Solved Secure Boot Allowed Signature Database (DB) Update


trevo

Well-known member
Power User
VIP
Local time
5:02 PM
Posts
622
OS
windows 11 Pro
Just got this Windows Update from Microsoft.
 

My Computer My Computer

At a glance

windows 11 Pro11th Gen Intel(R) Core(TM) i7-11800H @ 2.30GH...16 GBNVIDIA GeForce RTX 3050 Ti
OS
windows 11 Pro
Computer type
Laptop
Manufacturer/Model
Dell XPS 15 9510
CPU
11th Gen Intel(R) Core(TM) i7-11800H @ 2.30GHz (16 CPUs
Memory
16 GB
Graphics Card(s)
NVIDIA GeForce RTX 3050 Ti
Hard Drives
512GB Solid State Drive
Browser
Firefox
Same here
1777783794484.webp
 

My Computer My Computer

At a glance

Windows 11Intel 13th96GBRTX 4050 6GB
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
Acer Nitro V15
CPU
Intel 13th
Memory
96GB
Graphics Card(s)
RTX 4050 6GB
Monitor(s) Displays
amazon fire tv 50"
Screen Resolution
3840x2160

My Computer My Computer

At a glance

Windows 11AMD Ryzen 8700G64 GBOnboard
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
Generic
CPU
AMD Ryzen 8700G
Motherboard
Gigabyte B650 UD AC
Memory
64 GB
Graphics Card(s)
Onboard
Sound Card
Onboard
Monitor(s) Displays
Del U2723QE
Screen Resolution
3840 x 2160
Hard Drives
Corsiar MP600 1TB
PSU
Silverstone 750 GOLD
Case
Silverstone FARA 513
Have you done any manual updates to your boot certificates? e.g. using Garlins Scripts or Mosby.
No, I am not familiar with Garlins Scripts or Mosby.
 

My Computer My Computer

At a glance

Windows 11Intel 13th96GBRTX 4050 6GB
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
Acer Nitro V15
CPU
Intel 13th
Memory
96GB
Graphics Card(s)
RTX 4050 6GB
Monitor(s) Displays
amazon fire tv 50"
Screen Resolution
3840x2160
You have a supported PC (meaning Windows can install the Secure Boot updates by itself). A restart is required for the changes to take effect.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
On my computer (located under Other Updates): "Successfully installed on ‎5/‎15/‎2026: Secure Boot Allowed Signature Database (DB) Update"

However, under Device Security > Secure Boot (which is now check marked green) this dialog still displays:

"Secure boot is on but your device is using an older boot trust configuration that should be updated.
There is not enough data to classify your device for automatic update. Visit link below for more info"

I assumed that statement would have changed once I received & installed the Secure Boot DB (& associated Key Exchange Key?) although another automatic Windows Update might be required to fully complete the updated boot trust configuration process.
 

My Computer My Computer

At a glance

Win 11 Pro 25H2 ARM64 (Parallels VM) _ 26200....Apple Silicon M1 / 3.20 GHz (4 processors)16 GB
OS
Win 11 Pro 25H2 ARM64 (Parallels VM) _ 26200.8875
Computer type
Laptop
Manufacturer/Model
MacBook Pro (13-inch, M1, 2020)
CPU
Apple Silicon M1 / 3.20 GHz (4 processors)
Memory
16 GB
Monitor(s) Displays
13.3-inch (2560 × 1600)
Antivirus
N360 for Mac / Win / Win Defender
Other Info
Parallels Pro 26.4.0/ macOS Tahoe 26.5.2
If you get the "not enough data to classify your device", your UEFI is probably missing the KEK CA 2023 update (unsupported BIOS). You should download this check script, and see where your PC stands. Whenever there isn't enough telemetry data to suggest a specific model can be updated, Windows will hold updates back.

garlin's PowerShell scripts for updating Secure Boot CA 2023

Code:
Check-UEFI.bat -Verbose
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
2 days ago, an update to Parallels Desktop version 26.3.3 resolved the Secure Boot issue for my VM:

"Existing Windows 11 virtual machines will be updated to the new Secure Boot certificates automatically upon Windows restart after installing the Parallels Tools update.

After running this PowerShell command: ([System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match 'Windows UEFI CA 2023') I received a TRUE result as a certificate update confirmation.

I assumed I would get a new Secure Boot status message stating "all required certificates have been applied" (or seeing a green badge) means your certificates are fully updated" although the status message is still "Secure boot is on but your device is using an older boot trust configuration that should be updated. There is not enough data to classify your device for automatic update"
 

My Computer My Computer

At a glance

Win 11 Pro 25H2 ARM64 (Parallels VM) _ 26200....Apple Silicon M1 / 3.20 GHz (4 processors)16 GB
OS
Win 11 Pro 25H2 ARM64 (Parallels VM) _ 26200.8875
Computer type
Laptop
Manufacturer/Model
MacBook Pro (13-inch, M1, 2020)
CPU
Apple Silicon M1 / 3.20 GHz (4 processors)
Memory
16 GB
Monitor(s) Displays
13.3-inch (2560 × 1600)
Antivirus
N360 for Mac / Win / Win Defender
Other Info
Parallels Pro 26.4.0/ macOS Tahoe 26.5.2
Checking a single cert doesn't provide a complete summary of the situation. You won't get a change in the Security Center status until all of the CA 2023 certs are installed, Windows has switched to a new boot manager, AND rebooted the system.

For a VM, typically they update the "BIOS" so it appears you have new factory defaults. The Secure Boot update task runs twice a day, and will detect new certs are present, and finish the update process. Because a VM isn't a physical PC, it won't be listed in the Confidence Bucket JSON as a "known" device.

Running the update script and restarting Windows should get you the preferred Security Center status. There's no point in waiting for MS to decide if your device is ready, it probably is ready after the Parallels update.
 
Last edited:

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
garlin,

I appreciate your detailed information, instructions, and the time you have expended throughout the forums on the Secure Boot matter and others. Your explanations are precise, logical and intuitive.
 

My Computer My Computer

At a glance

Win 11 Pro 25H2 ARM64 (Parallels VM) _ 26200....Apple Silicon M1 / 3.20 GHz (4 processors)16 GB
OS
Win 11 Pro 25H2 ARM64 (Parallels VM) _ 26200.8875
Computer type
Laptop
Manufacturer/Model
MacBook Pro (13-inch, M1, 2020)
CPU
Apple Silicon M1 / 3.20 GHz (4 processors)
Memory
16 GB
Monitor(s) Displays
13.3-inch (2560 × 1600)
Antivirus
N360 for Mac / Win / Win Defender
Other Info
Parallels Pro 26.4.0/ macOS Tahoe 26.5.2
With today's Patch Tuesday (26200.8655) my VM Secure Boot was automatically updated under Device Security >

"Secure Boot is on and all required updates have been applied. No further certificate changes are needed."

Thanks again to garlin. I decided to wait for MS to update instead of running garlin's update script to see if this Patch Tuesday would update/change the certificate. Had it not, the script was next.
 

My Computer My Computer

At a glance

Win 11 Pro 25H2 ARM64 (Parallels VM) _ 26200....Apple Silicon M1 / 3.20 GHz (4 processors)16 GB
OS
Win 11 Pro 25H2 ARM64 (Parallels VM) _ 26200.8875
Computer type
Laptop
Manufacturer/Model
MacBook Pro (13-inch, M1, 2020)
CPU
Apple Silicon M1 / 3.20 GHz (4 processors)
Memory
16 GB
Monitor(s) Displays
13.3-inch (2560 × 1600)
Antivirus
N360 for Mac / Win / Win Defender
Other Info
Parallels Pro 26.4.0/ macOS Tahoe 26.5.2
The CA 2023 cert migration is an one-time event. Due to security fixes, June 2026 rolled out a new version of the boot manager and a higher DBX SVN along with it. Your Security Center status only refers to the basic Secure Boot certs.

If you see this message, Windows will handle installing the new boot manager for you. It might not happen right away, but within 24 hours.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Back
Top Bottom