If you're comfortable navigating your UEFI's Secure Boot setup menu, then run these steps.
1. Download this MS certificate file:
https://raw.githubusercontent.com/microsoft/secureboot_objects/main/PreSignedObjects/KEK/Certificates/microsoft corporation kek 2k ca 2023.der
2. Mount the EFI partition, and copy the downloaded file to it.
Code:mountvol S: /s copy "microsoft corporation kek 2k ca 2023.der" S:\EFI mountvol S: /d
3. Shutdown the PC, and enter BIOS. Navigate to your Secure Boot menu. Find the KEK key management screen (appearance depends on your BIOS), there should be an option to manage keys or "enroll a file". Enter that menu, you'll be asked to pick a drive volume to find the file. One of them will have the <EFI> folder underneath.
Navigate inside the <EFI> folder, and select the "microsoft corporation kek 2k ca 2023.der" file. Enroll it, and submit changes.
4. Restart Windows, check if KEK CA 2023 now appears in the script.
Hello garlin,
I checked on a machine that has it listed correctly, and that file is not in the EFI folder. I think that CA 2023 is stored in the BIOS.


My Computer
System One
-
- OS
- Windows 11 Pro 25H2
- Computer type
- PC/Desktop
- Manufacturer/Model
- Dell XPS 8930
- CPU
- Intel I9-9900K
- Memory
- 64GB
- Graphics Card(s)
- NVIDIA RTX 2060
- Sound Card
- NVIDIA High Definition Audio
- Monitor(s) Displays
- 4k Samsung
- Screen Resolution
- 3840 x 2160
- Hard Drives
- 512GB NVMe, ADATA SU 800, 2TB HDD









