Secure boot - database keys needing installed?


DeltaD

New member
Local time
7:01 PM
Posts
17
OS
WIndows 11 25H2: 26200.8457
I've an ASRock MB in a Win 11 PC bought in Feb. I'm unsure why but just discovered this week that the Secure Boot element is enabled but oddly has a note below saying "Not Active" - how do I get it to function fully?
 
Windows Build/Version
25H2 26200.8457

My Computer My Computer

At a glance

WIndows 11 25H2: 26200.8457Intel Core i3 1210016 Gb
OS
WIndows 11 25H2: 26200.8457
Computer type
PC/Desktop
CPU
Intel Core i3 12100
Motherboard
Gigabyte H610M K
Memory
16 Gb
Case
Antec
Keyboard
Ms Nat Keyboard Pro
Mouse
Penguin ambidextrous.

My Computers My Computers

  • At a glance

    Windows 11 HomeAMD Athlon Silver 3050U8GBRadeon Graphics
    OS
    Windows 11 Home
    Computer type
    Laptop
    Manufacturer/Model
    Acer Aspire 3 A315-23-R9VY
    CPU
    AMD Athlon Silver 3050U
    Memory
    8GB
    Graphics Card(s)
    Radeon Graphics
    Monitor(s) Displays
    laptop screen
    Screen Resolution
    1366x768 native resolution, up to 2560x1440 with Radeon Virtual Super Resolution
    Hard Drives
    1TB Samsung EVO 870 SSD (from April 2026: 250GB EVO 850)
    Internet Speed
    150 Mbps
    Browser
    Edge, Firefox
    Antivirus
    Defender
    Other Info
    fully 'Windows 11 ready' laptop. Windows 10 C: partition migrated from my old unsupported 'main machine' then upgraded to 11. A test migration ran Insider builds for 2 months. When 11 was released on 5th October 2021 it was re-imaged back to 10 and was offered the upgrade in Windows Update on 20th October. Windows Update offered the 22H2 Feature Update on 20th September 2022. It got the 23H2 Feature Update on 4th November 2023 through Windows Update, 24H2 on 3rd October 2024 through Windows Update by setting the Target Release Version for 24H2, and 25H2 on 30th September 2025 through Windows Update by setting the Target Release Version for 25H2.

    UPDATE - 11 April 2026: due to mechanical deterioration this PC has been retired from active duty. The OS with all software and files has been migrated to my System Seven in 'Other systems' to carry on as my general purpose 'main machine'.
  • At a glance

    Windows 11 ProIntel® Core™ i5-520M8GB(integrated graphics) Intel HD Graphics
    Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Dell Latitude E4310
    CPU
    Intel® Core™ i5-520M
    Motherboard
    0T6M8G
    Memory
    8GB
    Graphics card(s)
    (integrated graphics) Intel HD Graphics
    Screen Resolution
    1366x768
    Hard Drives
    500GB Crucial MX500 SSD
    Browser
    Firefox, Edge
    Antivirus
    Defender
    Other Info
    unsupported machine: Legacy bios, MBR, TPM 1.2, upgraded from W10 to W11 using W10/W11 hybrid install media workaround.

    In-place upgrade to 22H2 using ISO and a workaround.
    Feature Update to 23H2 by manually installing the Enablement Package.
    In-place upgrade to 24H2 using hybrid 23H2/24H2 install media.
    Upgraded to 25H2 by Enablement Package.

    Also running Insider Dev, and Canary builds and Windows 10 as native boot .vhdx.
  • My SYSTEM THREE is a Dell Latitude 5410, i7-10610U, 32GB RAM, 512GB NVMe ssd, supported device running Windows 11 Pro.

    My SYSTEM FOUR is a 2-in-1 convertible Lenovo Yoga 11e 20DA, Celeron N2930, 8GB RAM, 256GB ssd. Unsupported device: currently running Win10 Pro, plus Win11 Pro RTM and Insider Dev, Beta, and RP 24H2 as native boot vhdx.

    My SYSTEM FIVE is a Dell Latitude 3190 2-in-1, Pentium Silver N5030, 8GB RAM, 1TB NVMe ssd, supported device running Windows 11 Pro, plus Insider Beta, Dev, and Canary builds (and a few others) as a native boot .vhdx.

    My SYSTEM SIX is a Dell Latitude 5550, Core Ultra 7 165H, 64GB RAM, 1TB NVMe SSD, supported device, Windows 11 Pro 24H2, Hyper-V host machine. Updated to 25H2 on 30th September 2025.

    My SYSTEM SEVEN is a Lenovo Thinkpad T580, Intel Core i7-8650U, 16GB RAM, 512GB NVMe SSD + 2nd 512GB NVMe SSD, a supported device for Windows 11. This is my current general purpose 'main machine'. The installed Windows 11 Home from my System One has been migrated to this machine.
If you own a motherboard that was manufactured in the past two years, it should already have the new Secure Boot certs in the factory BIOS or would be available in the current supported firmware.

Secure Boot mode is either enabled or it's not. There is no in-between. Maybe Secure Boot mode was never enabled when it was shipped, but you can go into the BIOS menus and turn it on.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
You're telling me! We're all confused by this ;)

All, that is, except Garlin who is the 'guru-supreme' on these matters and has produced scripts to help....

garlin's PowerShell scripts for updating Secure Boot CA 2023
Appreciate that help, but it's rather beyond my level of expertise or at least what I'm comfortable tackling. So I presume it's going to be a visit to my local friendly PC engineer to sort as I gather it's not wise to leave secure boot disabled?
 

My Computer My Computer

At a glance

WIndows 11 25H2: 26200.8457Intel Core i3 1210016 Gb
OS
WIndows 11 25H2: 26200.8457
Computer type
PC/Desktop
CPU
Intel Core i3 12100
Motherboard
Gigabyte H610M K
Memory
16 Gb
Case
Antec
Keyboard
Ms Nat Keyboard Pro
Mouse
Penguin ambidextrous.
If you own a motherboard that was manufactured in the past two years, it should already have the new Secure Boot certs in the factory BIOS or would be available in the current supported firmware.

Secure Boot mode is either enabled or it's not. There is no in-between. Maybe Secure Boot mode was never enabled when it was shipped, but you can go into the BIOS menus and turn it on.
No - there's currently no option to enable it. Google said I should disable CSM but it was also disabled without any option to enable, stating that I needed an external graphics card weirdly!
 

My Computer My Computer

At a glance

WIndows 11 25H2: 26200.8457Intel Core i3 1210016 Gb
OS
WIndows 11 25H2: 26200.8457
Computer type
PC/Desktop
CPU
Intel Core i3 12100
Motherboard
Gigabyte H610M K
Memory
16 Gb
Case
Antec
Keyboard
Ms Nat Keyboard Pro
Mouse
Penguin ambidextrous.
It does sound like you're not familiar with the Secure Boot details, but if you have a local PC expert to review your system then try that approach first. The critical deadline for the Secure Boot migration is mid-October, so you have time to sort this out.

Secure Boot helps improve your system's protection from UEFI-level rootkits. It's an actual threat out there, and if you play some online games, having Secure Boot is a requirement for anti-cheating purposes.

A decent PC expert can teach you the relevant settings in the BIOS.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Thanks Garlin - I did wonder whether I really needed to delve into all this stuff at all, & while comfortable in the BIOS, some settings like this just want a bit more than I'm happy about messing around with - I've a neat habit of fixing things till they break!! So yeh - I'll get the local guy to see if he can sort it since he sold me this PC anyway :-) Appreciate your input.
 

My Computer My Computer

At a glance

WIndows 11 25H2: 26200.8457Intel Core i3 1210016 Gb
OS
WIndows 11 25H2: 26200.8457
Computer type
PC/Desktop
CPU
Intel Core i3 12100
Motherboard
Gigabyte H610M K
Memory
16 Gb
Case
Antec
Keyboard
Ms Nat Keyboard Pro
Mouse
Penguin ambidextrous.
As far as enabling secure boot, the user manual for that board says it's under the boot tab in uefi bios.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8655i9-10900 10 core 20 threads32 gbnone-Intel UHD Graphics 630
    OS
    Windows 11 Pro 25H2 26200.8655
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    2x1tb Solidigm m.2 nvme /External drives 512gb Samsung m.2 sata+2tb Kingston m2.nvme
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    #1 Edge #2 Firefox
    Antivirus
    Defender+MWB Premium
  • At a glance

    Windows 11 Pro 24H2 26200.8457AMD Ryzen 7 6800U32 gbintegrated
    Operating System
    Windows 11 Pro 24H2 26200.8457
    Computer type
    PC/Desktop
    Manufacturer/Model
    Beelink Mini PC SER5
    CPU
    AMD Ryzen 7 6800U
    Memory
    32 gb
    Graphics card(s)
    integrated
    Sound Card
    integrated
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Crucial nvme
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    still too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender
    Other Info
    System 3 is non compliant Dell 9020 i7-4770/24gb ram Win11 PRO 26200.8457
As far as enabling secure boot, the user manual for that board says it's under the boot tab in uefi bios.
Thanks glasskuter - but the problem isn't in the finding of it, it's the actual enabling since it's not providing any option to do so fully - if you read my 1st post that's the message underneath it. Seems there's a bit more to the problem than initially obvious in the BIOS. :(
 

My Computer My Computer

At a glance

WIndows 11 25H2: 26200.8457Intel Core i3 1210016 Gb
OS
WIndows 11 25H2: 26200.8457
Computer type
PC/Desktop
CPU
Intel Core i3 12100
Motherboard
Gigabyte H610M K
Memory
16 Gb
Case
Antec
Keyboard
Ms Nat Keyboard Pro
Mouse
Penguin ambidextrous.
Is CSM disabled?
Screenshot 2026-06-17 124434.webp
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8655i9-10900 10 core 20 threads32 gbnone-Intel UHD Graphics 630
    OS
    Windows 11 Pro 25H2 26200.8655
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    2x1tb Solidigm m.2 nvme /External drives 512gb Samsung m.2 sata+2tb Kingston m2.nvme
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    #1 Edge #2 Firefox
    Antivirus
    Defender+MWB Premium
  • At a glance

    Windows 11 Pro 24H2 26200.8457AMD Ryzen 7 6800U32 gbintegrated
    Operating System
    Windows 11 Pro 24H2 26200.8457
    Computer type
    PC/Desktop
    Manufacturer/Model
    Beelink Mini PC SER5
    CPU
    AMD Ryzen 7 6800U
    Memory
    32 gb
    Graphics card(s)
    integrated
    Sound Card
    integrated
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Crucial nvme
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    still too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender
    Other Info
    System 3 is non compliant Dell 9020 i7-4770/24gb ram Win11 PRO 26200.8457
Yep & I can't enable it either - gjves me a msg about needing an external graphic card!! If it's not one thing.... :-)
 

My Computer My Computer

At a glance

WIndows 11 25H2: 26200.8457Intel Core i3 1210016 Gb
OS
WIndows 11 25H2: 26200.8457
Computer type
PC/Desktop
CPU
Intel Core i3 12100
Motherboard
Gigabyte H610M K
Memory
16 Gb
Case
Antec
Keyboard
Ms Nat Keyboard Pro
Mouse
Penguin ambidextrous.
This might be related to the onboard graphics, if it needs something called the Option ROM. Your PC builder show know these details.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7

Latest Support Threads

Back
Top Bottom