Solved Secure Boot question


If you never updated the 24H2 or 25H2 ISO's, or even want to install 21H2... you can always temporarily disable Secure Boot to boot from the DVD or USB device. Secure Boot is never required to install Windows. It's recommended that you enable it, whenever possible.

In fact, before Rufus acquired a MS-signed boot file, Paul Batard used to argue with users and tell them to disable Secure Boot if their BIOS was incompatible with Rufus. And he would say turn Secure Boot on after Windows was installed.

That will still work next year.
 

My Computer

System One

  • OS
    Windows 7

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC12WSHi7
    CPU
    12th Gen Core i7-1260P
    Motherboard
    NUC12WSBi7
    Memory
    64 GB Micron PC4-25600
    Graphics Card(s)
    Intel Iris Xe Graphics
    Sound Card
    on-board Realtek HD Audio
    Monitor(s) Displays
    Dell U3219Q
    Screen Resolution
    3840 x 2160
    Hard Drives
    Samsung SSD 990 PRO 1TB
    Crucial MX500 2 TB
    Antivirus
    Microsoft Defender
but also means i can re-install Windows 11 24H2 and/or 25H2
You can build ISO's with the new cert through UUP dump, which pulls all the pieces from the MS servers.

1764735627631.webp
 

My Computers

System One System Two

  • OS
    Win 11 Pro 25H2 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel® Core™ i7-14700K
    Motherboard
    ASUS TUF Z690-PLUS WIFI BIOS 4505 11/29/25
    Memory
    G.SKILL Ripjaws S5 Series 64GB (2 x 32GB) DDR5
    Graphics Card(s)
    ASUS GeForce RTX 4070 Super 12GB
    Sound Card
    Sound Blaster AE-5 Plus
    Monitor(s) Displays
    ASUS TUF Gaming 27" 2K HDR Gaming
    Screen Resolution
    2560 x 1440
    Hard Drives
    Samsung 990 Pro 1TB NVMe (Win 11 25H2)
    SK hynix P41 500GB NVMe 25H2 DEV/Games
    SK hynix P41 2TB NVMe (x3)
    Crucial P3 Plus 4TB
    PSU
    Corsair RM850x Shift
    Case
    Antec Dark Phantom DP502 FLUX
    Cooling
    Corsair Nautilus 360 RS AIO
    Keyboard
    Logitech MK 320
    Mouse
    Razer Basilisk V3
    Internet Speed
    350Mbs
    Browser
    Firefox
    Antivirus
    Winows Security
    Other Info
    MR 8.1 Home

    System 3 Specs
    Win 11 Pro 25H2 26200.8524
    ASUS PRIME Z370-P II BIOS 3004 7/12/21
    Intel Core i7-8700 CPU @ 3.20GHz
    32GB DDR4 RAM (4x8)
    iGPU Intel UHD Graphics 630
  • Operating System
    Win 11 Pro 25H2 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    Self Built
    CPU
    Intel Core i7-11700F
    Motherboard
    Asus TUF Gaming Z590 Plus WiFi (BIOS 2803)
    Memory
    64 GB DDR4
    Graphics card(s)
    MSI GeForce RTX 3060 Ventus 2X 12GB
    Sound Card
    SoundBlaster Audigy Fx V2
    Monitor(s) Displays
    Samsung F27T350
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung 980 Pro 1TB
    Samsung 970 EVO Plus 2TB
    Samsung 870 EVO 500GB SSD
    PSU
    Corsair HX750
    Case
    Cougar MX330-G Window
    Cooling
    Thermalright Frozen Edge 240 Black AIO
    Internet Speed
    350Mbps
    Browser
    Firefox
    Antivirus
    Windows Security
i wonder how many people are able or willing to do all of that when all that is needed is to leave the 2011 cert in place
until MS sort it out as the 2011 cert has been in place for the last 15 years another few months is not going to cause any major issues.

but the 2023 cert can be used as default while the 2011 cert is still in place.
best of luck Steve ..
 

My Computers

System One System Two

  • OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
I was about to do part B and I thought about the Registry was still showing "inprogress" after I done it yesterday. After reading these posts just now, I did run the commands with the script and seen that cert 2023 was ALLOWED. So I checked the registry and it is now showing UPDATED. So I don't think I need to do anything further.
Greatly appreciate all your guidance though this matter.

Cheers
 

My Computer

System One

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    ASUS
    CPU
    Intel Core i7-11700K Desktop Processor 8 Cores
    Motherboard
    ASUS ROG Strix Z590-A Gaming WiFi LGA 1200
    Memory
    Corsair Vengeance LPX 32GB (2 x 16GB) DDR4 DRAM 3600MHz
    Graphics Card(s)
    ASUS GTX ROG STRIX 1080 8GB
    Sound Card
    Sound Blaster Z SE
    Monitor(s) Displays
    ASUS VG34VQL1B plus a Samsung 60" Smartv
    Screen Resolution
    3440x1440, 165Hz
    Hard Drives
    Samsung 980 Series - (OS)1TB Pro Gen4 NVMe M.2, 1TB Gen3. x4 NVMe 1.4 - M.2, WD 1TB, WD 500GB, WD 350GB
    PSU
    Silverstone Olympia OP1000W PSW
    Case
    Phanteks Enthoo Pro
    Cooling
    Noctua NH-D15 SSO2 D-Type Premium CPU Cooler, NF-A15 x 2 PWM Fans
    Keyboard
    Corsair K70 RGB
    Mouse
    Logitech 310 wireless
    Internet Speed
    1 GB
    Browser
    Firefox
    Antivirus
    ESET Internet Security
    Other Info
    Testing Windows 10 Pro on 350GB drive
For me, it's okay.
 

Attachments

My Computer

System One

  • OS
    windows 11 25H2
    Computer type
    Laptop
    Manufacturer/Model
    ASUS Vivobook 15 (X1504)
    Motherboard
    Intel Alder Lake-P PCH
    Memory
    24GB
    Graphics Card(s)
    iris xe
    Sound Card
    realtek
    Screen Resolution
    1920X1080
    Hard Drives
    Samsung SSD 990 PRO 1TB
    Browser
    edge
    Antivirus
    eset anti virus
I decided to try same thing on my new ASUS Vivobook. Secure Boot is already enabled so I ran the upgrade to get cert 2023. All went well but after the 2 reboots the registry is still showing IEFICA2023Status as "NotStarted".
Should I wait for that to change to "inprogress" before I proceed to Part B ?

cheers
 

My Computer

System One

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    ASUS
    CPU
    Intel Core i7-11700K Desktop Processor 8 Cores
    Motherboard
    ASUS ROG Strix Z590-A Gaming WiFi LGA 1200
    Memory
    Corsair Vengeance LPX 32GB (2 x 16GB) DDR4 DRAM 3600MHz
    Graphics Card(s)
    ASUS GTX ROG STRIX 1080 8GB
    Sound Card
    Sound Blaster Z SE
    Monitor(s) Displays
    ASUS VG34VQL1B plus a Samsung 60" Smartv
    Screen Resolution
    3440x1440, 165Hz
    Hard Drives
    Samsung 980 Series - (OS)1TB Pro Gen4 NVMe M.2, 1TB Gen3. x4 NVMe 1.4 - M.2, WD 1TB, WD 500GB, WD 350GB
    PSU
    Silverstone Olympia OP1000W PSW
    Case
    Phanteks Enthoo Pro
    Cooling
    Noctua NH-D15 SSO2 D-Type Premium CPU Cooler, NF-A15 x 2 PWM Fans
    Keyboard
    Corsair K70 RGB
    Mouse
    Logitech 310 wireless
    Internet Speed
    1 GB
    Browser
    Firefox
    Antivirus
    ESET Internet Security
    Other Info
    Testing Windows 10 Pro on 350GB drive
I decided to try same thing on my new ASUS Vivobook. Secure Boot is already enabled so I ran the upgrade to get cert 2023. All went well but after the 2 reboots the registry is still showing IEFICA2023Status as "NotStarted".
Should I wait for that to change to "inprogress" before I proceed to Part B ?

cheers

repeat part A please
leave about 5 minutes between the two restarts for part A.

after the second restart check the registry
then check with this PowerShell command
[System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match "Windows UEFI CA 2023"

if the output comes back as 'True'
then proceed with part B.

best of luck Steve ..
 

My Computers

System One System Two

  • OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
repeat part A please
leave about 5 minutes between the two restarts for part A.

after the second restart check the registry
then check with this PowerShell command


if the output comes back as 'True'
then proceed with part B.

best of luck Steve ..
Thanks for the reply. I will do that and report back
 

My Computer

System One

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    ASUS
    CPU
    Intel Core i7-11700K Desktop Processor 8 Cores
    Motherboard
    ASUS ROG Strix Z590-A Gaming WiFi LGA 1200
    Memory
    Corsair Vengeance LPX 32GB (2 x 16GB) DDR4 DRAM 3600MHz
    Graphics Card(s)
    ASUS GTX ROG STRIX 1080 8GB
    Sound Card
    Sound Blaster Z SE
    Monitor(s) Displays
    ASUS VG34VQL1B plus a Samsung 60" Smartv
    Screen Resolution
    3440x1440, 165Hz
    Hard Drives
    Samsung 980 Series - (OS)1TB Pro Gen4 NVMe M.2, 1TB Gen3. x4 NVMe 1.4 - M.2, WD 1TB, WD 500GB, WD 350GB
    PSU
    Silverstone Olympia OP1000W PSW
    Case
    Phanteks Enthoo Pro
    Cooling
    Noctua NH-D15 SSO2 D-Type Premium CPU Cooler, NF-A15 x 2 PWM Fans
    Keyboard
    Corsair K70 RGB
    Mouse
    Logitech 310 wireless
    Internet Speed
    1 GB
    Browser
    Firefox
    Antivirus
    ESET Internet Security
    Other Info
    Testing Windows 10 Pro on 350GB drive
I done part A and rebooted twice within 5 minutes and checked to see if 2023 cert was available and it came back "true".
I opened regedit and the servicing is still showing NotStarted. WindowsUEFICA2023Capable 0x000001 (1)

Even if it is not started, should I proceed with Part B?
 

My Computer

System One

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    ASUS
    CPU
    Intel Core i7-11700K Desktop Processor 8 Cores
    Motherboard
    ASUS ROG Strix Z590-A Gaming WiFi LGA 1200
    Memory
    Corsair Vengeance LPX 32GB (2 x 16GB) DDR4 DRAM 3600MHz
    Graphics Card(s)
    ASUS GTX ROG STRIX 1080 8GB
    Sound Card
    Sound Blaster Z SE
    Monitor(s) Displays
    ASUS VG34VQL1B plus a Samsung 60" Smartv
    Screen Resolution
    3440x1440, 165Hz
    Hard Drives
    Samsung 980 Series - (OS)1TB Pro Gen4 NVMe M.2, 1TB Gen3. x4 NVMe 1.4 - M.2, WD 1TB, WD 500GB, WD 350GB
    PSU
    Silverstone Olympia OP1000W PSW
    Case
    Phanteks Enthoo Pro
    Cooling
    Noctua NH-D15 SSO2 D-Type Premium CPU Cooler, NF-A15 x 2 PWM Fans
    Keyboard
    Corsair K70 RGB
    Mouse
    Logitech 310 wireless
    Internet Speed
    1 GB
    Browser
    Firefox
    Antivirus
    ESET Internet Security
    Other Info
    Testing Windows 10 Pro on 350GB drive
I done part A and rebooted twice within 5 minutes and checked to see if 2023 cert was available and it came back "true".
I opened regedit and the servicing is still showing NotStarted. WindowsUEFICA2023Capable 0x000001 (1)

Even if it is not started, should I proceed with Part B?

if the PowerShell CMD comes back 'true'
then please proceed to part B.

after restarting check the registry for this.
1764781576900.webp

best of luck Steve ..
 

My Computers

System One System Two

  • OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
if the PowerShell CMD comes back 'true'
then please proceed to part B.

after restarting check the registry for this.
View attachment 155407

best of luck Steve ..
Thanks for the reply. The registry is showing InProgress just like it did on this system. I will wait for it to change to Updated.
Greatly appreciate all the help. I will post again when it is Updated and is showing as ALLOWED.

Cheers
 

My Computer

System One

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    ASUS
    CPU
    Intel Core i7-11700K Desktop Processor 8 Cores
    Motherboard
    ASUS ROG Strix Z590-A Gaming WiFi LGA 1200
    Memory
    Corsair Vengeance LPX 32GB (2 x 16GB) DDR4 DRAM 3600MHz
    Graphics Card(s)
    ASUS GTX ROG STRIX 1080 8GB
    Sound Card
    Sound Blaster Z SE
    Monitor(s) Displays
    ASUS VG34VQL1B plus a Samsung 60" Smartv
    Screen Resolution
    3440x1440, 165Hz
    Hard Drives
    Samsung 980 Series - (OS)1TB Pro Gen4 NVMe M.2, 1TB Gen3. x4 NVMe 1.4 - M.2, WD 1TB, WD 500GB, WD 350GB
    PSU
    Silverstone Olympia OP1000W PSW
    Case
    Phanteks Enthoo Pro
    Cooling
    Noctua NH-D15 SSO2 D-Type Premium CPU Cooler, NF-A15 x 2 PWM Fans
    Keyboard
    Corsair K70 RGB
    Mouse
    Logitech 310 wireless
    Internet Speed
    1 GB
    Browser
    Firefox
    Antivirus
    ESET Internet Security
    Other Info
    Testing Windows 10 Pro on 350GB drive
Updated on the VivoBook. I now have 2023 certificates on 2 of my systems. I may try the Z270 system tomorrow.

Thanks again for all the help and guidance.

cheers
 

My Computer

System One

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    ASUS
    CPU
    Intel Core i7-11700K Desktop Processor 8 Cores
    Motherboard
    ASUS ROG Strix Z590-A Gaming WiFi LGA 1200
    Memory
    Corsair Vengeance LPX 32GB (2 x 16GB) DDR4 DRAM 3600MHz
    Graphics Card(s)
    ASUS GTX ROG STRIX 1080 8GB
    Sound Card
    Sound Blaster Z SE
    Monitor(s) Displays
    ASUS VG34VQL1B plus a Samsung 60" Smartv
    Screen Resolution
    3440x1440, 165Hz
    Hard Drives
    Samsung 980 Series - (OS)1TB Pro Gen4 NVMe M.2, 1TB Gen3. x4 NVMe 1.4 - M.2, WD 1TB, WD 500GB, WD 350GB
    PSU
    Silverstone Olympia OP1000W PSW
    Case
    Phanteks Enthoo Pro
    Cooling
    Noctua NH-D15 SSO2 D-Type Premium CPU Cooler, NF-A15 x 2 PWM Fans
    Keyboard
    Corsair K70 RGB
    Mouse
    Logitech 310 wireless
    Internet Speed
    1 GB
    Browser
    Firefox
    Antivirus
    ESET Internet Security
    Other Info
    Testing Windows 10 Pro on 350GB drive
Back
Top Bottom