How to check if your Secure Boot certs are updated. (three methods)


They're not true "failures", you should ask the script's dev why it reports the DBX discrepancy this way or if there's a newer script.

My own script will correctly report these 154 missing signatures were retired by MS in later versions of dbxupdate.bin. The fancy word is "superseded": MS removed them from later file versions since banning PCA 2011 does the same thing as the 151 missing EFI signatures. 3 of them belong to Canonical (owners of Ubuntu).

151 + 3 = 154

But your Secure Boot updates are successful (since it was factory supported by a recent BIOS release).
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
They're not true "failures", you should ask the script's dev why it reports the DBX discrepancy this way or if there's a newer script.

My own script will correctly report these 154 missing signatures were retired by MS in later versions of dbxupdate.bin. The fancy word is "superseded": MS removed them from later file versions since banning PCA 2011 does the same thing as the 151 missing EFI signatures. 3 of them belong to Canonical (owners of Ubuntu).

151 + 3 = 154

But your Secure Boot updates are successful (since it was factory supported by a recent BIOS release).
Thank you for the reply, this is for cjee21's repo on github - i have several versions of that tool and they all do the same thing.

I just want to see the whole output green but none the less, nothings broken so I wont break things anymore :) I just used your script to check and confirmed im all good
 
Last edited:

My Computer My Computer

At a glance

Windows 11AMD 5800X3D32gb 3600mhz corsair vengance ddr4gigabyte rtx 4090 gaming oc
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
Homemade
CPU
AMD 5800X3D
Motherboard
gigabyte x470 ultra gaming rev 1.0
Memory
32gb 3600mhz corsair vengance ddr4
Graphics Card(s)
gigabyte rtx 4090 gaming oc
Sound Card
n/a
Monitor(s) Displays
2
Screen Resolution
2k
Hard Drives
samsung 870, 960, 990 pro
PSU
rm1000x
I'm not sure why he keeps older versions of the DBX update bin file on the repo. The only one that matters is the latest version currently sitting in the "\Windows\System32\SecureBootUpdates" folder.

Everyone can get a different number of total EFI signatures. The DBX variable works mostly on appended writes. If you wish to add a new EFI signature (to ban a known file), you request to the API to add it. Assuming it's not a duplicate entry, the new entry gets added and the list grows longer.

Unless you've wiped out the Secure Boot variables, your final DBX signature count will be:
- Starting with whatever list was pre-installed by the BIOS firmware you have​
- Added non-dupe entries from the SecureBootUpdates folder version of dbxupdate.bin
- Added by applying DBXUpdateSVN.bin to boost the SVN numbers​

Depending on your starting count (from the BIOS defaults) + how many non-dupe DBX entries (added when Windows Update installed a newer DBX file) + how many SVN entries were added (Windows Update installing a newer file again).

There is no "correct" count, all you can do is check if the current DBXupdate file has entries you're missing in the DBX variable. Some people applied the older version and now have 154 more than you. Not that you need those signatures, but MS was trying to conserve valuable NVRAM space by not permanently eating away bytes in the fixed-size NVRAM memory.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Hi Garlin, I'm here again needing your help with updating a Dell computer. This time it's my daughter's XPS 15 9550. Here is the result of the Check UEFI PK, KEK, DB and DBX command. I'm not sure of my next steps, and I don't want to guess. It does have the latest Dell BIOS.

Check UEFI PK, KEK, DB and DBX.webp

Thanks
Barry
 

My Computer My Computer

At a glance

Windows 11Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz, 300016GNVIDIA GeForce GTX 1050Ti, Intel(R) UHD Graph...
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
Dell XPS 8930
CPU
Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz, 3000
Memory
16G
Graphics Card(s)
NVIDIA GeForce GTX 1050Ti, Intel(R) UHD Graphics 630
Sound Card
Creative Sound Blaster Z SE
Screen Resolution
1920 x 1080
Antivirus
MS Defender
@barryde, there's basically an universal answer to most cases where a PC is over 4 -5years old. You will need to manually intervene by either trying the manual key enrollment for the KEK CA 2023 cert (if possible), or deleting all keys and replacing them (last resort).

It's the same as all the other PC's you've done before. Except how the BIOS menus appear can vary from model to model.

All that matters is getting the KEK CA 2023 installed. After that, everything can be updated.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Garlin, thanks for the response. I will attempt the manual KEK enrollment with crossed fingers and fall to back deleting all keys method if necessary.

Barry
 

My Computer My Computer

At a glance

Windows 11Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz, 300016GNVIDIA GeForce GTX 1050Ti, Intel(R) UHD Graph...
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
Dell XPS 8930
CPU
Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz, 3000
Memory
16G
Graphics Card(s)
NVIDIA GeForce GTX 1050Ti, Intel(R) UHD Graphics 630
Sound Card
Creative Sound Blaster Z SE
Screen Resolution
1920 x 1080
Antivirus
MS Defender
Hi community,

i am still getting many DBX-errors with my Gigabyte Z790 D AX.

Is there a workaround for this? It is running fine on my other board.

Current UEFI DBX
2025-10-14 (v1.6.0) [x64] : FAIL: 404 failures, 27 successes detected
Windows Bootmgr SVN : 9.0
Windows cdboot SVN : 3.0
Windows wdsmgfw SVN : 3.0

---

EDIT:
I reset the keys in the Bios, and not got this output after running it again:

Current UEFI DBX
2025-10-14 (v1.6.0) [x64] : FAIL: 1 failures, 430 successes detected
Windows Bootmgr SVN : 9.0
Windows cdboot SVN : 3.0
Windows wdsmgfw SVN : 3.0


It's kidding me. One failure!

---

EDIT2:

I ran the "Apply DBX update.cmd" and now i got success everywhere. Well, the lord or secure boot works in mysterious ways i guess. :poop:
 
Last edited:

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
self built
The latest version of O&O will also check your secure boot and whether the 2023 certificates have been installed.
 

My Computers My Computers

  • At a glance

    Windows 11 Education For 25H2Intel® Core i7 5500u8 GBIntel HD Family Graphics 5500 AMD Firepro 4150M
    OS
    Windows 11 Education For 25H2
    Computer type
    Laptop
    Manufacturer/Model
    HP ZBook G2
    CPU
    Intel® Core i7 5500u
    Motherboard
    HP
    Memory
    8 GB
    Graphics Card(s)
    Intel HD Family Graphics 5500 AMD Firepro 4150M
    Sound Card
    Realtek High Audio
    Hard Drives
    1 TB SSD
    Mouse
    HP USB Mouse
    Antivirus
    Windows Defender
  • At a glance

    Windows 11 Pro For Workstations 25H2Xeon 1535m v632 GBAMD Quadro Pro 4100
    Operating System
    Windows 11 Pro For Workstations 25H2
    Computer type
    Laptop
    Manufacturer/Model
    HP Zbook G4
    CPU
    Xeon 1535m v6
    Motherboard
    HP
    Memory
    32 GB
    Graphics card(s)
    AMD Quadro Pro 4100
    Sound Card
    Bang and Olufson Audio
    Hard Drives
    1TB SSD
    Mouse
    HP USB Mouse
    Antivirus
    Windows Defender

Latest Support Threads

Back
Top Bottom