Safe to do clean install--security certificates?


imaref

Well-known member
Local time
1:39 AM
Posts
4
OS
Windows 11
Planning to do a clean Windows 11 install on my laptop. If I use the Windows Media Creation Tool and create a flash drive, will I have any trouble because of the updated security certificates? I always delete all of the partitions and start fresh so kind of worried this might mess with those updated security certificates. Any advice? My current installation has the updated certificates, but by deleting all of the partitions will I mess it up?
 
Windows Build/Version
26200.8737 (Windows 11)

My Computer My Computer

At a glance

Windows 11i7-9750H16GBIntel UHD Graphics 630 (HP) 4095MB NVIDIA GeF...
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Omen 17
CPU
i7-9750H
Motherboard
HP 8604 (U3E1)
Memory
16GB
Graphics Card(s)
Intel UHD Graphics 630 (HP) 4095MB NVIDIA GeForce GTX 1650 (HP)
Sound Card
Realtek High Definition Audio
Hard Drives
476GB Intel Optane+477GBSSD (RAID (SSD))
You can always put back the complete set using the @garlin scripts.
 

My Computers My Computers

  • At a glance

    Win 11 Pro 25H2, Build 26200.8737Intel Core i5 1450064GB DDR4GeForce RTX 4060
    OS
    Win 11 Pro 25H2, Build 26200.8737
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14500
    Motherboard
    Gigabyte B760M G P WIFI
    Memory
    64GB DDR4
    Graphics Card(s)
    GeForce RTX 4060
    Sound Card
    Chipset Realtek
    Monitor(s) Displays
    LG 45" Ultragear, Acer 24" 1080p
    Screen Resolution
    5120x1440, 1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 3D NAND NVMe M.2 SSD (O/S)
    Silicon Power 2TB US75 NVMe PCIe Gen4 M.2 2280 SSD (backup)
    Crucial BX500 2TB 3D NAND (2nd backup)
    Seagate 4TB Ironwolf, rotating HDD archive files
    External off-line backup Drives: 2 NVMe 4TB drives in external enclosures
    PSU
    Thermaltake Toughpower GF3 750W
    Case
    LIAN LI LANCOOL 216 E-ATX PC Case
    Cooling
    Lots of fans!
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • At a glance

    Win 11 Pro 25H2, Build 26200.8655Intel Core i5 1440032GB DDR5Intel 700 Embedded GPU
    Operating System
    Win 11 Pro 25H2, Build 26200.8655
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Brew
    CPU
    Intel Core i5 14400
    Motherboard
    Gigabyte B760M DS3H AX
    Memory
    32GB DDR5
    Graphics card(s)
    Intel 700 Embedded GPU
    Sound Card
    Realtek Embedded
    Monitor(s) Displays
    27" HP 1080p
    Screen Resolution
    1920x1080
    Hard Drives
    Crucial P310 2TB 2280 PCIe Gen4 eD NAND PCIe SSD
    Samsung EVO 990 2TB NVMe Gen4 SSD
    Samsung 2TB SATA SSD
    PSU
    Thermaltake Smart BM3 650W
    Case
    Okinos Micro ATX Case
    Cooling
    Fans
    Keyboard
    Microsoft Comfort Curve 2000
    Mouse
    Logitech G305
    Internet Speed
    Verizon FiOS 1GB
    Browser
    Firefox
    Antivirus
    Malware Bytes & Windows Defender Security
  • Nimo N171 17" Laptop, (Intel i3-1215U, 16GB RAM, 2TB NVMe, Win11 Pro)
    Acemagic Vista Mini PC V1 (Intel N150, 16GB RAM, 1TB NVMe, Win11 Pro)
    HP ENVY h8-1540t, (24GB RAM, 2TB SSD, 2TB HDD, Win11 Pro)
The Secure Boot certs are written to the UEFI's NVRAM memory, they exist in the BIOS and outside of Windows. You can wipe the disk or replace the drive and the certs will stay the same.

After the certs are applied once, the only way to delete them is from the BIOS menu, or using a highly specialized EFI boot tool.

You should have no problems wiping the disk. But if you're using MCT to create an install USB, make sure you run MCT after updating the Secure Boot certs. Otherwise you get an USB drive with the wrong version of the boot file (that will fail the Secure Boot checks).
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
The Secure Boot certs are written to the UEFI's NVRAM memory, they exist in the BIOS and outside of Windows. You can wipe the disk or replace the drive and the certs will stay the same.

After the certs are applied once, the only way to delete them is from the BIOS menu, or using a highly specialized EFI boot tool.

You should have no problems wiping the disk. But if you're using MCT to create an install USB, make sure you run MCT after updating the Secure Boot certs. Otherwise you get an USB drive with the wrong version of the boot file (that will fail the Secure Boot checks).
Thanks. Yes I do have the updated certificates so I guess I'm good.
 

My Computer My Computer

At a glance

Windows 11i7-9750H16GBIntel UHD Graphics 630 (HP) 4095MB NVIDIA GeF...
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Omen 17
CPU
i7-9750H
Motherboard
HP 8604 (U3E1)
Memory
16GB
Graphics Card(s)
Intel UHD Graphics 630 (HP) 4095MB NVIDIA GeForce GTX 1650 (HP)
Sound Card
Realtek High Definition Audio
Hard Drives
476GB Intel Optane+477GBSSD (RAID (SSD))

Latest Support Threads

Back
Top Bottom