU
    Lenovo integrated 65W power brick
    Case
    Laptop
    Cooling
    Laptop
    Keyboard
    Integrated Lenovo ThinkPad keyboard
    Mouse
    touchscreen, touchpad
    Internet Speed
    GbE (Spectrum/Charter)
    Browser
    all of em
    Antivirus
    Defender
    Other Info
    Purchased early 2019 as Windows Insider test PC
  • At a glance

    Windows 11Ryzen 5800X128 GB (4x32 DDR5-5600)NVIDIA 3070Ti
    Operating System
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 5800X
    Motherboard
    Asrock B550 Extreme4
    Memory
    128 GB (4x32 DDR5-5600)
    Graphics card(s)
    NVIDIA 3070Ti
    Sound Card
    built-in
    Monitor(s) Displays
    2xDell 2707
    Screen Resolution
    1980x1200
    Hard Drives
    2XNVMe, multiple HDDs from 3 to 12 TB
    PSU
    Seasonic 650
    Case
    NZXT Flo 6
    Cooling
    dual-fan air cooler
    Keyboard
    Logitech Wave
    Mouse
    Logitech Logi
    Internet Speed
    GbE
    Browser
    all of 'em
    Antivirus
    Defender
    Other Info
    temperamental UEFI
win 11 somehow has secure boot off - but the other machine running win 10 using Z370 chipset has it on - both report the same issues
Secure Boot can only be enabled or disabled in the BIOS. Windows cannot change that setting.

OEM's are allowed to add extra certs in their factory defaults. MS only expects the base certs to be present for Windows to boot.

If you haven't revoked PCA 2011, then you don't get any SVN's. The SVN is first installed (if the normal process is correctly followed) only when PCA 2011 is added to the DBX.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Secure Boot can only be enabled or disabled in the BIOS. Windows cannot change that setting.

OEM's are allowed to add extra certs in their factory defaults. MS only expects the base certs to be present for Windows to boot.


If you haven't revoked PCA 2011, then you don't get any SVN's. The SVN is first installed (if the normal process is correctly followed) only when PCA 2011 is added to the DBX.
as per post #3854, revoke didn't complete (that's the same machine those verbose outputs show as posted in #3867, having tried revoke and rebooting on two separate occasions). would secure boot have to be on to revoke a cert?

the other machine with secure boot on - also doesn't revoke the cert
 
Last edited:

My Computer My Computer

At a glance

Win11
OS
Win11

Latest Support Threads

Back
Top Bottom