Solved I am getting an error about the secure boot


Do I have to use the PK, KEK, DB, DBX from Microsoft ?
MOSBY includes all of the Microsoft 2023 keys (including KEK) with it's distribution and loads them into firmware. You only have to dl MOSBY v2.8 from GitHUB and install it on a bootable UEFI shell USB, then run it after putting your system's Secure Boot into SETUP MODE. Read the instructions on GitHUB and the README's in the distribution.

But to Secure Boot Windows 11 you have to use Microsoft's secure boot chain of trust, therefore use Microsoft's keys. You can install your own chain of trust for other OS's, even creating/signing your own custom keys that work with your own custom boot loader; I am pretty sure there are more than a few Linux users who do just that.

But also, I'm not sure the registry entry you did is "final" for the Windows scheduled task to push ALL the keys into firmware. It may have more to come... or might not due to being problematic. But if your firmware can be updated, MOSBY will update all the keys and get latest SVN and revocations.
 
Last edited:

My Computers My Computers

  • At a glance

    Windows 11 ProRyzen 7 5800XGSkill 3200, 2x8GBMSI RX 6800 XT Gaming Z
    OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 5800X
    Motherboard
    Gigabyte B550M Aorus Pro
    Memory
    GSkill 3200, 2x8GB
    Graphics Card(s)
    MSI RX 6800 XT Gaming Z
    Sound Card
    on-board Realtek
    Monitor(s) Displays
    MSI 180hz
    Screen Resolution
    1440p
    Hard Drives
    Samsung 980 Pro, Samsung 870 Evo, generic PCIe NVME, WD 1TB 2.5" laptop spinner
    PSU
    Corsair RM 650
    Case
    mATX
    Cooling
    BeQuiet 240mm AIO and a bunch of case fans
    Keyboard
    one that clacks softly
    Mouse
    logitech
    Internet Speed
    bunches of bps
    Browser
    Firefox
    Antivirus
    Windows' own
  • At a glance

    Win11 ProRyzen 7 170016GB DDR4RX-480
    Operating System
    Win11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 1700
    Motherboard
    GA-AB350M G-3
    Memory
    16GB DDR4
    Graphics card(s)
    RX-480
    Sound Card
    In-Built Realtek
    Monitor(s) Displays
    Samsung
    Screen Resolution
    1440p
    Hard Drives
    NVME/SSD's
    PSU
    Thermaltake BX1 550W
    Case
    Some junky thing
    Cooling
    ThermalTake Assassin(?)
    Browser
    FF/Edge
    Antivirus
    Whatever Windows does
    Other Info
    Secure Boot enabled updated to 2023 CA keys, TPM2.0 enabled with system drive Bitlocker'd.
Do I have to use the PK, KEK, DB, DBX from Microsoft ?
What method did you use to install the KEK on your Lenovo IdeaPad with an unsupported 7th generation Intel processor?
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
What method did you use to install the KEK on your Lenovo IdeaPad with an unsupported 7th generation Intel processor?
fwupdmgr on linux, I had to reset to factory keys and that's it. It's an IdeaPad 320-14IKB running Fedora 42. It kept prompting me to install the uefi stuff but wouldn't when I reboot. I read somewhere that I had to reset the uefi keys to default before trying again and that's that.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
I think other Acer Aspire owners have reported problems with updating / appending to the 2023 KEK key.

Have you tried MOSBY? It's author has reported there are several BIOS' he has run across that simply do not allow updating/appending to KEK. Whether due to poor UEFI implementation or by design it's obviously a problem for owners if the OEM/manufacturer has abandoned it for BIOS updates. He has implemented a work-around in v2.8 of MOSBY that can help in some cases.

A proper BIOS update would be best, but if all-else has failed and Acer isn't forthcoming with one this might be worth trying.
I'm getting full checkmarks here after running MOSBY:
1766679668660.webp
When I use Check-SecureBootCerts.ps1:
1766679851054.webp
And on event viewer:
1766679725909.webp
Not sure what I have to do now. I read somewhere that I should replace the EFI files but idk.
 

Attachments

  • 1766679694750.webp
    1766679694750.webp
    10.3 KB · Views: 3

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
I'm getting full checkmarks here after running MOSBY:
View attachment 157997
When I use Check-SecureBootCerts.ps1:
View attachment 157998
And on event viewer:
View attachment 157999
Not sure what I have to do now. I read somewhere that I should replace the EFI files but idk.
That shows it has a full complement of keys... and even the latest SVN. You're gold, nothing more to do.

Don't worry the eventlog event's. It's notoriously slow in getting up-to-date with what's actually in firmware, especially if you used any method other than its scheduled task to get the keys installed (which it seems you did by using MOSBY!)
 

My Computers My Computers

  • At a glance

    Windows 11 ProRyzen 7 5800XGSkill 3200, 2x8GBMSI RX 6800 XT Gaming Z
    OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 5800X
    Motherboard
    Gigabyte B550M Aorus Pro
    Memory
    GSkill 3200, 2x8GB
    Graphics Card(s)
    MSI RX 6800 XT Gaming Z
    Sound Card
    on-board Realtek
    Monitor(s) Displays
    MSI 180hz
    Screen Resolution
    1440p
    Hard Drives
    Samsung 980 Pro, Samsung 870 Evo, generic PCIe NVME, WD 1TB 2.5" laptop spinner
    PSU
    Corsair RM 650
    Case
    mATX
    Cooling
    BeQuiet 240mm AIO and a bunch of case fans
    Keyboard
    one that clacks softly
    Mouse
    logitech
    Internet Speed
    bunches of bps
    Browser
    Firefox
    Antivirus
    Windows' own
  • At a glance

    Win11 ProRyzen 7 170016GB DDR4RX-480
    Operating System
    Win11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 1700
    Motherboard
    GA-AB350M G-3
    Memory
    16GB DDR4
    Graphics card(s)
    RX-480
    Sound Card
    In-Built Realtek
    Monitor(s) Displays
    Samsung
    Screen Resolution
    1440p
    Hard Drives
    NVME/SSD's
    PSU
    Thermaltake BX1 550W
    Case
    Some junky thing
    Cooling
    ThermalTake Assassin(?)
    Browser
    FF/Edge
    Antivirus
    Whatever Windows does
    Other Info
    Secure Boot enabled updated to 2023 CA keys, TPM2.0 enabled with system drive Bitlocker'd.
I'm getting full checkmarks here after running MOSBY:
View attachment 157997
When I use Check-SecureBootCerts.ps1:
View attachment 158000
And on event viewer:
View attachment 157999
Not sure what I have to do now. I read somewhere that I should replace the EFI files but idk.
Here are my reg keys now:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot
1766680007391.webp
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing
1766680028256.webp

The CA status used to be stuck in InProgress.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Here are my reg keys now:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing


The CA status used to be stuck in InProgress.
I'd just ignore those registry entries. It will resolve itself in time as the Microsoft process realizes you have all the secure boot keys in firmware.
 

My Computers My Computers

  • At a glance

    Windows 11 ProRyzen 7 5800XGSkill 3200, 2x8GBMSI RX 6800 XT Gaming Z
    OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 5800X
    Motherboard
    Gigabyte B550M Aorus Pro
    Memory
    GSkill 3200, 2x8GB
    Graphics Card(s)
    MSI RX 6800 XT Gaming Z
    Sound Card
    on-board Realtek
    Monitor(s) Displays
    MSI 180hz
    Screen Resolution
    1440p
    Hard Drives
    Samsung 980 Pro, Samsung 870 Evo, generic PCIe NVME, WD 1TB 2.5" laptop spinner
    PSU
    Corsair RM 650
    Case
    mATX
    Cooling
    BeQuiet 240mm AIO and a bunch of case fans
    Keyboard
    one that clacks softly
    Mouse
    logitech
    Internet Speed
    bunches of bps
    Browser
    Firefox
    Antivirus
    Windows' own
  • At a glance

    Win11 ProRyzen 7 170016GB DDR4RX-480
    Operating System
    Win11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 1700
    Motherboard
    GA-AB350M G-3
    Memory
    16GB DDR4
    Graphics card(s)
    RX-480
    Sound Card
    In-Built Realtek
    Monitor(s) Displays
    Samsung
    Screen Resolution
    1440p
    Hard Drives
    NVME/SSD's
    PSU
    Thermaltake BX1 550W
    Case
    Some junky thing
    Cooling
    ThermalTake Assassin(?)
    Browser
    FF/Edge
    Antivirus
    Whatever Windows does
    Other Info
    Secure Boot enabled updated to 2023 CA keys, TPM2.0 enabled with system drive Bitlocker'd.
I'd just ignore those registry entries. It will resolve itself in time as the Microsoft process realizes you have all the secure boot keys in firmware.
Thanks, I saw mosby before but shook it off. It was much easier than I thought.

So this is what they say when some manufacturers have terrible BIOS implementations.

I feel more at ease with this machine using keys not made by the oem. I wish I could donate to the mosby author with their tremendous work.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
No matter what I do, I am unable to install the KEK CA on my main PC. I do not understand how, meanwhile my IdeaPad laptop running a 7th gen CPU is up-to-date with all 2023 certs. I'm not sure why this PC is struggling. It's a coffee lake machine from 2020. I keep getting Error 1801 for no reason. I even tried fwupdmgr on fedora and even it says that the KEK CA has no updates.:

I ran these two:
Code:
reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x200 /f
Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"

And I get these:
Your are nearly there. All you need is to run is "Apply DBX update.cmd" to fix your DBX and "Apply 2023 KEK, DB and bootmgfw update.cmd" to solve your UEFI KEK, DBX issue and update the SVN part. Rerun "Check UEFI PK, KEK, DB and DBX.cmd" If Current UEFI KEK is Green, DBX shows SUCCESS and SVN=7.0 or 5.0, 3.0, 3.0 Then your done. (if 5.0 instead of 7.0; you are not on the latest build yet. When you are on 26200.7462 it will be 7.0)
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2 Build 26200.8894, Zorin OS ProIntel® Core™ i7-12700KF 12th Gen. (S1700)32GB DDR5 5600-36 Vengeance (2x16)PCIe4.0 Asus NVIDIA RTX3060Ti
    OS
    Win 11 Pro 25H2 Build 26200.8894, Zorin OS Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self built
    CPU
    Intel® Core™ i7-12700KF 12th Gen. (S1700)
    Motherboard
    ASUS Prime Z690-A, BIOS v4505 (Z690 Intel Chipset)
    Memory
    32GB DDR5 5600-36 Vengeance (2x16)
    Graphics Card(s)
    PCIe4.0 Asus NVIDIA RTX3060Ti
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    34" LG 34UC79G-B Curved 21:9 144Hz
    Screen Resolution
    2560x1080 (No HDR)
    Hard Drives
    250Gb Samsung 870PRO NVMe (Win 11 Pro)
    1Tb Samsung 980PRO NVMe
    1Tb Samsung 970EVO NVMe
    2Tb Samsung 990PRO NVMe with heatsink.
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    4Tb WDC WD40EZRZ Blue SATA (Int.)
    3Tb WDC WD30EFRZ Red SATA (Int.)
    256Gb Samsung 840PRO SSD (RHEL 9,5)
    256Gb Samsung 850PRO SSD (Zorin OS Pro 18)
    PSU
    Coolermaster 850W V2 Gold with internal 12cm exaust fan
    Case
    Be-Quiet Pure Base 600.
    Cooling
    3x Be-Quiet! 12/14cm "Silent Wings 4" casefans, 1x Arctic Freezer i35 CPU towerblock with fan.
    Keyboard
    Steelseries APEX 7 keyboard.
    Mouse
    Logitech G-502 Hero
    Internet Speed
    1Gb
    Browser
    Brave
    Antivirus
    F-Secure
    Other Info
    No Noise system.
    256Gb Kingston Travler USB 3.0 drive.
    64Gb Sandisk USB 3.2 drive. (Ventoy)
    8Gb Philips USB 3.0 drive. (Win. Inst.)
    8Gb Philips USB 3.0 drive. (Rescue disk)
    2Tb WD USB 3.0 Passport drive.
    USB Ext. 500Gb WD SATA drive.
    External USB 3.0 C.A. CD/DVD* burner.
  • At a glance

    Windows 11 Pro 25H2Intel® Core™ i7-6700K 6th Gen. (S1151)32Gb DDR4 2400 Corsair Vengeance (4x8)ASUS GeForce GTX1080
    Operating System
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Selfbuild
    CPU
    Intel® Core™ i7-6700K 6th Gen. (S1151)
    Motherboard
    ASUS Maximus VIII Ranger (Intel Chipset Z170)
    Memory
    32Gb DDR4 2400 Corsair Vengeance (4x8)
    Graphics card(s)
    ASUS GeForce GTX1080
    Sound Card
    Onboard; Realtek
    Monitor(s) Displays
    LG IPS277L 27" WideLED, IPS
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 850 Pro SSD
    PSU
    Zalman ZM600-HP with internal exhaust fan. Heatpipes & Modular cables.
    Case
    Cooler Master Aero
    Cooling
    Scythe Mugen 4 dual fan towerblock.
    Keyboard
    Red Dragon
    Mouse
    Red Dragon
    Internet Speed
    1Gb
    Browser
    Chrome
    Antivirus
    F-Secure
I can see the updating of the secure boot keys when MS decide to roll it out to the public will become a nightmare.
 

My Computer My Computer

At a glance

Win 11 ProAMD Ryzen 7 9700XG.Skill Trident Z5 Neo RGB 64GB Kit (2x32GB) ...PowerColor Radeon RX 9060 XT Reaper GDDR6 16GB
OS
Win 11 Pro
Computer type
PC/Desktop
Manufacturer/Model
N/A
CPU
AMD Ryzen 7 9700X
Motherboard
Asrock 870E Nova WiFi
Memory
G.Skill Trident Z5 Neo RGB 64GB Kit (2x32GB) DDR5-6000 C30
Graphics Card(s)
PowerColor Radeon RX 9060 XT Reaper GDDR6 16GB
Sound Card
USB Out NAD M51 DAC with Adams A8 powered speakers
Monitor(s) Displays
Dell 3219Q
Screen Resolution
3840 x 2160
Hard Drives
5 x WD_BLACK SN850x PCIe Gen4 NVMe M.2 SSD - 4TB
PSU
be quiet! DARK POWER 13 1000W Titanium PCIe 5.0 ATX Modular PSU
Case
Fractal Design Define 7 Full Tower Case (Black)
Cooling
Noctua NH-D15 G2 LBC - High Performance Multi-Socket PWM CPU Cooler
Keyboard
Razer Huntsman V2
Mouse
Razer Viper Ultimate
Internet Speed
Starlink 94Mbps down 20Mbps up
Browser
Brave
Antivirus
ESET
I feel more at ease with this machine using keys not made by the oem.
That was my feeling too. Even for my machines the OEM supported with a BIOS update adding all the necessary 2023 keys. I noticed that they installed another Chain of Trust (one MSI and two Gigabyte boards, their own KEK and DB keys) alongside the Microsoft Chain of Trust allowing to secure boot something of their own. I'm not sure why they'd want that and got a bit spooked... so I used MOSBY even for those machines.

I honestly don't know how far I can trust OEM's that have so much invested in countries with authoritarian governments that spy on their own citizens' computer useage.
 
Last edited:

My Computers My Computers

  • At a glance

    Windows 11 ProRyzen 7 5800XGSkill 3200, 2x8GBMSI RX 6800 XT Gaming Z
    OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 5800X
    Motherboard
    Gigabyte B550M Aorus Pro
    Memory
    GSkill 3200, 2x8GB
    Graphics Card(s)
    MSI RX 6800 XT Gaming Z
    Sound Card
    on-board Realtek
    Monitor(s) Displays
    MSI 180hz
    Screen Resolution
    1440p
    Hard Drives
    Samsung 980 Pro, Samsung 870 Evo, generic PCIe NVME, WD 1TB 2.5" laptop spinner
    PSU
    Corsair RM 650
    Case
    mATX
    Cooling
    BeQuiet 240mm AIO and a bunch of case fans
    Keyboard
    one that clacks softly
    Mouse
    logitech
    Internet Speed
    bunches of bps
    Browser
    Firefox
    Antivirus
    Windows' own
  • At a glance

    Win11 ProRyzen 7 170016GB DDR4RX-480
    Operating System
    Win11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 1700
    Motherboard
    GA-AB350M G-3
    Memory
    16GB DDR4
    Graphics card(s)
    RX-480
    Sound Card
    In-Built Realtek
    Monitor(s) Displays
    Samsung
    Screen Resolution
    1440p
    Hard Drives
    NVME/SSD's
    PSU
    Thermaltake BX1 550W
    Case
    Some junky thing
    Cooling
    ThermalTake Assassin(?)
    Browser
    FF/Edge
    Antivirus
    Whatever Windows does
    Other Info
    Secure Boot enabled updated to 2023 CA keys, TPM2.0 enabled with system drive Bitlocker'd.

Latest Support Threads

Back
Top Bottom