How to check if your Secure Boot certs are updated. (three methods)


The only thing that I still don't have, that I have been told I do not need, is the Microsoft UEFI CA 2023 in the Current UEFI DB. I've run that script you suggested several times and I get an access error in the event viewer.
Access error? Make sure to run the commands as admin.
Don't have that Microsoft UEFI CA 2023 in the current EUFI DB? It should be there. That was the whole point.

If not? Run these commands, again Powershell as admin
reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot /v AvailableUpdates /t REG_DWORD /d 0x5944 /f
Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

After that check with regedit if the value of AvailableUpdates went back to 0x0
Querys;
reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot /v AvailableUpdates
reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing /v UEFICA2023Status
reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing /v WindowsUEFICA2023Capable

The response should be;
AvailableUpdates REG_DWORD 0x0
UEFICA2023Status REG_SZ Updated
WindowsUEFICA2023Capable REG_DWORD 0x2
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 Build 26200.8894, Zorin OS ProIntel® Core™ i7-12700KF 12th Gen. (S1700)32GB DDR5 5600-36 Vengeance (2x16)PCIe4.0 Asus NVIDIA RTX3060Ti
    OS
    Win 11 Pro 25H2 Build 26200.8894, Zorin OS Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self built
    CPU
    Intel® Core™ i7-12700KF 12th Gen. (S1700)
    Motherboard
    ASUS Prime Z690-A, BIOS v4505 (Z690 Intel Chipset)
    Memory
    32GB DDR5 5600-36 Vengeance (2x16)
    Graphics Card(s)
    PCIe4.0 Asus NVIDIA RTX3060Ti
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    34" LG 34UC79G-B Curved 21:9 144Hz
    Screen Resolution
    2560x1080 (No HDR)
    Hard Drives
    250Gb Samsung 870PRO NVMe (Win 11 Pro)
    1Tb Samsung 980PRO NVMe
    1Tb Samsung 970EVO NVMe
    2Tb Samsung 990PRO NVMe with heatsink.
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    3Tb WDC WD30EFRZ Red SATA (Int.)
    256Gb Samsung 840PRO SSD (RHEL 9,5)
    256Gb Samsung 850PRO SSD (Zorin OS Pro 18)
    PSU
    Coolermaster 850W V2 Gold with internal 12cm exaust fan
    Case
    Be-Quiet Pure Base 600.
    Cooling
    3x Be-Quiet! 12/14cm "Silent Wings 4" casefans, 1x Arctic Freezer i35 CPU towerblock with fan.
    Keyboard
    Steelseries APEX 7 keyboard.
    Mouse
    Logitech G-502 Hero
    Internet Speed
    1Gb
    Browser
    Brave
    Antivirus
    F-Secure
    Other Info
    No Noise system.
    256Gb Kingston Travler USB 3.0 drive.
    64Gb Sandisk USB 3.2 drive. (Ventoy)
    8Gb Philips USB 3.0 drive. (Win. Inst.)
    8Gb Philips USB 3.0 drive. (Rescue disk)
    2Tb WD USB 3.0 Passport drive.
    USB Ext. 500Gb WD SATA drive.
    External USB 3.0 C.A. CD/DVD* burner.
  • At a glance

    Windows 11 Pro 25H2Intel® Core™ i7-6700K 6th Gen. (S1151)32Gb DDR4 2400 Corsair Vengeance (4x8)ASUS GeForce GTX1080
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Selfbuild
    CPU
    Intel® Core™ i7-6700K 6th Gen. (S1151)
    Motherboard
    ASUS Maximus VIII Ranger (Intel Chipset Z170)
    Memory
    32Gb DDR4 2400 Corsair Vengeance (4x8)
    Graphics card(s)
    ASUS GeForce GTX1080
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    LG IPS277L 27" WideLED, IPS
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 850 Pro SSD
    PSU
    Zalman ZM600-HP with internal exhaust fan. Heatpipes & Modular cables.
    Case
    Cooler Master Aero
    Cooling
    Scythe Mugen 4 dual fan towerblock.
    Keyboard
    Red Dragon
    Mouse
    Red Dragon
    Internet Speed
    1Gb
    Browser
    Chrome
    Antivirus
    F-Secure
@hader The commands in your post didn't display.
Not sure what you mean. I can see everything I posted.
Again;
Commands are: (powershell as admin)
reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x200 /f
Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

Ah..... You mean; You are using the Light theme.... Chips. did not think about that......:rolleyes::D
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 Build 26200.8894, Zorin OS ProIntel® Core™ i7-12700KF 12th Gen. (S1700)32GB DDR5 5600-36 Vengeance (2x16)PCIe4.0 Asus NVIDIA RTX3060Ti
    OS
    Win 11 Pro 25H2 Build 26200.8894, Zorin OS Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self built
    CPU
    Intel® Core™ i7-12700KF 12th Gen. (S1700)
    Motherboard
    ASUS Prime Z690-A, BIOS v4505 (Z690 Intel Chipset)
    Memory
    32GB DDR5 5600-36 Vengeance (2x16)
    Graphics Card(s)
    PCIe4.0 Asus NVIDIA RTX3060Ti
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    34" LG 34UC79G-B Curved 21:9 144Hz
    Screen Resolution
    2560x1080 (No HDR)
    Hard Drives
    250Gb Samsung 870PRO NVMe (Win 11 Pro)
    1Tb Samsung 980PRO NVMe
    1Tb Samsung 970EVO NVMe
    2Tb Samsung 990PRO NVMe with heatsink.
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    3Tb WDC WD30EFRZ Red SATA (Int.)
    256Gb Samsung 840PRO SSD (RHEL 9,5)
    256Gb Samsung 850PRO SSD (Zorin OS Pro 18)
    PSU
    Coolermaster 850W V2 Gold with internal 12cm exaust fan
    Case
    Be-Quiet Pure Base 600.
    Cooling
    3x Be-Quiet! 12/14cm "Silent Wings 4" casefans, 1x Arctic Freezer i35 CPU towerblock with fan.
    Keyboard
    Steelseries APEX 7 keyboard.
    Mouse
    Logitech G-502 Hero
    Internet Speed
    1Gb
    Browser
    Brave
    Antivirus
    F-Secure
    Other Info
    No Noise system.
    256Gb Kingston Travler USB 3.0 drive.
    64Gb Sandisk USB 3.2 drive. (Ventoy)
    8Gb Philips USB 3.0 drive. (Win. Inst.)
    8Gb Philips USB 3.0 drive. (Rescue disk)
    2Tb WD USB 3.0 Passport drive.
    USB Ext. 500Gb WD SATA drive.
    External USB 3.0 C.A. CD/DVD* burner.
  • At a glance

    Windows 11 Pro 25H2Intel® Core™ i7-6700K 6th Gen. (S1151)32Gb DDR4 2400 Corsair Vengeance (4x8)ASUS GeForce GTX1080
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Selfbuild
    CPU
    Intel® Core™ i7-6700K 6th Gen. (S1151)
    Motherboard
    ASUS Maximus VIII Ranger (Intel Chipset Z170)
    Memory
    32Gb DDR4 2400 Corsair Vengeance (4x8)
    Graphics card(s)
    ASUS GeForce GTX1080
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    LG IPS277L 27" WideLED, IPS
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 850 Pro SSD
    PSU
    Zalman ZM600-HP with internal exhaust fan. Heatpipes & Modular cables.
    Case
    Cooler Master Aero
    Cooling
    Scythe Mugen 4 dual fan towerblock.
    Keyboard
    Red Dragon
    Mouse
    Red Dragon
    Internet Speed
    1Gb
    Browser
    Chrome
    Antivirus
    F-Secure
Not sure what you mean. I can see everything I posted.
Again;
Commands are: (powershell as admin)


Ah..... You mean; You are using the Light theme.... Chips. did not think about that......
Yes, light theme. ;-) Now I can see the commands and will run them. I'll post the results.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2i7-8565U16GBIntel UHD Graphics 620
    OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo T490 (2020 Hardware)
    CPU
    i7-8565U
    Motherboard
    20N20028US
    Memory
    16GB
    Graphics Card(s)
    Intel UHD Graphics 620
    Sound Card
    Realtec Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 970 PRO 512GB NVMe
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Supported hardware, upgraded from Windows 10 Pro to Windows 11 Pro version 24H2 on 06/01/2025 using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/07/2025. Secure boot enabled. Secure Boot CA 2023 updated.
  • At a glance

    Windows 11 Pro 25H2i7-4770 (with SSE4.2, and POPCNT)16GBIntel HD Graphics 4600
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Lenovo ThinkCentre M83 (2014 Hardware)
    CPU
    i7-4770 (with SSE4.2, and POPCNT)
    Motherboard
    10AL000GUS
    Memory
    16GB
    Graphics card(s)
    Intel HD Graphics 4600
    Sound Card
    Realtec High Definition Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 860 PRO 1TB SATA
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Unsupported hardware, upgraded from Windows 10 Pro (TPM 1.2 & unsupported CPU, but does have SSE4.2, and POPCNT) to Windows 11 Pro version 24H2 on 06/15/2025. Added Registry Key HKEY_LOCAL_MACHINE\SYSTEM\Setup\MoSetup – AllowUpgradesWithUnsupportedTPMOrCPU=1 to allow installation using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/08/2025. Secure boot enabled. Secure Boot CA 2023 updated.
Im on ASUS Z97-K , legacy-bios , no secure-boot enabled , latest bios-update from 05-02-2020.
Just checked ; no updates available , from the ASUS-site.

WHAT ?? , should I do , after reading the secure-boot forums .............?
(btw; this PC works very fine on latest Win11 , booting fast also......)

Do I really need " secure boot" and EUFI instead of legacy..............!!!?
Everyone has an opinion, I'll take the position that it's preferred to have secure boot enabled. If you don't have keys on your device to launch nuclear weapons and wipe out mankind, it shouldn't be much of an issue and you shouldn't worry too much.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Ok , so this "secure boot " is no problem for me anymore , coz I stay on legacy bios...........! :wink:
 

My Computers My Computers

  • At a glance

    Windows11 Pro 25H2i732GBnVidia
    OS
    Windows11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Asus
    CPU
    i7
    Motherboard
    z97k
    Memory
    32GB
    Graphics Card(s)
    nVidia
    Sound Card
    Realtek
    Hard Drives
    3
    Cooling
    air
    Browser
    Edge
    Antivirus
    ESET
  • At a glance

    Windows11 ProIntel i516GBIntel
    Operating System
    Windows11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    ASUS
    CPU
    Intel i5
    Motherboard
    ASUS Basic
    Memory
    16GB
    Graphics card(s)
    Intel
    Sound Card
    Realtek
    Monitor(s) Displays
    Samsung
    Hard Drives
    one intern , 0ne extern, OS on SSD
    Cooling
    air
    Keyboard
    wireless Logitech
    Mouse
    wireless Logitech
    Internet Speed
    1GB
    Browser
    Edge
    Antivirus
    ESET
Not sure what you mean. I can see everything I posted.
Again;
Commands are: (powershell as admin)


Ah..... You mean; You are using the Light theme.... Chips. did not think about that......:rolleyes::D
TADA!!! I'm down to 1 red X which you said is okay. Looks like I'm done on this machine.

Variables2.webp
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2i7-8565U16GBIntel UHD Graphics 620
    OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo T490 (2020 Hardware)
    CPU
    i7-8565U
    Motherboard
    20N20028US
    Memory
    16GB
    Graphics Card(s)
    Intel UHD Graphics 620
    Sound Card
    Realtec Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 970 PRO 512GB NVMe
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Supported hardware, upgraded from Windows 10 Pro to Windows 11 Pro version 24H2 on 06/01/2025 using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/07/2025. Secure boot enabled. Secure Boot CA 2023 updated.
  • At a glance

    Windows 11 Pro 25H2i7-4770 (with SSE4.2, and POPCNT)16GBIntel HD Graphics 4600
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Lenovo ThinkCentre M83 (2014 Hardware)
    CPU
    i7-4770 (with SSE4.2, and POPCNT)
    Motherboard
    10AL000GUS
    Memory
    16GB
    Graphics card(s)
    Intel HD Graphics 4600
    Sound Card
    Realtec High Definition Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 860 PRO 1TB SATA
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Unsupported hardware, upgraded from Windows 10 Pro (TPM 1.2 & unsupported CPU, but does have SSE4.2, and POPCNT) to Windows 11 Pro version 24H2 on 06/15/2025. Added Registry Key HKEY_LOCAL_MACHINE\SYSTEM\Setup\MoSetup – AllowUpgradesWithUnsupportedTPMOrCPU=1 to allow installation using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/08/2025. Secure boot enabled. Secure Boot CA 2023 updated.
TADA!!! I'm down to 1 red X which you said is okay. Looks like I'm done on this machine.

View attachment 157437
Yes this the result what it should be. Done. Everything is updated en ready. Now wait until MS replace all their signed files by an update. They are pointing now to CA 2011, and through that update it will point towards CA 2023.
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 Build 26200.8894, Zorin OS ProIntel® Core™ i7-12700KF 12th Gen. (S1700)32GB DDR5 5600-36 Vengeance (2x16)PCIe4.0 Asus NVIDIA RTX3060Ti
    OS
    Win 11 Pro 25H2 Build 26200.8894, Zorin OS Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self built
    CPU
    Intel® Core™ i7-12700KF 12th Gen. (S1700)
    Motherboard
    ASUS Prime Z690-A, BIOS v4505 (Z690 Intel Chipset)
    Memory
    32GB DDR5 5600-36 Vengeance (2x16)
    Graphics Card(s)
    PCIe4.0 Asus NVIDIA RTX3060Ti
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    34" LG 34UC79G-B Curved 21:9 144Hz
    Screen Resolution
    2560x1080 (No HDR)
    Hard Drives
    250Gb Samsung 870PRO NVMe (Win 11 Pro)
    1Tb Samsung 980PRO NVMe
    1Tb Samsung 970EVO NVMe
    2Tb Samsung 990PRO NVMe with heatsink.
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    3Tb WDC WD30EFRZ Red SATA (Int.)
    256Gb Samsung 840PRO SSD (RHEL 9,5)
    256Gb Samsung 850PRO SSD (Zorin OS Pro 18)
    PSU
    Coolermaster 850W V2 Gold with internal 12cm exaust fan
    Case
    Be-Quiet Pure Base 600.
    Cooling
    3x Be-Quiet! 12/14cm "Silent Wings 4" casefans, 1x Arctic Freezer i35 CPU towerblock with fan.
    Keyboard
    Steelseries APEX 7 keyboard.
    Mouse
    Logitech G-502 Hero
    Internet Speed
    1Gb
    Browser
    Brave
    Antivirus
    F-Secure
    Other Info
    No Noise system.
    256Gb Kingston Travler USB 3.0 drive.
    64Gb Sandisk USB 3.2 drive. (Ventoy)
    8Gb Philips USB 3.0 drive. (Win. Inst.)
    8Gb Philips USB 3.0 drive. (Rescue disk)
    2Tb WD USB 3.0 Passport drive.
    USB Ext. 500Gb WD SATA drive.
    External USB 3.0 C.A. CD/DVD* burner.
  • At a glance

    Windows 11 Pro 25H2Intel® Core™ i7-6700K 6th Gen. (S1151)32Gb DDR4 2400 Corsair Vengeance (4x8)ASUS GeForce GTX1080
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Selfbuild
    CPU
    Intel® Core™ i7-6700K 6th Gen. (S1151)
    Motherboard
    ASUS Maximus VIII Ranger (Intel Chipset Z170)
    Memory
    32Gb DDR4 2400 Corsair Vengeance (4x8)
    Graphics card(s)
    ASUS GeForce GTX1080
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    LG IPS277L 27" WideLED, IPS
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 850 Pro SSD
    PSU
    Zalman ZM600-HP with internal exhaust fan. Heatpipes & Modular cables.
    Case
    Cooler Master Aero
    Cooling
    Scythe Mugen 4 dual fan towerblock.
    Keyboard
    Red Dragon
    Mouse
    Red Dragon
    Internet Speed
    1Gb
    Browser
    Chrome
    Antivirus
    F-Secure
Yes this the result what it should be. Done. Everything is updated en ready. Now wait until MS replace all their signed files by an update. They are pointing now to CA 2011, and through that update it will point towards CA 2023.
How is a novice, non-techie user ever going to deal with this. SMH
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2i7-8565U16GBIntel UHD Graphics 620
    OS
    Windows 11 Pro 25H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo T490 (2020 Hardware)
    CPU
    i7-8565U
    Motherboard
    20N20028US
    Memory
    16GB
    Graphics Card(s)
    Intel UHD Graphics 620
    Sound Card
    Realtec Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 970 PRO 512GB NVMe
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Supported hardware, upgraded from Windows 10 Pro to Windows 11 Pro version 24H2 on 06/01/2025 using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/07/2025. Secure boot enabled. Secure Boot CA 2023 updated.
  • At a glance

    Windows 11 Pro 25H2i7-4770 (with SSE4.2, and POPCNT)16GBIntel HD Graphics 4600
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Lenovo ThinkCentre M83 (2014 Hardware)
    CPU
    i7-4770 (with SSE4.2, and POPCNT)
    Motherboard
    10AL000GUS
    Memory
    16GB
    Graphics card(s)
    Intel HD Graphics 4600
    Sound Card
    Realtec High Definition Audio
    Monitor(s) Displays
    ASUS VE248
    Screen Resolution
    1920 X 1080
    Hard Drives
    Samsung SSD 860 PRO 1TB SATA
    Internet Speed
    Frontier fiber 1GB
    Browser
    Chrome, Firefox, Edge
    Antivirus
    Norton 360 Deluxe Plus
    Other Info
    Unsupported hardware, upgraded from Windows 10 Pro (TPM 1.2 & unsupported CPU, but does have SSE4.2, and POPCNT) to Windows 11 Pro version 24H2 on 06/15/2025. Added Registry Key HKEY_LOCAL_MACHINE\SYSTEM\Setup\MoSetup – AllowUpgradesWithUnsupportedTPMOrCPU=1 to allow installation using the Windows 11 ISO file. Used the enablement package to upgrade to version 25H2 on 10/08/2025. Secure boot enabled. Secure Boot CA 2023 updated.
Access error? Make sure to run the commands as admin.
Don't have that Microsoft UEFI CA 2023 in the current EUFI DB? It should be there. That was the whole point.

If not? Run these commands, again Powershell as admin
reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot /v AvailableUpdates /t REG_DWORD /d 0x5944 /f
Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

After that check with regedit if the value of AvailableUpdates went back to 0x0
Querys;
reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot /v AvailableUpdates
reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing /v UEFICA2023Status
reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing /v WindowsUEFICA2023Capable

The response should be;
AvailableUpdates REG_DWORD 0x0
UEFICA2023Status REG_SZ Updated
WindowsUEFICA2023Capable REG_DWORD 0x2

I'm sure you have not gone through my posting history to know that I have done these commands repeatedly over the last month or so. ;-) I am aware that I need to run them with an elevated command prompt or elevated Powershell. I get the access errors as I stated regardless of the method used. I just ran them again and this is the result I get: error.webp

Here's the event viewer after I run the commands
1.webp
 
Last edited:

My Computer My Computer

At a glance

Windows 11 25H2Broadwell-e 6850K 4.5ghz @1.36v32GB Corsair LPM 3600 C16EVGA RTX 3080Ti FTW
OS
Windows 11 25H2
Computer type
PC/Desktop
Manufacturer/Model
EVGA home brew
CPU
Broadwell-e 6850K 4.5ghz @1.36v
Motherboard
EVGA X99 FTW K
Memory
32GB Corsair LPM 3600 C16
Graphics Card(s)
EVGA RTX 3080Ti FTW
Sound Card
Asus Centurion true 7.1 headset. (5 speakers in each earpeice)
Monitor(s) Displays
LG C4 55"
Screen Resolution
4K 144hz
Hard Drives
Various models of SSDs ~10TB No HDDs installed.
PSU
be quiet! BN516 Straight Power 12-1000w 80 Plus Platinum
Case
Corsair 780T modified to dual 200mm intake fans
Cooling
Corsair H110i
Keyboard
Corsair K95 Platinum
Mouse
Corsair M65 RGB Elite
Internet Speed
50Mbs
I just ran the Check UEFI PK, KEK, DB and DBX.cmd (R-click and run as Administrator) and got this. Need to know about these warnings!
Note: all the "v" characters are green checks.

Code:
Checking for Administrator permission...
Running as administrator - continuing execution...

19 December 2025
Manufacturer: Hewlett-Packard
Model: HP Spectre x360 Convertible 13
BIOS: American Megatrends Inc., F.54, F.54, HPQOEM - 1072009
Windows version: 25H2 (Build 26200.7462)

Secure Boot status: Enabled

Current UEFI PK
v Mosby Generated PK [2025.12.17]

Default UEFI PK
WARNING: Failed to query UEFI variable PKDefault
                                                                                                                        
Current UEFI KEK                                                                                                        
v Microsoft Corporation KEK CA 2011 (revoked: False)                                                                    
v Microsoft Corporation KEK 2K CA 2023 (revoked: False)                                                                                                                                                                                         
Default UEFI KEK                                                                                                       
 WARNING: Failed to query UEFI variable 'KEKDefault' for cert 'Microsoft Corporation KEK CA 2011'                        
WARNING: Failed to query UEFI variable 'KEKDefault' for cert 'Microsoft Corporation KEK 2K CA 2023'                     
WARNING: Failed to query UEFI variable 'KEKDefault'        
                                                             
Current UEFI DB
v Microsoft Windows Production PCA 2011 (revoked: False)
v Microsoft Corporation UEFI CA 2011 (revoked: False)
v Windows UEFI CA 2023 (revoked: False)
v Microsoft UEFI CA 2023 (revoked: False)
v Microsoft Option ROM UEFI CA 2023 (revoked: False)
v MosbyKey [2025.12.17] (revoked: False)

Default UEFI DB
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft Windows Production PCA 2011'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft Corporation UEFI CA 2011'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Windows UEFI CA 2023'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft UEFI CA 2023'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft Option ROM UEFI CA 2023'
WARNING: Failed to query UEFI variable 'DBDefault'

Current UEFI DBX
2025-10-14 (v1.6.0) : SUCCESS: 431 successes detected
Windows Bootmgr SVN : 7.0
Windows cdboot SVN  : 3.0
Windows wdsmgfw SVN : 3.0

Press any key to continue . . .

Here is the output of the Check_EFIBootFile.ps1 run:

Code:
PS C:\temp> powershell -nop -ep bypass -f Check_EFIBootFile.ps1
Secure Boot: ON
BitLocker on (C:) OFF

UEFI KEK Certs
--------------
    Microsoft Corporation KEK CA 2011
    Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
    Microsoft Corporation UEFI CA 2011
    Microsoft Windows Production PCA 2011
    Microsoft Option ROM UEFI CA 2023
    Microsoft UEFI CA 2023
    Windows UEFI CA 2023

UEFI DBX Certs
--------------

EFI Files
---------
    Disk 0: Boot Manager [Windows UEFI CA 2023] is ALLOWED.

    Registry: WindowsUEFICA2023Capable = 2
        [Windows UEFI CA 2023] is in UEFI DB, and Windows is starting from CA 2023 Boot Manager.
 

My Computers My Computers

  • At a glance

    Windows 11 Home, ver 25H2 build 26200.8246Intel Core i5 5200U @ 2.20GH4 GBIntel HD Graphics 5500 on board
    OS
    Windows 11 Home, ver 25H2 build 26200.8246
    Computer type
    Laptop
    Manufacturer/Model
    Hewlett-Packard Spectre 13-4001 x360 convertable
    CPU
    Intel Core i5 5200U @ 2.20GH
    Motherboard
    Hewlett-Packard 802D
    Memory
    4 GB
    Graphics Card(s)
    Intel HD Graphics 5500 on board
    Sound Card
    Intel Smart Sound Technology (Intel SST)
    Hard Drives
    Micron 256GB M.2 2280 NGFF SSD MTFDDAV256TBN, (SATA 6.0 Gb/s)
    Keyboard
    Model # G01KB
    Antivirus
    Microsoft Defender
    Other Info
    born on date: 25 Feb 2016
  • At a glance

    Win 11 Home 25H2 build 26200.7922Intel Core i7 4th Gen 4790 (3.60GHz), Haswell...Samsung 16 GB DDR3 (8GB in 2 modules)NVIDIA GeForce GTX 760, 3GB, and on-board Int...
    Operating System
    Win 11 Home 25H2 build 26200.7922
    Computer type
    PC/Desktop
    Manufacturer/Model
    Asus Desktop model M32AD-US019S (DOM: 6/9/2014 )
    CPU
    Intel Core i7 4th Gen 4790 (3.60GHz), Haswell 22nm Technology, SOCKET 1150
    Motherboard
    H81M-E/M51AD/DP_MB
    Memory
    Samsung 16 GB DDR3 (8GB in 2 modules)
    Graphics card(s)
    NVIDIA GeForce GTX 760, 3GB, and on-board Intel HD Graphics 4600 Rev 6
    Monitor(s) Displays
    HP EliteDisplay E241i LED; HP EliteDisplay E243
    Hard Drives
    Samsung 500GB SSD, 870 EVO (SATA 6.0 )
    Micron 250GB SSD, CT250MX500
    Toshiba HDD, 3GB (original drive w/PC)
    Case
    ASUS
    Keyboard
    ASUS-------------------------
    Antivirus
    MS Defender
    Other Info
    Additional Laptops:

    HEWLETT PACKARD
    HP OmniBook X Flip NGAI (Next Gen AI),
    Model: 16-as0023dx
    PT# B5UH1UA#ABA Product #: B5UH1UA
    delivered and setup 7/25/25
    16" 2K Touch-Screen Laptop
    Intel Core Ultra 7 256V '24 Series 2 - CPU
    Boost Clock Frequency 4.8 gigahertz; Neural Processing Unit (NPU) Yes;
    16GB Memory, LPDDR5X
    1TB SSD PCIe 4.0
    Graphics: Intel Arc 140V
    1 x HDMI 2.1
    1 x Thunderbolt 4
    2K Touch-Screen display, LED, IPS; 1920 x 1200 (Full HD+)
    USB Ports: 1 x USB-C 3.1, 2 x USB-A 3.1
    Wi-Fi 6E
    weight 4.15 pounds

    DELL
    Model:I7591-7483BLK-PUS 2-in-1 (7000 Series)
    purchased 12/3/2019,
    15.6 inch 2-IN-1;
    4K Ultra HD Touch-Screen, 3840 x 2160,
    Intel Core i7 10510U CPU 1.80GHz,
    16GB RAM DDR4 SDRAM 2400 megahert (2 slots),
    dedicated graphics Nvidia GeForce MX250 2 GB Graphics,
    PCIe 512GB Intel SSD + 32GB Optane Memory (Intel Optane Memory H10 with solid-state storage),
    wireless-AX & Bluetooth
    Battery: 68wh, Type 4VGMP 4 cell
How is a novice, non-techie user ever going to deal with this. SMH
You're not !!!! :LOL: :LOL: :LOL:

Look. This issue came about because MS made a mistake during on off their update (Think 6899) TPM-WMI errors started to occur in the system logbooks of Windows. So they woke up the dogs. And oh yes they started to bark loud!!!

My personal opinion? If MS had done their job without producing errors. Nobody would to be wiser. MS would placed this whole issue and changes inside their updates before Jun 2026. But because we noticed this error; the ball started to roll. We have now solved it ourselves ahead of time to be frank.

Normal users. You can't expect from them to do this stuff. They have a PC, Windows, Browse, e-mail, game a bit and that's it.
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 Build 26200.8894, Zorin OS ProIntel® Core™ i7-12700KF 12th Gen. (S1700)32GB DDR5 5600-36 Vengeance (2x16)PCIe4.0 Asus NVIDIA RTX3060Ti
    OS
    Win 11 Pro 25H2 Build 26200.8894, Zorin OS Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self built
    CPU
    Intel® Core™ i7-12700KF 12th Gen. (S1700)
    Motherboard
    ASUS Prime Z690-A, BIOS v4505 (Z690 Intel Chipset)
    Memory
    32GB DDR5 5600-36 Vengeance (2x16)
    Graphics Card(s)
    PCIe4.0 Asus NVIDIA RTX3060Ti
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    34" LG 34UC79G-B Curved 21:9 144Hz
    Screen Resolution
    2560x1080 (No HDR)
    Hard Drives
    250Gb Samsung 870PRO NVMe (Win 11 Pro)
    1Tb Samsung 980PRO NVMe
    1Tb Samsung 970EVO NVMe
    2Tb Samsung 990PRO NVMe with heatsink.
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    3Tb WDC WD30EFRZ Red SATA (Int.)
    256Gb Samsung 840PRO SSD (RHEL 9,5)
    256Gb Samsung 850PRO SSD (Zorin OS Pro 18)
    PSU
    Coolermaster 850W V2 Gold with internal 12cm exaust fan
    Case
    Be-Quiet Pure Base 600.
    Cooling
    3x Be-Quiet! 12/14cm "Silent Wings 4" casefans, 1x Arctic Freezer i35 CPU towerblock with fan.
    Keyboard
    Steelseries APEX 7 keyboard.
    Mouse
    Logitech G-502 Hero
    Internet Speed
    1Gb
    Browser
    Brave
    Antivirus
    F-Secure
    Other Info
    No Noise system.
    256Gb Kingston Travler USB 3.0 drive.
    64Gb Sandisk USB 3.2 drive. (Ventoy)
    8Gb Philips USB 3.0 drive. (Win. Inst.)
    8Gb Philips USB 3.0 drive. (Rescue disk)
    2Tb WD USB 3.0 Passport drive.
    USB Ext. 500Gb WD SATA drive.
    External USB 3.0 C.A. CD/DVD* burner.
  • At a glance

    Windows 11 Pro 25H2Intel® Core™ i7-6700K 6th Gen. (S1151)32Gb DDR4 2400 Corsair Vengeance (4x8)ASUS GeForce GTX1080
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Selfbuild
    CPU
    Intel® Core™ i7-6700K 6th Gen. (S1151)
    Motherboard
    ASUS Maximus VIII Ranger (Intel Chipset Z170)
    Memory
    32Gb DDR4 2400 Corsair Vengeance (4x8)
    Graphics card(s)
    ASUS GeForce GTX1080
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    LG IPS277L 27" WideLED, IPS
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 850 Pro SSD
    PSU
    Zalman ZM600-HP with internal exhaust fan. Heatpipes & Modular cables.
    Case
    Cooler Master Aero
    Cooling
    Scythe Mugen 4 dual fan towerblock.
    Keyboard
    Red Dragon
    Mouse
    Red Dragon
    Internet Speed
    1Gb
    Browser
    Chrome
    Antivirus
    F-Secure
I'm sure you have not gone through my posting history to know that I have done these commands repeatedly over the last month or so. ;-) I am aware that I need to run them with an elevated command prompt or elevated Powershell. I get the access errors as I stated regardless of the method used. I just ran them again and this is the result I get: View attachment 157441
OK clear enough. You have to focus on those error codes. They are telling something. That is the main reason why the status is holding onto "InProgress". forever. You can wait of reboot a 1000 times it will not solve this problem. Looking at the error it's saying "not enough rights" Occurred when you try to initiate something without being a admin. Make sure that your system is OK using DISM /Restorehealth and SFC /scannow. There may be an issue here.

If I compare it with mine; UEFICAError and UEFICAErrorError are not there. UEFICA2023Status is Updated and WindowsEFICA2023Capable is 0x2.
In the part below it "DeviceAttributes" I see some info about my motherboard. Is inside SecureBoot, AvailiableUpdates stil 0x0?

Delete those keys; UEFICAError and UEFICAErrorError. They might be from an other attempt. They should not be there only in cases things went wrong.

Retry again now. There seems to be something wrong with that CA 2023 certificate. You can see it also in the eventviewer.

So let's correct that first with these commands (Powershell as admin)
reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot /v AvailableUpdates /t REG_DWORD /d 0x5944 /f
Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

Querys;
reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot /v AvailableUpdates
reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing /v UEFICA2023Status
reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing /v WindowsUEFICA2023Capable

The response should be;
AvailableUpdates REG_DWORD 0x0
UEFICA2023Status REG_SZ Updated
WindowsUEFICA2023Capable REG_DWORD 0x2

Are those UEFICAError and UEFICAErrorError back again? And is Status is again InProgress?
My BucketHash is filled with some kind of checksum value (SHA-256) (can be empty also) And the ConfidenceLevel is empty. Besides UEFICA2023Status and WindowsUEFICA2023Capable There should not be any keys normally in this tree-part.
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 Build 26200.8894, Zorin OS ProIntel® Core™ i7-12700KF 12th Gen. (S1700)32GB DDR5 5600-36 Vengeance (2x16)PCIe4.0 Asus NVIDIA RTX3060Ti
    OS
    Win 11 Pro 25H2 Build 26200.8894, Zorin OS Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self built
    CPU
    Intel® Core™ i7-12700KF 12th Gen. (S1700)
    Motherboard
    ASUS Prime Z690-A, BIOS v4505 (Z690 Intel Chipset)
    Memory
    32GB DDR5 5600-36 Vengeance (2x16)
    Graphics Card(s)
    PCIe4.0 Asus NVIDIA RTX3060Ti
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    34" LG 34UC79G-B Curved 21:9 144Hz
    Screen Resolution
    2560x1080 (No HDR)
    Hard Drives
    250Gb Samsung 870PRO NVMe (Win 11 Pro)
    1Tb Samsung 980PRO NVMe
    1Tb Samsung 970EVO NVMe
    2Tb Samsung 990PRO NVMe with heatsink.
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    3Tb WDC WD30EFRZ Red SATA (Int.)
    256Gb Samsung 840PRO SSD (RHEL 9,5)
    256Gb Samsung 850PRO SSD (Zorin OS Pro 18)
    PSU
    Coolermaster 850W V2 Gold with internal 12cm exaust fan
    Case
    Be-Quiet Pure Base 600.
    Cooling
    3x Be-Quiet! 12/14cm "Silent Wings 4" casefans, 1x Arctic Freezer i35 CPU towerblock with fan.
    Keyboard
    Steelseries APEX 7 keyboard.
    Mouse
    Logitech G-502 Hero
    Internet Speed
    1Gb
    Browser
    Brave
    Antivirus
    F-Secure
    Other Info
    No Noise system.
    256Gb Kingston Travler USB 3.0 drive.
    64Gb Sandisk USB 3.2 drive. (Ventoy)
    8Gb Philips USB 3.0 drive. (Win. Inst.)
    8Gb Philips USB 3.0 drive. (Rescue disk)
    2Tb WD USB 3.0 Passport drive.
    USB Ext. 500Gb WD SATA drive.
    External USB 3.0 C.A. CD/DVD* burner.
  • At a glance

    Windows 11 Pro 25H2Intel® Core™ i7-6700K 6th Gen. (S1151)32Gb DDR4 2400 Corsair Vengeance (4x8)ASUS GeForce GTX1080
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Selfbuild
    CPU
    Intel® Core™ i7-6700K 6th Gen. (S1151)
    Motherboard
    ASUS Maximus VIII Ranger (Intel Chipset Z170)
    Memory
    32Gb DDR4 2400 Corsair Vengeance (4x8)
    Graphics card(s)
    ASUS GeForce GTX1080
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    LG IPS277L 27" WideLED, IPS
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 850 Pro SSD
    PSU
    Zalman ZM600-HP with internal exhaust fan. Heatpipes & Modular cables.
    Case
    Cooler Master Aero
    Cooling
    Scythe Mugen 4 dual fan towerblock.
    Keyboard
    Red Dragon
    Mouse
    Red Dragon
    Internet Speed
    1Gb
    Browser
    Chrome
    Antivirus
    F-Secure
OK clear enough. You have to focus on those error codes. They are telling something. That is the main reason why the status is holding onto "InProgress". forever. You can wait of reboot a 1000 times it will not solve this problem. Looking at the error it's saying "not enough rights" Occurred when you try to initiate something without being a admin. Make sure that your system is OK using DISM /Restorehealth and SFC /scannow. There may be an issue here.

If I compare it with mine; UEFICAError and UEFICAErrorError are not there. UEFICA2023Status is Updated and WindowsEFICA2023Capable is 0x2.
In the part below it "DeviceAttributes" I see some info about my motherboard. Is inside SecureBoot, AvailiableUpdates stil 0x0?

Delete those keys; UEFICAError and UEFICAErrorError. They might be from an other attempt. They should not be there only in cases things went wrong.

Retry again now. There seems to be something wrong with that CA 2023 certificate. You can see it also in the eventviewer.

So let's correct that first with these commands (Powershell as admin)
reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot /v AvailableUpdates /t REG_DWORD /d 0x5944 /f
Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

Querys;
reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot /v AvailableUpdates
reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing /v UEFICA2023Status
reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing /v WindowsUEFICA2023Capable

The response should be;
AvailableUpdates REG_DWORD 0x0
UEFICA2023Status REG_SZ Updated
WindowsUEFICA2023Capable REG_DWORD 0x2

Are those UEFICAError and UEFICAErrorError back again? And is Status is again InProgress?
My BucketHash is filled with some kind of checksum value (SHA-256) (can be empty also) And the ConfidenceLevel is empty. Besides UEFICA2023Status and WindowsUEFICA2023Capable There should not be any keys normally in this tree-part.
I realize you're trying to help, but asking me to run the exact same commands I've done repeatedly and using the same trouble shooting steps and expecting a different result does not seem helpful. 🤷‍♂️ I've also been assured that I don't need this particular item for the system to run correctly.
 

My Computer My Computer

At a glance

Windows 11 25H2Broadwell-e 6850K 4.5ghz @1.36v32GB Corsair LPM 3600 C16EVGA RTX 3080Ti FTW
OS
Windows 11 25H2
Computer type
PC/Desktop
Manufacturer/Model
EVGA home brew
CPU
Broadwell-e 6850K 4.5ghz @1.36v
Motherboard
EVGA X99 FTW K
Memory
32GB Corsair LPM 3600 C16
Graphics Card(s)
EVGA RTX 3080Ti FTW
Sound Card
Asus Centurion true 7.1 headset. (5 speakers in each earpeice)
Monitor(s) Displays
LG C4 55"
Screen Resolution
4K 144hz
Hard Drives
Various models of SSDs ~10TB No HDDs installed.
PSU
be quiet! BN516 Straight Power 12-1000w 80 Plus Platinum
Case
Corsair 780T modified to dual 200mm intake fans
Cooling
Corsair H110i
Keyboard
Corsair K95 Platinum
Mouse
Corsair M65 RGB Elite
Internet Speed
50Mbs
I just ran the Check UEFI PK, KEK, DB and DBX.cmd (R-click and run as Administrator) and got this. Need to know about these warnings!
Note: all the "v" characters are green checks.

Code:
Checking for Administrator permission...
Running as administrator - continuing execution...

19 December 2025
Manufacturer: Hewlett-Packard
Model: HP Spectre x360 Convertible 13
BIOS: American Megatrends Inc., F.54, F.54, HPQOEM - 1072009
Windows version: 25H2 (Build 26200.7462)

Secure Boot status: Enabled

Current UEFI PK
v Mosby Generated PK [2025.12.17]

Default UEFI PK
WARNING: Failed to query UEFI variable PKDefault
                                                                                                                       
Current UEFI KEK                                                                                                       
v Microsoft Corporation KEK CA 2011 (revoked: False)                                                                   
v Microsoft Corporation KEK 2K CA 2023 (revoked: False)                                                                                                                                                                                        
Default UEFI KEK                                                                                                      
 WARNING: Failed to query UEFI variable 'KEKDefault' for cert 'Microsoft Corporation KEK CA 2011'                       
WARNING: Failed to query UEFI variable 'KEKDefault' for cert 'Microsoft Corporation KEK 2K CA 2023'                    
WARNING: Failed to query UEFI variable 'KEKDefault'       
                                                            
Current UEFI DB
v Microsoft Windows Production PCA 2011 (revoked: False)
v Microsoft Corporation UEFI CA 2011 (revoked: False)
v Windows UEFI CA 2023 (revoked: False)
v Microsoft UEFI CA 2023 (revoked: False)
v Microsoft Option ROM UEFI CA 2023 (revoked: False)
v MosbyKey [2025.12.17] (revoked: False)

Default UEFI DB
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft Windows Production PCA 2011'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft Corporation UEFI CA 2011'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Windows UEFI CA 2023'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft UEFI CA 2023'
WARNING: Failed to query UEFI variable 'dbDefault' for cert 'Microsoft Option ROM UEFI CA 2023'
WARNING: Failed to query UEFI variable 'DBDefault'

Current UEFI DBX
2025-10-14 (v1.6.0) : SUCCESS: 431 successes detected
Windows Bootmgr SVN : 7.0
Windows cdboot SVN  : 3.0
Windows wdsmgfw SVN : 3.0

Press any key to continue . . .

Here is the output of the Check_EFIBootFile.ps1 run:

Code:
PS C:\temp> powershell -nop -ep bypass -f Check_EFIBootFile.ps1
Secure Boot: ON
BitLocker on (C:) OFF

UEFI KEK Certs
--------------
    Microsoft Corporation KEK CA 2011
    Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
    Microsoft Corporation UEFI CA 2011
    Microsoft Windows Production PCA 2011
    Microsoft Option ROM UEFI CA 2023
    Microsoft UEFI CA 2023
    Windows UEFI CA 2023

UEFI DBX Certs
--------------

EFI Files
---------
    Disk 0: Boot Manager [Windows UEFI CA 2023] is ALLOWED.

    Registry: WindowsUEFICA2023Capable = 2
        [Windows UEFI CA 2023] is in UEFI DB, and Windows is starting from CA 2023 Boot Manager.
Since the lines showing "Current UEFI ..." locations are all green check marked, and the error codes are all in the so-called "Default UEFI" locations I'm going to assume that my machine is set up just fine and the error codes are really irrelevant for purposes of running the laptop. :unsure:
 

My Computers My Computers

  • At a glance

    Windows 11 Home, ver 25H2 build 26200.8246Intel Core i5 5200U @ 2.20GH4 GBIntel HD Graphics 5500 on board
    OS
    Windows 11 Home, ver 25H2 build 26200.8246
    Computer type
    Laptop
    Manufacturer/Model
    Hewlett-Packard Spectre 13-4001 x360 convertable
    CPU
    Intel Core i5 5200U @ 2.20GH
    Motherboard
    Hewlett-Packard 802D
    Memory
    4 GB
    Graphics Card(s)
    Intel HD Graphics 5500 on board
    Sound Card
    Intel Smart Sound Technology (Intel SST)
    Hard Drives
    Micron 256GB M.2 2280 NGFF SSD MTFDDAV256TBN, (SATA 6.0 Gb/s)
    Keyboard
    Model # G01KB
    Antivirus
    Microsoft Defender
    Other Info
    born on date: 25 Feb 2016
  • At a glance

    Win 11 Home 25H2 build 26200.7922Intel Core i7 4th Gen 4790 (3.60GHz), Haswell...Samsung 16 GB DDR3 (8GB in 2 modules)NVIDIA GeForce GTX 760, 3GB, and on-board Int...
    Operating System
    Win 11 Home 25H2 build 26200.7922
    Computer type
    PC/Desktop
    Manufacturer/Model
    Asus Desktop model M32AD-US019S (DOM: 6/9/2014 )
    CPU
    Intel Core i7 4th Gen 4790 (3.60GHz), Haswell 22nm Technology, SOCKET 1150
    Motherboard
    H81M-E/M51AD/DP_MB
    Memory
    Samsung 16 GB DDR3 (8GB in 2 modules)
    Graphics card(s)
    NVIDIA GeForce GTX 760, 3GB, and on-board Intel HD Graphics 4600 Rev 6
    Monitor(s) Displays
    HP EliteDisplay E241i LED; HP EliteDisplay E243
    Hard Drives
    Samsung 500GB SSD, 870 EVO (SATA 6.0 )
    Micron 250GB SSD, CT250MX500
    Toshiba HDD, 3GB (original drive w/PC)
    Case
    ASUS
    Keyboard
    ASUS-------------------------
    Antivirus
    MS Defender
    Other Info
    Additional Laptops:

    HEWLETT PACKARD
    HP OmniBook X Flip NGAI (Next Gen AI),
    Model: 16-as0023dx
    PT# B5UH1UA#ABA Product #: B5UH1UA
    delivered and setup 7/25/25
    16" 2K Touch-Screen Laptop
    Intel Core Ultra 7 256V '24 Series 2 - CPU
    Boost Clock Frequency 4.8 gigahertz; Neural Processing Unit (NPU) Yes;
    16GB Memory, LPDDR5X
    1TB SSD PCIe 4.0
    Graphics: Intel Arc 140V
    1 x HDMI 2.1
    1 x Thunderbolt 4
    2K Touch-Screen display, LED, IPS; 1920 x 1200 (Full HD+)
    USB Ports: 1 x USB-C 3.1, 2 x USB-A 3.1
    Wi-Fi 6E
    weight 4.15 pounds

    DELL
    Model:I7591-7483BLK-PUS 2-in-1 (7000 Series)
    purchased 12/3/2019,
    15.6 inch 2-IN-1;
    4K Ultra HD Touch-Screen, 3840 x 2160,
    Intel Core i7 10510U CPU 1.80GHz,
    16GB RAM DDR4 SDRAM 2400 megahert (2 slots),
    dedicated graphics Nvidia GeForce MX250 2 GB Graphics,
    PCIe 512GB Intel SSD + 32GB Optane Memory (Intel Optane Memory H10 with solid-state storage),
    wireless-AX & Bluetooth
    Battery: 68wh, Type 4VGMP 4 cell
Random trivia from script testing:

If you finished adding all the CA 2023 certs, UEFICA2023Status = Updated.
But if you go back and manually delete a cert (ie. Option ROM), UEFICA2023Status = NotStarted :think:

Code:
Secure Boot: OFF
BitLocker on (C:) OFF

UEFI KEK Certs
--------------
    Microsoft Corporation KEK CA 2011
    Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
    Microsoft Corporation UEFI CA 2011
    Microsoft Windows Production PCA 2011
    Microsoft UEFI CA 2023
    Windows UEFI CA 2023

UEFI DBX Certs
--------------
    Microsoft Windows Production PCA 2011
    Windows Boot Manager SVN 7.0

EFI Files
---------
    Disk 0: Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.

    Registry: WindowsUEFICA2023Capable = 2
        [Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

PS C:\Users\GARLIN\Downloads> start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"
PS C:\Users\GARLIN\Downloads> reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing
    WindowsUEFICA2023Capable    REG_DWORD    0x2
    UEFICA2023Status    REG_SZ    NotStarted
    BucketHash    REG_SZ    4adea2baf22d03771e783bc274830e699f2c9e6ca97d2f8c720ff01139a08309
    ConfidenceLevel    REG_SZ

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing\DeviceAttributes
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing\UploadedForCurrentBootCycle
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
I realize you're trying to help, but asking me to run the exact same commands I've done repeatedly and using the same trouble shooting steps and expecting a different result does not seem helpful. 🤷‍♂️ I've also been assured that I don't need this particular item for the system to run correctly.
OK. No need to complete quote me. If you say I am convinced that this will not help; there is then only one solution;
Apparently your administrator account seems to be damaged in such a way that the scheduled task script "Secure-Boot-Update" is giving rights errors. That (as I suggested) is an indication that your system is damaged. I would execute the In-Place-Installment procedure in order to refresh your whole Windows system. (all your data will be left alone)

"Not needed?"
You can also run further with the current system without any problems. Make sure you disable secure boot before June 2026. Because MS wil replaced all the Windows files with files signed with this new CA 2023 certificate. (Until then it will point to the be soon expiring CA 2011 certificate that gives you now no issues.) If you leave it as it is (secure boot=on) Windows will after the change refuse to boot. With secure boot disabled your system will run without any problems. But make sure that you have a good virusprogram that intercepts rootkit's that will try to inject or replace Windows files. With all the security risks that comes with it. (Ransomware for example) That is the whole point of MS; more secure. The bootloader will look during (startup) loading at drivers and files and inspects it certificate. If it's not right or the certificate has been expired: The bootload will not load them.
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 Build 26200.8894, Zorin OS ProIntel® Core™ i7-12700KF 12th Gen. (S1700)32GB DDR5 5600-36 Vengeance (2x16)PCIe4.0 Asus NVIDIA RTX3060Ti
    OS
    Win 11 Pro 25H2 Build 26200.8894, Zorin OS Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self built
    CPU
    Intel® Core™ i7-12700KF 12th Gen. (S1700)
    Motherboard
    ASUS Prime Z690-A, BIOS v4505 (Z690 Intel Chipset)
    Memory
    32GB DDR5 5600-36 Vengeance (2x16)
    Graphics Card(s)
    PCIe4.0 Asus NVIDIA RTX3060Ti
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    34" LG 34UC79G-B Curved 21:9 144Hz
    Screen Resolution
    2560x1080 (No HDR)
    Hard Drives
    250Gb Samsung 870PRO NVMe (Win 11 Pro)
    1Tb Samsung 980PRO NVMe
    1Tb Samsung 970EVO NVMe
    2Tb Samsung 990PRO NVMe with heatsink.
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    3Tb WDC WD30EFRZ Red SATA (Int.)
    256Gb Samsung 840PRO SSD (RHEL 9,5)
    256Gb Samsung 850PRO SSD (Zorin OS Pro 18)
    PSU
    Coolermaster 850W V2 Gold with internal 12cm exaust fan
    Case
    Be-Quiet Pure Base 600.
    Cooling
    3x Be-Quiet! 12/14cm "Silent Wings 4" casefans, 1x Arctic Freezer i35 CPU towerblock with fan.
    Keyboard
    Steelseries APEX 7 keyboard.
    Mouse
    Logitech G-502 Hero
    Internet Speed
    1Gb
    Browser
    Brave
    Antivirus
    F-Secure
    Other Info
    No Noise system.
    256Gb Kingston Travler USB 3.0 drive.
    64Gb Sandisk USB 3.2 drive. (Ventoy)
    8Gb Philips USB 3.0 drive. (Win. Inst.)
    8Gb Philips USB 3.0 drive. (Rescue disk)
    2Tb WD USB 3.0 Passport drive.
    USB Ext. 500Gb WD SATA drive.
    External USB 3.0 C.A. CD/DVD* burner.
  • At a glance

    Windows 11 Pro 25H2Intel® Core™ i7-6700K 6th Gen. (S1151)32Gb DDR4 2400 Corsair Vengeance (4x8)ASUS GeForce GTX1080
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Selfbuild
    CPU
    Intel® Core™ i7-6700K 6th Gen. (S1151)
    Motherboard
    ASUS Maximus VIII Ranger (Intel Chipset Z170)
    Memory
    32Gb DDR4 2400 Corsair Vengeance (4x8)
    Graphics card(s)
    ASUS GeForce GTX1080
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    LG IPS277L 27" WideLED, IPS
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 850 Pro SSD
    PSU
    Zalman ZM600-HP with internal exhaust fan. Heatpipes & Modular cables.
    Case
    Cooler Master Aero
    Cooling
    Scythe Mugen 4 dual fan towerblock.
    Keyboard
    Red Dragon
    Mouse
    Red Dragon
    Internet Speed
    1Gb
    Browser
    Chrome
    Antivirus
    F-Secure
Since the lines showing "Current UEFI ..." locations are all green check marked, and the error codes are all in the so-called "Default UEFI" locations I'm going to assume that my machine is set up just fine and the error codes are really irrelevant for purposes of running the laptop. :unsure:
I agree. The current values are the one that are important. It is a bit strange that it can't get the default values.

It seems like that piece of memory has been wiped clean in the past. There is an option in the BIOS to wipe PK, KEK, DB, DBX values. Did you clear them in the past? Inside the BIOS: Under Boot-options, Secure Boot, Key management there is an option to "Install Default Secure Boot Keys" (besides "Clear Secure Boot keys") Do this and see it will now give you a normal result (without warnings). Other option is to reset all your values inside your BIOS (default values). If this does not help reflash your BIOS with your current one. Or you leave it as it is... Your choice.

All the values current and default ones are stored in a piece of NVRAM flashmemory on your motherboard. It is also the same location where your BIOS stores it's current BIOS values. During flashing a new BIOS version those default values of PK, KEK, DB and DBX will be filled also. It is possible that it will leave the current values alone. Because they were filled initial by the OEM (during manufacturing) with the default ones. (otherwise you have to repeat this whole CA2023 procedure again....)
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 Build 26200.8894, Zorin OS ProIntel® Core™ i7-12700KF 12th Gen. (S1700)32GB DDR5 5600-36 Vengeance (2x16)PCIe4.0 Asus NVIDIA RTX3060Ti
    OS
    Win 11 Pro 25H2 Build 26200.8894, Zorin OS Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self built
    CPU
    Intel® Core™ i7-12700KF 12th Gen. (S1700)
    Motherboard
    ASUS Prime Z690-A, BIOS v4505 (Z690 Intel Chipset)
    Memory
    32GB DDR5 5600-36 Vengeance (2x16)
    Graphics Card(s)
    PCIe4.0 Asus NVIDIA RTX3060Ti
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    34" LG 34UC79G-B Curved 21:9 144Hz
    Screen Resolution
    2560x1080 (No HDR)
    Hard Drives
    250Gb Samsung 870PRO NVMe (Win 11 Pro)
    1Tb Samsung 980PRO NVMe
    1Tb Samsung 970EVO NVMe
    2Tb Samsung 990PRO NVMe with heatsink.
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    3Tb WDC WD30EFRZ Red SATA (Int.)
    256Gb Samsung 840PRO SSD (RHEL 9,5)
    256Gb Samsung 850PRO SSD (Zorin OS Pro 18)
    PSU
    Coolermaster 850W V2 Gold with internal 12cm exaust fan
    Case
    Be-Quiet Pure Base 600.
    Cooling
    3x Be-Quiet! 12/14cm "Silent Wings 4" casefans, 1x Arctic Freezer i35 CPU towerblock with fan.
    Keyboard
    Steelseries APEX 7 keyboard.
    Mouse
    Logitech G-502 Hero
    Internet Speed
    1Gb
    Browser
    Brave
    Antivirus
    F-Secure
    Other Info
    No Noise system.
    256Gb Kingston Travler USB 3.0 drive.
    64Gb Sandisk USB 3.2 drive. (Ventoy)
    8Gb Philips USB 3.0 drive. (Win. Inst.)
    8Gb Philips USB 3.0 drive. (Rescue disk)
    2Tb WD USB 3.0 Passport drive.
    USB Ext. 500Gb WD SATA drive.
    External USB 3.0 C.A. CD/DVD* burner.
  • At a glance

    Windows 11 Pro 25H2Intel® Core™ i7-6700K 6th Gen. (S1151)32Gb DDR4 2400 Corsair Vengeance (4x8)ASUS GeForce GTX1080
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Selfbuild
    CPU
    Intel® Core™ i7-6700K 6th Gen. (S1151)
    Motherboard
    ASUS Maximus VIII Ranger (Intel Chipset Z170)
    Memory
    32Gb DDR4 2400 Corsair Vengeance (4x8)
    Graphics card(s)
    ASUS GeForce GTX1080
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    LG IPS277L 27" WideLED, IPS
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 850 Pro SSD
    PSU
    Zalman ZM600-HP with internal exhaust fan. Heatpipes & Modular cables.
    Case
    Cooler Master Aero
    Cooling
    Scythe Mugen 4 dual fan towerblock.
    Keyboard
    Red Dragon
    Mouse
    Red Dragon
    Internet Speed
    1Gb
    Browser
    Chrome
    Antivirus
    F-Secure
Random trivia from script testing:

If you finished adding all the CA 2023 certs, UEFICA2023Status = Updated.
But if you go back and manually delete a cert (ie. Option ROM), UEFICA2023Status = NotStarted :think:
Not strange. It seems that that certificate must be there. If not then it does not meet the UEFICA2023 demands. You have to install it back again. Hope you have saved it somewhere. You can re-install it with certmgr.msc. The script "Secure-Boot-Update" (or some other check script) wants to see it. If not? It will say "Not updated, so NotStarted" And why bother? Secure boot is turned off..... It's only effective if secure boot = on.
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 Build 26200.8894, Zorin OS ProIntel® Core™ i7-12700KF 12th Gen. (S1700)32GB DDR5 5600-36 Vengeance (2x16)PCIe4.0 Asus NVIDIA RTX3060Ti
    OS
    Win 11 Pro 25H2 Build 26200.8894, Zorin OS Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self built
    CPU
    Intel® Core™ i7-12700KF 12th Gen. (S1700)
    Motherboard
    ASUS Prime Z690-A, BIOS v4505 (Z690 Intel Chipset)
    Memory
    32GB DDR5 5600-36 Vengeance (2x16)
    Graphics Card(s)
    PCIe4.0 Asus NVIDIA RTX3060Ti
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    34" LG 34UC79G-B Curved 21:9 144Hz
    Screen Resolution
    2560x1080 (No HDR)
    Hard Drives
    250Gb Samsung 870PRO NVMe (Win 11 Pro)
    1Tb Samsung 980PRO NVMe
    1Tb Samsung 970EVO NVMe
    2Tb Samsung 990PRO NVMe with heatsink.
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    3Tb WDC WD30EFRZ Red SATA (Int.)
    256Gb Samsung 840PRO SSD (RHEL 9,5)
    256Gb Samsung 850PRO SSD (Zorin OS Pro 18)
    PSU
    Coolermaster 850W V2 Gold with internal 12cm exaust fan
    Case
    Be-Quiet Pure Base 600.
    Cooling
    3x Be-Quiet! 12/14cm "Silent Wings 4" casefans, 1x Arctic Freezer i35 CPU towerblock with fan.
    Keyboard
    Steelseries APEX 7 keyboard.
    Mouse
    Logitech G-502 Hero
    Internet Speed
    1Gb
    Browser
    Brave
    Antivirus
    F-Secure
    Other Info
    No Noise system.
    256Gb Kingston Travler USB 3.0 drive.
    64Gb Sandisk USB 3.2 drive. (Ventoy)
    8Gb Philips USB 3.0 drive. (Win. Inst.)
    8Gb Philips USB 3.0 drive. (Rescue disk)
    2Tb WD USB 3.0 Passport drive.
    USB Ext. 500Gb WD SATA drive.
    External USB 3.0 C.A. CD/DVD* burner.
  • At a glance

    Windows 11 Pro 25H2Intel® Core™ i7-6700K 6th Gen. (S1151)32Gb DDR4 2400 Corsair Vengeance (4x8)ASUS GeForce GTX1080
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Selfbuild
    CPU
    Intel® Core™ i7-6700K 6th Gen. (S1151)
    Motherboard
    ASUS Maximus VIII Ranger (Intel Chipset Z170)
    Memory
    32Gb DDR4 2400 Corsair Vengeance (4x8)
    Graphics card(s)
    ASUS GeForce GTX1080
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    LG IPS277L 27" WideLED, IPS
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 850 Pro SSD
    PSU
    Zalman ZM600-HP with internal exhaust fan. Heatpipes & Modular cables.
    Case
    Cooler Master Aero
    Cooling
    Scythe Mugen 4 dual fan towerblock.
    Keyboard
    Red Dragon
    Mouse
    Red Dragon
    Internet Speed
    1Gb
    Browser
    Chrome
    Antivirus
    F-Secure
Good evening, is this situation satisfactory or should I do something else? Thank you for your help.
Sincerely,
 

Attachments

My Computer My Computer

At a glance

windows 11 25H224GBiris xe
OS
windows 11 25H2
Computer type
Laptop
Manufacturer/Model
ASUS Vivobook 15 (X1504)
Motherboard
Intel Alder Lake-P PCH
Memory
24GB
Graphics Card(s)
iris xe
Sound Card
realtek
Screen Resolution
1920X1080
Hard Drives
Samsung SSD 990 PRO 1TB
Browser
edge
Antivirus
eset anti virus
I am not sure what happened here. I was in the BIOS and decided to save the secure boot keys. Exited out of the menu, rebooted and was greeted with this: oops1.webp

So, I go back in to the BIOS and notice that the authorized signatures was set to default. I tried to restore this from the save I had just made but apparently that didn't work.
oops2.webp

So I had to disable secure boot to get back to the desktop. My secure boot now seems all jacked up.


hard fail.webp
 

My Computer My Computer

At a glance

Windows 11 25H2Broadwell-e 6850K 4.5ghz @1.36v32GB Corsair LPM 3600 C16EVGA RTX 3080Ti FTW
OS
Windows 11 25H2
Computer type
PC/Desktop
Manufacturer/Model
EVGA home brew
CPU
Broadwell-e 6850K 4.5ghz @1.36v
Motherboard
EVGA X99 FTW K
Memory
32GB Corsair LPM 3600 C16
Graphics Card(s)
EVGA RTX 3080Ti FTW
Sound Card
Asus Centurion true 7.1 headset. (5 speakers in each earpeice)
Monitor(s) Displays
LG C4 55"
Screen Resolution
4K 144hz
Hard Drives
Various models of SSDs ~10TB No HDDs installed.
PSU
be quiet! BN516 Straight Power 12-1000w 80 Plus Platinum
Case
Corsair 780T modified to dual 200mm intake fans
Cooling
Corsair H110i
Keyboard
Corsair K95 Platinum
Mouse
Corsair M65 RGB Elite
Internet Speed
50Mbs
Back
Top Bottom