If the update script cannot find a matching KEK bin for your PC, it will recommend you first try manual KEK enrollment.
That's wheere you enter Custom Mode, and see if you're allowed to add a KEK cert from a file. Depending on your BIOS, this may not be supported. If it works, add the KEK cert and run the update script again. If you're not allowed to add a KEK file, then use the Clear All Keys option, and run the update script.
Run the update script first without -Revoke to see if it's successful. Presuming everything work, then run the -Revoke.
26H2 is the same as 24H2 & 25H2 in terms of Secure Boot. The certs are the same for all Windows releases.
Hello Garlin, I had to delete all keys, ran script, looked good, ran script with -Revoke, here's the outcome:
PS C:\User\Bob\GarlinUEFI2023> .\check_uefi-ca2023.ps1 -audit -verbose
Windows 11 25H2 (26200.9550)
Secure Boot: OFF (Audit Report runs as ON)
Virtualization Based Security: OFF (Audit Report runs as ON)
BitLocker on (C:) OFF
BIOS Firmware
-------------
Sony Corporation SVE15128CXS
Version: R0200D5
Date: 2016-09-25
Factory Default UEFI PK Cert
----------------------------
(NONE)
UEFI PK Cert
------------
Windows OEM Devices PK
Factory Default UEFI KEK Certs
------------------------------
(NONE)
UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023
Factory Default UEFI DB Certs
-----------------------------
(NONE)
UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023
Factory Default UEFI DBX Certs
------------------------------
(NONE)
EFI_CERT_SHA256_GUID Signatures: 0
UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 11.0
EFI_CERT_SHA256_GUID Signatures: 5
UEFI Variables
--------------
SBAT (Linux only): sbat,1,2025051000 / shim,4 / grub,5 / grub.debian,4 / grub.peimage,2 / grub.proxmox,2
EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] will be ALLOWED.
\\.\HarddiskVolume3\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.367, SVN 11.0
Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.
[OPTIONAL] SkuSiPolicy.p7b (for VBS) is MISSING.
AUDIT REPORT
============
1. Secure Boot is DISABLED
2. DBX Updates are missing from UEFI DBX
[OPTIONAL] SkuSiPolicy.p7b (for VBS) is missing from EFI
STATUS REPORT
-------------
Registry: "UEFICA2023Status" = Updated
REQUIRED ACTION
===============
To update DBXUpdate signatures, run the commands:
reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x2 /f
powershell Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"
I have'nt done the above "required actions". Should I?
================================
FAILED: Missing 291/291 SVN signatures from "dbxupdate.bin"
SUCCESS: Matched 3/3 SVN signatures from "DBXUpdate2024.bin"
SUCCESS: Matched 3/3 SVN signatures from "DBXUpdateSVN.bin"
===========================================
anything I should do?
I have'nt applied: schtasks /change /disable /tn "\Microsoft\Windows\PI\Secure-Boot-Update,
should I?
Thank you so much for you guidance!