How to check if your Secure Boot certs are updated. (three methods)


Could i leave it like that, or will there still be work to do?
You can wait for the revocation, or do it yourself. If you want to revoke now, then follow the instructions at the end of the report.
 

My Computer

System One

  • OS
    Windows 7
certi.webp
Hardware was compatible with Windows 11. In the event display there is
12.03.2026 17:14:04 1801 Fehler Updated Secure Boot certificates are available on this device but have not yet been applied to the firmware. Review the published guidance to complete the update and maintain full ...

So, how do I proceed, please?
 

My Computer

System One

  • OS
    Windows 11
Your PC has not revoked the PCA 2011 cert. This is an optional step for now. You can wait for Windows, or do it now.

Run these commands as the Admin:
Code:
reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x282 /f
powershell Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"
 

My Computer

System One

  • OS
    Windows 7
Well, yes, but I'm more worried about

x Microsoft Corporation KEK 2K CA 2023
x Windows UEFI CA 2023
x Microsoft UEFI CA 2023
x Microsoft Option ROM UEFI CA 2023
Windows Bootmgr SVN: None
Windows cdboot SVN: None
Windows wdsmgfw SVN: None

Shouldn't I do something about the four issues on top of this list?
 

My Computer

System One

  • OS
    Windows 11
No. That script's output causes endless confusion. Read the sections in this different order:

1. Default PK (UEFI started from the factory BIOS)
2. Current PK (right now)

3. Default KEK (starting)
4. Current KEK (now)

5. Default DB (starting)
6. Current DB (now)

Afterwards, you shouldn't be so worried about Defaults.
 

My Computer

System One

  • OS
    Windows 7
Just do nothing! All my PCs have been updated via Windows Update as confirmed by running the script Detect-SecureBootCertUpdateStatus.ps1 in C:\Windows\SecureBoot\ExampleRolloutScripts installed in the latest monthly update.
 

My Computer

System One

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self build
    CPU
    Core i7-13700K
    Motherboard
    Asus TUF Gaming Plus WiFi Z790
    Memory
    64 GB Kingston Fury Beast DDR5
    Graphics Card(s)
    Gigabyte GeForce RTX 2060 Super Gaming OC 8G
    Sound Card
    Realtek S1200A
    Monitor(s) Displays
    Viewsonic VP2770 & Dell (secondary)
    Screen Resolution
    2560 x 1440
    Hard Drives
    Kingston KC3000 2TB NVME SSD & SATA HDDs & SSD
    PSU
    EVGA SuperNova G2 850W
    Case
    Nanoxia Deep Silence 1
    Cooling
    Noctua NH-D14
    Keyboard
    Microsoft Digital Media Pro
    Mouse
    Logitech Wireless
    Internet Speed
    80 Mb / s
    Browser
    Chrome
    Antivirus
    Defender, Malwarebytes Free & AdwCleaner

My Computers

System One System Two

  • OS
    11 Home
    Computer type
    Laptop
    Manufacturer/Model
    Asus TUF Gaming F16 (2024)
    CPU
    i7 13650HX
    Memory
    16GB DDR5
    Graphics Card(s)
    GeForce RTX 4060 Mobile
    Sound Card
    Eastern Electric MiniMax DAC Supreme; Emotiva UMC-200; Astell & Kern AK240
    Monitor(s) Displays
    Sony Bravia XR-55X90J
    Screen Resolution
    3840×2160
    Hard Drives
    512GB SSD internal
    37TB external
    PSU
    Li-ion
    Cooling
    2× Arc Flow Fans, 4× exhaust vents, 5× heatpipes
    Keyboard
    Logitech K800
    Mouse
    Logitech G402
    Internet Speed
    30Mbit/s up, 500Mbit/s down
    Browser
    FF
    Antivirus
    What's an antivirus?
  • Operating System
    11 Home
    Computer type
    Laptop
    Manufacturer/Model
    Medion S15450
    CPU
    i5 1135G7
    Memory
    16GB DDR4
    Graphics card(s)
    Intel Iris Xe
    Sound Card
    Eastern Electric MiniMax DAC Supreme; Emotiva UMC-200; Astell & Kern AK240
    Monitor(s) Displays
    Sony Bravia XR-55X90J
    Screen Resolution
    3840×2160
    Hard Drives
    2TB SSD internal
    37TB external
    PSU
    Li-ion
    Keyboard
    Logitech K800
    Mouse
    Logitech G402
    Internet Speed
    30Mbit/s up, 500Mbit/s down
    Browser
    FF
Hi Team, can you help with this:
Checking for Administrator permission...
Running as administrator - continuing execution...

20 May 2026
Manufacturer: Dell Inc.
Model: XPS 8930
BIOS: Dell Inc., 1.1.31, 1.1.31, DELL - 1072009
Windows version: 25H2 (Build 26200.8457)

Secure Boot status: Enabled

Current UEFI PK
√ Pegatron PK
Default UEFI PK √ Pegatron PK Current UEFI KEK √ Microsoft Corporation KEK CA 2011 (revoked: False) X Microsoft Corporation KEK 2K CA 2023 Default UEFI KEK √ Microsoft Corporation KEK CA 2011 (revoked: False)
X Microsoft Corporation KEK 2K CA 2023

Current UEFI DB
√ Microsoft Windows Production PCA 2011 (revoked: False)
√ Microsoft Corporation UEFI CA 2011 (revoked: False)
X Windows UEFI CA 2023
X Microsoft UEFI CA 2023
X Microsoft Option ROM UEFI CA 2023

Default UEFI DB
√ Microsoft Windows Production PCA 2011 (revoked: False)
√ Microsoft Corporation UEFI CA 2011 (revoked: False)
X Windows UEFI CA 2023
X Microsoft UEFI CA 2023
X Microsoft Option ROM UEFI CA 2023

Current UEFI DBX
2025-10-14 (v1.6.0) : SUCCESS: 431 successes detected
Windows Bootmgr SVN : None
Windows cdboot SVN : None
Windows wdsmgfw SVN : None

Press any key to continue . . .



Show Secure Boot update events.cmd output


ProviderName: Microsoft-Windows-TPM-WMI

TimeCreated Id LevelDisplayName Message
----------- -- ---------------- -------
5/20/2026 10:01:15 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/20/2026 10:01:15 PM 1796 Error The Secure Boot update failed to update 3P UEFI CA 2023 (DB) wi...
5/20/2026 10:01:15 PM 1796 Error The Secure Boot update failed to update Option ROM CA 2023 (DB)...
5/20/2026 10:01:15 PM 1796 Error The Secure Boot update failed to update Windows UEFI CA 2023 (D...
5/20/2026 2:09:01 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/20/2026 2:09:01 PM 1796 Error The Secure Boot update failed to update 3P UEFI CA 2023 (DB) wi...
5/20/2026 2:09:01 PM 1796 Error The Secure Boot update failed to update Option ROM CA 2023 (DB)...
5/20/2026 2:09:01 PM 1796 Error The Secure Boot update failed to update Windows UEFI CA 2023 (D...
5/20/2026 1:40:40 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/20/2026 1:40:40 PM 1796 Error The Secure Boot update failed to update 3P UEFI CA 2023 (DB) wi...
5/20/2026 1:40:40 PM 1796 Error The Secure Boot update failed to update Option ROM CA 2023 (DB)...
5/20/2026 1:40:40 PM 1796 Error The Secure Boot update failed to update Windows UEFI CA 2023 (D...
5/20/2026 11:33:26 AM 1801 Error Updated Secure Boot certificates are available on this device b...
5/20/2026 11:33:26 AM 1796 Error The Secure Boot update failed to update 3P UEFI CA 2023 (DB) wi...
5/20/2026 11:33:26 AM 1796 Error The Secure Boot update failed to update Option ROM CA 2023 (DB)...
5/20/2026 11:33:26 AM 1796 Error The Secure Boot update failed to update Windows UEFI CA 2023 (D...
5/20/2026 10:14:44 AM 1796 Error The Secure Boot update failed to update 3P UEFI CA 2023 (DB) wi...
5/20/2026 10:14:44 AM 1796 Error The Secure Boot update failed to update Option ROM CA 2023 (DB)...
5/20/2026 10:14:44 AM 1796 Error The Secure Boot update failed to update Windows UEFI CA 2023 (D...
5/19/2026 10:14:48 AM 1801 Error Updated Secure Boot certificates are available on this device b...
5/19/2026 10:06:51 AM 1801 Error Updated Secure Boot certificates are available on this device b...
5/18/2026 8:41:19 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/18/2026 8:33:20 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/18/2026 9:54:17 AM 1801 Error Updated Secure Boot certificates are available on this device b...
5/16/2026 6:53:51 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/16/2026 5:55:30 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/14/2026 4:13:23 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/14/2026 4:04:49 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/13/2026 9:17:00 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/13/2026 4:23:06 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/13/2026 11:07:36 AM 1801 Error Updated Secure Boot certificates are available on this device b...
5/12/2026 10:37:56 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/12/2026 10:08:55 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/12/2026 9:24:53 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/12/2026 8:26:19 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/12/2026 8:01:07 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/12/2026 7:39:12 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/12/2026 7:19:07 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/12/2026 7:07:48 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/12/2026 6:33:09 PM 1801 Error Updated Secure Boot certificates are available on this device b...
5/12/2026 6:03:54 PM 1034 Information Secure Boot Dbx update applied successfully
5/12/2026 6:03:53 PM 1801 Error Updated Secure Boot certificates are available on this device b...



Press any key to continue . . .



And from event log:
Event[10648]
Log Name: System
Source: Microsoft-Windows-TPM-WMI
Date: 2026-05-20T14:09:01.9440000Z
Event ID: 1796
Task: N/A
Level: Error
Opcode: Info
Keyword: N/A
User: S-1-5-18
User Name: NT AUTHORITY\SYSTEM
Computer: TopFuel
Description:
The Secure Boot update failed to update Windows UEFI CA 2023 (DB) with error The process cannot access the file because it is being used by another process.. For more information, please see Secure Boot DB and DBX variable update events - Microsoft Support

Event[10649]
Log Name: System
Source: Microsoft-Windows-TPM-WMI
Date: 2026-05-20T14:09:01.9520000Z
Event ID: 1796
Task: N/A
Level: Error
Opcode: Info
Keyword: N/A
User: S-1-5-18
User Name: NT AUTHORITY\SYSTEM
Computer: TopFuel
Description:
The Secure Boot update failed to update Option ROM CA 2023 (DB) with error The process cannot access the file because it is being used by another process.. For more information, please see Secure Boot DB and DBX variable update events - Microsoft Support

Event[10650]
Log Name: System
Source: Microsoft-Windows-TPM-WMI
Date: 2026-05-20T14:09:01.9610000Z
Event ID: 1796
Task: N/A
Level: Error
Opcode: Info
Keyword: N/A
User: S-1-5-18
User Name: NT AUTHORITY\SYSTEM
Computer: TopFuel
Description:
The Secure Boot update failed to update 3P UEFI CA 2023 (DB) with error The process cannot access the file because it is being used by another process.. For more information, please see Secure Boot DB and DBX variable update events - Microsoft Support

Event[10651]
Log Name: System
Source: Microsoft-Windows-TPM-WMI
Date: 2026-05-20T14:09:01.9750000Z
Event ID: 1801
Task: N/A
Level: Error
Opcode: Info
Keyword: N/A
User: S-1-5-18
User Name: NT AUTHORITY\SYSTEM
Computer: TopFuel
Description:
Updated Secure Boot certificates are available on this device but have not yet been applied to the firmware. Review the published guidance to complete the update and maintain full protection. This device signature information is included here.
DeviceAttributes: FirmwareManufacturer:Dell Inc.;FirmwareVersion:1.1.31;OEMManufacturerName:Dell Inc.;OEMModelSKU:0859;OSArchitecture:amd64;
BucketId: 20b053aa5ab91c5a11490dea87f49522aa09ffaa65d03a1a24eb8d73cfd89c4d
BucketConfidenceLevel: Under Observation - More Data Needed
UpdateType:
For more information, please see Windows Secure Boot certificate expiration and CA updates - Microsoft Support.


I checked the MS links in the error messages but they were of no help.

Thanks
Barry
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell XPS 8930
    CPU
    Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz, 3000
    Memory
    16G
    Graphics Card(s)
    NVIDIA GeForce GTX 1050Ti, Intel(R) UHD Graphics 630
    Sound Card
    Creative Sound Blaster Z SE
    Screen Resolution
    1920 x 1080
    Antivirus
    MS Defender
Manufacturer: Dell Inc.
Model: XPS 8930
BIOS: Dell Inc., 1.1.31, 1.1.31, DELL - 1072009
Version 1.1.31 is the last BIOS for the XPS 8930. It's probably not a factory supported BIOS for CA 2023 updates.

Current UEFI KEK
√ Microsoft Corporation KEK CA 2011 (revoked: False)
X Microsoft Corporation KEK 2K CA 2023
You're missing a Dell provided KEK CA 2023, which is blocking the update. And none will be provided.
Mostly likely, you need to delete all of the current Secure Boot keys, to allow the installation of a replacement set of keys.

1. Check if BitLocker encryption is enabled on the system drive, disable or suspend it.
2. Check if you're using Windows Hello PIN to unlock Windows. Disable it.
3. Enter the BIOS, and disable Secure Boot mode.
4. Change the UEFI mode to Custom mode.
5. Look for the option to Delete All Keys.
6. Restart Windows.

Download the scripts from this thread, and run the update script:
garlin's PowerShell scripts for updating Secure Boot CA 2023

Code:
Update-UEFI.bat

After the script has confirmed successful install of a replacement set of Secure Boot certs, you can:

1. Enable Secure Boot mode.
2. Enable BitLocker and Windows Hello if needed.
 

My Computer

System One

  • OS
    Windows 7
You're missing a Dell provided KEK CA 2023, which is blocking the update. And none will be provided.
Mostly likely, you need to delete all of the current Secure Boot keys, to allow the installation of a replacement set of keys.

1. Check if BitLocker encryption is enabled on the system drive, disable or suspend it.
2. Check if you're using Windows Hello PIN to unlock Windows. Disable it.
3. Enter the BIOS, and disable Secure Boot mode.
4. Change the UEFI mode to Custom mode.
5. Look for the option to Delete All Keys.
6. Restart Windows.

Download the scripts from this thread, and run the update script:
garlin's PowerShell scripts for updating Secure Boot CA 2023

Hi Garlin, I am not using either item mentioned in steps 1 and 2
When I enter the BIOS, the selections regarding Secure Boot Mode are

UEFI Boot Mode, Secure Boot ON
or
Legacy Boot Mode, Secure Boot Off

So I selected - Legacy Boot Mode, Secure Boot Off
I exited BIOS and let system attempt a boot which fails - seems he can't find the boot device

So looked around for step 4 setting: 4. Change the UEFI mode to Custom mode.
There is no setting like that.

I switched back to UEFI Boot Mode, Secure Boot ON and the pc now boots normally.

Any ideas?

Thanks
Barry
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell XPS 8930
    CPU
    Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz, 3000
    Memory
    16G
    Graphics Card(s)
    NVIDIA GeForce GTX 1050Ti, Intel(R) UHD Graphics 630
    Sound Card
    Creative Sound Blaster Z SE
    Screen Resolution
    1920 x 1080
    Antivirus
    MS Defender
We're discussing two different settings.

1. UEFI Boot Mode will only run on a GPT system drive with an UEFI boot file, and Legacy Boot Mode will only run on MBR using the "BIOS" boot file. Although some BIOS'es have a quirky UEFI+CSM mode that allows both. Secure Boot doesn't exist for CSM, since it requires UEFI support.

2. Secure Boot mode manages whether cert enforcement is done. If your boot file isn't signed with the right certs, then you can't boot.

Your possible combinations are:

Secure Boot OFFSecure Boot ON
Legacy Boot ModeCan boot any version of non-UEFI boot fileCan boot any version of non-UEFI boot file
UEFI Boot ModeCan boot any version of the UEFI boot fileMust have a specific UEFI boot file, depending on UEFI certs

On some BIOS'es, there may not be an explicit option to choose a Custom Mode. You may end up in Custom Mode by making a different change like Deleting All Keys, or if your BIOS has options for manual key enrollment. On really old Dell's, manual enrollment doesn't really work with these types of certs, and you have to choose the Delete All Keys option (which should end up as "Custom Mode").

When the keys are gone, it's possible to install a whole new set of keys to replace them (which are now compatible with CA 2023). Until then, the lack of factory support holds you back.
 

My Computer

System One

  • OS
    Windows 7
Hi Garlin, silly me, I didn't look close enough to the options.

I have now set UEFI Boot Mode, Secure Boot Off

However, I don't see any options like Delete keys or Custom Mode or Manual Enrollment

I do see some cryptic settings like:
UEFI Firmware Capsule Updates and it is set to <ENABLE>
UEFI Boot Path Security and it's set to <Always Except Internal HDD>


Also there are these:
Intel Software Guard Extensions
the option are:
Disabled
Enabled
Software Controlled <============= Thia is the one that is set

Thanks
Barry
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell XPS 8930
    CPU
    Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz, 3000
    Memory
    16G
    Graphics Card(s)
    NVIDIA GeForce GTX 1050Ti, Intel(R) UHD Graphics 630
    Sound Card
    Creative Sound Blaster Z SE
    Screen Resolution
    1920 x 1080
    Antivirus
    MS Defender
Hi, I checked this page for the BIOS examples
How To Update Secure Boot Active Database from BIOS | Dell US

I have BIOS Type 4. however there the menus don't match exactly

The link you sent says this:

Perform the following steps:​


  1. Press F2 to enter the BIOS
  2. Select Security tab along top
  3. Select Secure Boot

There is no Secure Boot on the Security Tab - mine is on the Boot Tab
1779490337996.webp



Mine is on the Boot Tab
1779490443576.webp





The only selections on the Boot --- Secure Boot ---- are enable or disable

1779490488828.webp


Any ideas

Thanks
Barry
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell XPS 8930
    CPU
    Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz, 3000
    Memory
    16G
    Graphics Card(s)
    NVIDIA GeForce GTX 1050Ti, Intel(R) UHD Graphics 630
    Sound Card
    Creative Sound Blaster Z SE
    Screen Resolution
    1920 x 1080
    Antivirus
    MS Defender
This is a REALLY OLD PC. It's unlikely any Secure Boot update is possible.

You have two (or three) options:
1. Leave Secure Boot mode enabled, and ignore all future Windows messages and alerts about Secure Boot. Windows can't help you with updates, but it will complain more and more as time goes by. You will be slightly more protected with Secure Boot than without it

2. Leave Secure Boot mode disabled, which is less secure but eliminates a lot of Windows warnings about failed update attempts. When you don't have Secure Boot enabled, Windows will know not to bother trying.

3. Get a less outdated PC.
 

My Computer

System One

  • OS
    Windows 7
This is a REALLY OLD PC. It's unlikely any Secure Boot update is possible.

It's too bad his outdated bios is preventing him from updating Secure Boot certs.
My i7-8700 is one generation older than his i7-9700 but my ASUS bios is more modern
and allowed my to add the CA2023 certificate using a .der file from Github. Ever since
then WU has been doing it's thing and keeping it updated.
 

My Computers

System One System Two

  • OS
    Win 11 Pro 25H2 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel® Core™ i7-14700K
    Motherboard
    ASUS TUF Z690-PLUS WIFI BIOS 4505 11/29/25
    Memory
    G.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5
    Graphics Card(s)
    ASUS GeForce RTX 4070 Super 12GB
    Sound Card
    Sound Blaster AE-5 Plus
    Monitor(s) Displays
    ASUS TUF Gaming 27" 2K HDR Gaming
    Screen Resolution
    2560 x 1440
    Hard Drives
    Samsung 990 Pro 1TB NVMe (Win 11 25H2)
    SK hynix P41 500GB NVMe 25H2 DEV/Games
    SK hynix P41 2TB NVMe (x3)
    Crucial P3 Plus 4TB
    PSU
    Corsair RM850x Shift
    Case
    Antec Dark Phantom DP502 FLUX
    Cooling
    Corsair Nautilus 360 RS AIO
    Keyboard
    Logitech MK 320
    Mouse
    Razer Basilisk V3
    Internet Speed
    350Mbs
    Browser
    Firefox
    Antivirus
    Winows Security
    Other Info
    MR 8.1 Home

    System 3 Specs
    Win 11 Pro 25H2 26200.8524
    ASUS PRIME Z370-P II BIOS 3004 7/12/21
    Intel Core i7-8700 CPU @ 3.20GHz
    32GB DDR4 RAM (4x8)
    iGPU Intel UHD Graphics 630
  • Operating System
    Win 11 Pro 25H2 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel Core i7-11700F
    Motherboard
    Asus TUF Gaming Z590 Plus WiFi (BIOS 2803)
    Memory
    64 GB DDR4
    Graphics card(s)
    MSI GeForce RTX 3060 Ventus 2X 12GB
    Sound Card
    SoundBlaster Audigy Fx V2
    Monitor(s) Displays
    Samsung F27T350
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 980 Pro 1TB
    Samsung 970 EVO Plus 2TB
    Samsung 870 EVO 500GB SSD
    PSU
    Corsair HX750
    Case
    Cougar MX330-G Window
    Cooling
    Thermalright Frozen Edge 240 Black AIO
    Internet Speed
    350Mbps
    Browser
    Firefox
    Antivirus
    Windows Security
Hi Garlin, I found the setting to change to get to Key Management Screen.


When I followed steps 1-3 and then went to step 4 I there was no BIOS options for Key Management

1. Check if BitLocker encryption is enabled on the system drive, disable or suspend it.
2. Check if you're using Windows Hello PIN to unlock Windows. Disable it.
3. Enter the BIOS, and disable Secure Boot mode.
4. Change the UEFI mode to Custom mode.
5. Look for the option to Delete All Keys.
6. Restart Windows.

I had to have enable Secure Boot on the Boot tab. I then save and exited the BIOS to set the Secure Boot. I then went back into the BIOS and Secure Boot was a selectable option on the Security tab. When selected it went to the Key Management screen and the options were <standard> and <custom>

1779589982434.webp

1779590054749.webp

So you original instructions were this:

1. Check if BitLocker encryption is enabled on the system drive, disable or suspend it.
2. Check if you're using Windows Hello PIN to unlock Windows. Disable it.
3. Enter the BIOS, and disable Secure Boot mode. <==================
4. Change the UEFI mode to Custom mode. <==================
5. Look for the option to Delete All Keys.
6. Restart Windows.


So I thinks the screenshots are good news so I can continue with your update instructions but I think step 3 should should be"
3. Enter the BIOS and change the UEFI mode to Custom mode
4. Look for the option to Delete All Keys.
5. Restart Windows


Download the scripts from this thread, and run the update script:
garlin's PowerShell scripts for updating Secure Boot CA 2023


Since at this point I don't know what state my BIOS will be in when I delete the keys?
Will I need to be in secure boot enabled still be enabled after this, Disabled because all the keys are deleted or something else


Thanks
Barry
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell XPS 8930
    CPU
    Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz, 3000
    Memory
    16G
    Graphics Card(s)
    NVIDIA GeForce GTX 1050Ti, Intel(R) UHD Graphics 630
    Sound Card
    Creative Sound Blaster Z SE
    Screen Resolution
    1920 x 1080
    Antivirus
    MS Defender
If you switch to Custom Mode, does that unlock other options to Delete Keys? We may be looking at a really old BIOS that has limited support for replacing the current Secure Boot keys.
 

My Computer

System One

  • OS
    Windows 7
Hi , I didn't drill in the the Custom Mode options last night, so I just did and here are the options

1779626112638.webp

So I assume I want to
1. select Delete All Secure Boot Variables
2. save settings
3. restart and let windows boot
4. run Update-UEFI.bat
5. cross fingers all goes well

Do I want to do a normal windows boot or a clean boot or doesn't matter?

Barry
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell XPS 8930
    CPU
    Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz, 3000
    Memory
    16G
    Graphics Card(s)
    NVIDIA GeForce GTX 1050Ti, Intel(R) UHD Graphics 630
    Sound Card
    Creative Sound Blaster Z SE
    Screen Resolution
    1920 x 1080
    Antivirus
    MS Defender
Back
Top Bottom