Secure Boot Certificate problems with GT1 Mega


TomTiddler167

Member
Member
Local time
9:01 PM
Posts
5
OS
Windows 11 25H2 Pro
I'm having trouble with Secure Boot on a Geekom GT1 Mega Intel version (Intel Core Ultra 9 185H). No matter what I do, I can't get it to install the latest certificates, and the most recent attempt left me unable to enable Secure Boot!

Is there any way to 'reset' the BIOS so that I can start again??
 
Windows Build/Version
Win 11 Pro 25H2 Build

My Computer My Computer

At a glance

Windows 11 25H2 ProIntel Core Ultra 9 185H32 GBNvidia GeForce RTX 4070
OS
Windows 11 25H2 Pro
Computer type
PC/Desktop
Manufacturer/Model
Geekom GT1 Mega Intel version
CPU
Intel Core Ultra 9 185H
Motherboard
GT1 Mega (U3E1)
Memory
32 GB
Graphics Card(s)
Nvidia GeForce RTX 4070
Sound Card
Realtek HiDef Audio
Monitor(s) Displays
N/A
Screen Resolution
N/A
Hard Drives
3 x 2TB SSD 2.5 Inch
PSU
N/A
Case
N/A
Internet Speed
250 Mb/s Up ; 250 Mb/s Down
Browser
MS Edge
Antivirus
MS Security & Fortect
Hello @TomTiddler167 and welcome to ElevenForum.


Also, here's ten points for filling out your computer specs. :-)





Here's some other things that you may find useful...



 

My Computers My Computers

  • At a glance

    Win 11 Home ♦♦♦26300.9550 ♦♦♦♦♦♦♦26H2AMD Ryzen 7 3700XG.Skill (F4-3200C14D-16GTZKW)EVGA RTX 2070 (08G-P4-2171-KR)
    OS
    Win 11 Home ♦♦♦26300.9550 ♦♦♦♦♦♦♦26H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® [May 2020]
    CPU
    AMD Ryzen 7 3700X
    Motherboard
    Asus Pro WS X570-ACE (BIOS 5302)
    Memory
    G.Skill (F4-3200C14D-16GTZKW)
    Graphics Card(s)
    EVGA RTX 2070 (08G-P4-2171-KR)
    Sound Card
    Realtek ALC1220P / ALC S1220A
    Monitor(s) Displays
    Dell U3011 30"
    Screen Resolution
    2560 x 1600
    Hard Drives
    2x Samsung 860 EVO 500GB,
    WD 4TB Black FZBX - SATA III,
    WD 8TB Black FZBX - SATA III,
    DRW-24B1ST CD/DVD Burner
    PSU
    PC Power & Cooling 750W Quad EPS12V
    Case
    Cooler Master ATCS 840 Tower
    Cooling
    CM Hyper 212 EVO (push/pull)
    Keyboard
    Ducky DK9008 Shine II Blue LED
    Mouse
    Logitech Optical M-100
    Internet Speed
    300/300
    Browser
    Firefox (latest)
    Antivirus
    Bitdefender Total Security
    Other Info
    Speakers: Klipsch Pro Media 2.1
  • At a glance

    Windows XP Pro 32bit w/SP3AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Operating System
    Windows XP Pro 32bit w/SP3
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® (not in use)
    CPU
    AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)
    Motherboard
    ASUS M2N32-SLI Deluxe Wireless Edition
    Memory
    TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)
    Graphics card(s)
    EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Sound Card
    Onboard
    Monitor(s) Displays
    ViewSonic G90FB Black 19" Professional (CRT)
    Screen Resolution
    up to 2048 x 1536
    Hard Drives
    WD 36GB 10,000rpm Raptor SATA
    Seagate 80GB 7200rpm SATA
    Lite-On LTR-52246S CD/RW
    Lite-On LH-18A1P CD/DVD Burner
    PSU
    PC Power & Cooling Silencer 750 Quad EPS12V
    Case
    Generic Beige case, 80mm fans
    Cooling
    ZALMAN 9500A 92mm CPU Cooler
    Keyboard
    Logitech Classic Keybooard 200
    Mouse
    Logitech Optical M-BT96a
    Internet Speed
    300/300
    Browser
    Firefox 3.x ??
    Antivirus
    Symantec (Norton)
    Other Info
    Still assembled, still runs. Haven't turned it on for 15 years?

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
To Garlin ...

1) Yes

2) I thought I did this, but that immediately preceeded the inability to enable Secure Boot, so I suspect I did something wrong :confused:
 

My Computer My Computer

At a glance

Windows 11 25H2 ProIntel Core Ultra 9 185H32 GBNvidia GeForce RTX 4070
OS
Windows 11 25H2 Pro
Computer type
PC/Desktop
Manufacturer/Model
Geekom GT1 Mega Intel version
CPU
Intel Core Ultra 9 185H
Motherboard
GT1 Mega (U3E1)
Memory
32 GB
Graphics Card(s)
Nvidia GeForce RTX 4070
Sound Card
Realtek HiDef Audio
Monitor(s) Displays
N/A
Screen Resolution
N/A
Hard Drives
3 x 2TB SSD 2.5 Inch
PSU
N/A
Case
N/A
Internet Speed
250 Mb/s Up ; 250 Mb/s Down
Browser
MS Edge
Antivirus
MS Security & Fortect
1. Leave Secure Boot disabled for now.

2. Download the ZIP from here, and run:
Code:
Check-UEFI.bat -Verbose

3. Post the script's results so we can see what your current settings.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Here's the output of Check_UEFI

------------------------
Secure Boot: OFF
Virtualization Based Security: ON
BitLocker on (C:) OFF

UEFI PK Cert
------------
DO NOT TRUST - OEM Test Certificate
Platform Key is UNTRUSTED.

UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011

UEFI DBX Certs
--------------
(NONE)

EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.

Registry: "WindowsUEFICA2023Capable" = 0
[Windows UEFI CA 2023] not in UEFI DB.

[OPTIONAL] SkuSiPolicy.p7b (for VBS) is MISSING.

REQUIRED ACTION
===============

MANUAL UPDATE of the BIOS is required.

Enter the BIOS menu, and search for User or Custom Mode option of updating the UEFI PK or KEK keys.
If your BIOS doesn't support this feature, select Setup Mode to clear all certs.

IMPORTANT: Disable Windows Hello PIN before clearing certs.

OPTION 1: To install [UEFI CA 2023] certs

Update_UEFI-CA2023.ps1


OPTION 2: To install [UEFI CA 2023] certs and REVOKE the [PCA 2011] cert

Update_UEFI-CA2023.ps1 -Revoke
 

My Computer My Computer

At a glance

Windows 11 25H2 ProIntel Core Ultra 9 185H32 GBNvidia GeForce RTX 4070
OS
Windows 11 25H2 Pro
Computer type
PC/Desktop
Manufacturer/Model
Geekom GT1 Mega Intel version
CPU
Intel Core Ultra 9 185H
Motherboard
GT1 Mega (U3E1)
Memory
32 GB
Graphics Card(s)
Nvidia GeForce RTX 4070
Sound Card
Realtek HiDef Audio
Monitor(s) Displays
N/A
Screen Resolution
N/A
Hard Drives
3 x 2TB SSD 2.5 Inch
PSU
N/A
Case
N/A
Internet Speed
250 Mb/s Up ; 250 Mb/s Down
Browser
MS Edge
Antivirus
MS Security & Fortect
From your output, this BIOS should be ready to accept Secure Boot updates from Windows.

1. Geekom shouldn't be using the "DO NOT TRUST - OEM Test Certificate". It's a default copy of the BIOS they (or their Chinese OEM supplier) are licensing, and nobody changed the standard test example for the PK. While it works perfectly fine with "DO NOT TRUST", it's generally frowned upon for security reasons.

The script warns you about these types of "DO NOT TRUST" PK's as a public service.

2. You should be able to enable Secure Boot mode, and restart Windows. Is the problem that you can't enable Secure Boot mode? Is the BIOS setup for pure UEFI mode? (no CSM or UEFI + CSM mode)
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Yes, when I enable Secure Boot in the BIOS I get a warning message. I can provide a photo of that screen if it helps.
 

My Computer My Computer

At a glance

Windows 11 25H2 ProIntel Core Ultra 9 185H32 GBNvidia GeForce RTX 4070
OS
Windows 11 25H2 Pro
Computer type
PC/Desktop
Manufacturer/Model
Geekom GT1 Mega Intel version
CPU
Intel Core Ultra 9 185H
Motherboard
GT1 Mega (U3E1)
Memory
32 GB
Graphics Card(s)
Nvidia GeForce RTX 4070
Sound Card
Realtek HiDef Audio
Monitor(s) Displays
N/A
Screen Resolution
N/A
Hard Drives
3 x 2TB SSD 2.5 Inch
PSU
N/A
Case
N/A
Internet Speed
250 Mb/s Up ; 250 Mb/s Down
Browser
MS Edge
Antivirus
MS Security & Fortect
That will probably help.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Never mind. You need to perform the cert updates since CA 2023 keys are missing (other than KEK CA 2023).

1. Leave Secure Boot disabled.

2. Run the update script.
Code:
Update-UEFI.bat

3. Run the check script again
Code:
Check-UEFI.bat -Verbose

You should now see (5x) UEFI DB Certs listed. After that you should be able to turn on Secure Boot.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Thankyou, thankyou, thankyou!!!! Finally, I appear to have got it thanks to your help, SecureBoot enabled successfully and seems like all the certs are in place.
 

My Computer My Computer

At a glance

Windows 11 25H2 ProIntel Core Ultra 9 185H32 GBNvidia GeForce RTX 4070
OS
Windows 11 25H2 Pro
Computer type
PC/Desktop
Manufacturer/Model
Geekom GT1 Mega Intel version
CPU
Intel Core Ultra 9 185H
Motherboard
GT1 Mega (U3E1)
Memory
32 GB
Graphics Card(s)
Nvidia GeForce RTX 4070
Sound Card
Realtek HiDef Audio
Monitor(s) Displays
N/A
Screen Resolution
N/A
Hard Drives
3 x 2TB SSD 2.5 Inch
PSU
N/A
Case
N/A
Internet Speed
250 Mb/s Up ; 250 Mb/s Down
Browser
MS Edge
Antivirus
MS Security & Fortect

Latest Support Threads

Back
Top Bottom