Solved Secure boot update HowTo


My Computers

System One System Two

  • OS
    Windows 11 Pro x64 24H2
    Computer type
    PC/Desktop
    CPU
    Ryzen 9 5900X
    Motherboard
    ASRock B550 PG Velocita (UEFI-BIOS 3.90)
    Memory
    64 GB G.Skill RipJaws V F4-3200C16D-64GVK
    Graphics Card(s)
    ASRock Steel Legend Arc B580 12 GB
    Monitor(s) Displays
    Alienware AW3423DWF OLED ultrawide
    Hard Drives
    Samsung 990 Pro 1 TB NVMe SSD
    PSU
    eVGA Supernova 750 G3
    Case
    Corsair 275R
    Internet Speed
    VTel FTTH 1 Gb down and 1 Gb up
  • Computer type
    PC/Desktop
    CPU
    Ryzen 7 5800X3D
    Motherboard
    Asus ROG Strix B550-F Gaming (UEFI-BIOS version 3607)
    Memory
    32 GB (2x16 GB G.Skill TridentZ Neo)
    Graphics card(s)
    Sapphire Nitro+ Radeon RX 6750 XT
    Hard Drives
    Samsung 970 Pro 512 GB NVMe SSD
    PSU
    Corsair RM850x
    Case
    Fractal Focus G
See

View attachment 154542

Is this how rufus should look after creating the USB boot stick?

stick?View attachment 154542

It's really quite easy:

First thing to do is prepare an EFI bootable USB drive with the Mosby files on it. Go get RUFUS, the latest version, to create it. Use the Bootable UEFI V2.2 option and it will both create the EFI bootable USB drive and copy in the MOSBY files you'll need. Once you have a bootable USB drive with the MOSBY files go to the next part.

There are how-to's all over Eleven Forums on using RUFUS to create EFI bootable drives, and even a few youtube vid's.

In BIOS settings disable Secure Boot and put it in what's called SETUP mode. It depends on how your BIOS is set up, with some you just delete all the keys (not reset, completely delete). If you can't find this then MOSBY won't work; UEFI Secure Boot MUST be in SETUP mode (all the key variables emptied) to have keys installed like this.

Read the MOSBY README's that are on the USB drive.

Then restart the system and boot into the EFI bootable USB drive you created.

Run MOSBY from the EFI command line. It does the rest. There are command line options (covered in the readme) for doing custom things (like including your own key you might want in DB as for booting to another OS like Linux), you don't really need to worry those just run MOSBY and it does what's needed for Windows to boot.

Once it's finished, reboot into BIOS settings, enable Secure Boot, boot into the system.

If you see there's a STANDARD mode and CUSTOM mode, leave it in CUSTOM mode or it will revert all to default keys (at least it did with mine). You can delete and re-install again, it's just an unnecessary hassle. (BTW, it will do that with keys that have been pushed into firmware by Microsoft too.)

So, to summarize: 1: Prepare Bootable USB w/MOSBY, 2: Disable Secure Boot and put it in Setup Mode in BIOS settings, 3: Boot to the USB, run MOSBY, 4: Boot back into BIOS and enable Secure Boot. Done.

BitLocker will probably go into Recovery if using it, so be prepared.

If things go south you can Restore Default Keys to get the default keys restored and Secure Boot back.
Something like this?
 

Attachments

  • Screenshot 2025-11-27 133000.webp
    Screenshot 2025-11-27 133000.webp
    36.2 KB · Views: 7

My Computer

System One

  • OS
    Windows 11
View attachment 154542

Is this how rufus should look after creating the USB boot stick?

stick?View attachment 154542


Something like this?
As I recall, yes.

Examine the USB drive with Explorer, you should see the MOSBY files in the root folder. Open the README's in Notepad and read them through.

And BTW, don't use the -X option when you run MOSBY. It revokes trust in the Windows CA 2011 key and you MUST have the 2023 Boot Manager installed before you do that. You can do either of these easily enough, in the right sequence, after you KNOW you have all the 2023 keys installed.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 5800X
    Motherboard
    Gigabyte B550M Aorus Pro
    Memory
    GSkill 3200, 2x8GB
    Graphics Card(s)
    MSI RX 6800 XT Gaming Z
    Sound Card
    on-board Realtek
    Monitor(s) Displays
    MSI 180hz
    Screen Resolution
    1440p
    Hard Drives
    Samsung 980 Pro, Samsung 870 Evo, generic PCIe NVME, WD 1TB 2.5" laptop spinner
    PSU
    Corsair RM 650
    Case
    mATX
    Cooling
    BeQuiet 240mm AIO and a bunch of case fans
    Keyboard
    one that clacks softly
    Mouse
    logitech
    Internet Speed
    bunches of bps
    Browser
    Firefox
    Antivirus
    Windows' own
  • Operating System
    Win11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 1700
    Motherboard
    GA-AB350M G-3
    Memory
    16GB DDR4
    Graphics card(s)
    RX-480
    Sound Card
    In-Built Realtek
    Monitor(s) Displays
    Samsung
    Screen Resolution
    1440p
    Hard Drives
    NVME/SSD's
    PSU
    Thermaltake BX1 550W
    Case
    Some junky thing
    Cooling
    ThermalTake Assassin(?)
    Browser
    FF/Edge
    Antivirus
    Whatever Windows does
    Other Info
    Secure Boot enabled updated to 2023 CA keys, TPM2.0 enabled with system drive Bitlocker'd.
As I recall, yes.

Examine the USB drive with Explorer, you should see the MOSBY files in the root folder. Open the README's in Notepad and read them through.

And BTW, don't use the -X option when you run MOSBY. It revokes trust in the Windows CA 2011 key and you MUST have the 2023 Boot Manager installed before you do that. You can do either of these easily enough, in the right sequence, after you KNOW you have all the 2023 keys installed.
It sort of went okay. Got the missing KEK 2023 certificate installed. At the end of the Mosby process there was a " Security violation" notification. I checked the status of all the keys and it looks okay except for it could not read the PK key details. Other than that, I'm struggling to get the Secure Boot turned back on, it's a work in progress.

Edit hours later: I had to blow out the keys and reset them to factory and reinstall Windows. Once installed it automatically turn Secure Boot back on. I then used a backup image to restore my previous setup, but it wouldn't boot, so I turned off Secure Boot and it loaded Windows. It's still a work in progress.
 
Last edited:

My Computer

System One

  • OS
    Windows 11

My Computer

System One

  • OS
    Windows 11 Pro x64 25H2
    Computer type
    PC/Desktop
    CPU
    i9 14900k
    Motherboard
    MSI Z790 Gaming Plus WiFi-AMZ Gaming Motherboard
    Memory
    G.SKILL Ripjaws S5 Series DDR5 64gb 6400MT/s
    Graphics Card(s)
    NVIDIA Geforce RTX 5070 Ti OC 16gb
    Sound Card
    HyperX Cloud 3 Wireless Headset , Astro A50 Gen 5 Wireless Gaming Headset
    Monitor(s) Displays
    Acer Prediator x34 X5 QD-OLED Ultrawide 240hz, Portable Monitor 1920x1080p 60hz
    Screen Resolution
    3440x1440p , 1920x1080p
    Hard Drives
    Crucial P3 Plus 500gb NVMe M.2
    WD Black SN750 NVMe SSD 1TB
    WD Black SN7100 NVMe SSD 2TB
    Crucial MX500 1TB
    PSU
    Corsair RMx Series RM1000x ATX 3.1 PCIe 5.1
    Case
    MSI MAG PANO 100L PZ
    Cooling
    ID-COOLING FX360 Pro Liquid CPU Cooler
    Keyboard
    CORSAIR - K70 PRO TKL RGB Hall Effect Gaming Keyboard
    Mouse
    Glorious Model O 2 Pro Wireless Gaming Mouse
    Internet Speed
    https://www.speedtest.net/result/19091168380.png
    Browser
    Firefox
    Antivirus
    Windows Security
I'm having this same exact issue.. Anyone know of a solution to this?
Try an earlier version of MOSBY. I'd suggest trying v2.3; it doesn't include the OpROM key but that's not likely to ever be an issue on a laptop.

This is the GitHUB:

 

My Computers

System One System Two

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 5800X
    Motherboard
    Gigabyte B550M Aorus Pro
    Memory
    GSkill 3200, 2x8GB
    Graphics Card(s)
    MSI RX 6800 XT Gaming Z
    Sound Card
    on-board Realtek
    Monitor(s) Displays
    MSI 180hz
    Screen Resolution
    1440p
    Hard Drives
    Samsung 980 Pro, Samsung 870 Evo, generic PCIe NVME, WD 1TB 2.5" laptop spinner
    PSU
    Corsair RM 650
    Case
    mATX
    Cooling
    BeQuiet 240mm AIO and a bunch of case fans
    Keyboard
    one that clacks softly
    Mouse
    logitech
    Internet Speed
    bunches of bps
    Browser
    Firefox
    Antivirus
    Windows' own
  • Operating System
    Win11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 1700
    Motherboard
    GA-AB350M G-3
    Memory
    16GB DDR4
    Graphics card(s)
    RX-480
    Sound Card
    In-Built Realtek
    Monitor(s) Displays
    Samsung
    Screen Resolution
    1440p
    Hard Drives
    NVME/SSD's
    PSU
    Thermaltake BX1 550W
    Case
    Some junky thing
    Cooling
    ThermalTake Assassin(?)
    Browser
    FF/Edge
    Antivirus
    Whatever Windows does
    Other Info
    Secure Boot enabled updated to 2023 CA keys, TPM2.0 enabled with system drive Bitlocker'd.
Edit hours later: I had to blow out the keys and reset them to factory and reinstall Windows. Once installed it automatically turn Secure Boot back on. I then used a backup image to restore my previous setup, but it wouldn't boot, so I turned off Secure Boot and it loaded Windows. It's still a work in progress.
What happened when you reset to factory keys that made you reinstall Windows? Did it have the 2023 boot manager installed?

Separately: how do you manage to edit a post "hours later"? I get about 1 hr. max to make an edit!
 

My Computers

System One System Two

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 5800X
    Motherboard
    Gigabyte B550M Aorus Pro
    Memory
    GSkill 3200, 2x8GB
    Graphics Card(s)
    MSI RX 6800 XT Gaming Z
    Sound Card
    on-board Realtek
    Monitor(s) Displays
    MSI 180hz
    Screen Resolution
    1440p
    Hard Drives
    Samsung 980 Pro, Samsung 870 Evo, generic PCIe NVME, WD 1TB 2.5" laptop spinner
    PSU
    Corsair RM 650
    Case
    mATX
    Cooling
    BeQuiet 240mm AIO and a bunch of case fans
    Keyboard
    one that clacks softly
    Mouse
    logitech
    Internet Speed
    bunches of bps
    Browser
    Firefox
    Antivirus
    Windows' own
  • Operating System
    Win11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 1700
    Motherboard
    GA-AB350M G-3
    Memory
    16GB DDR4
    Graphics card(s)
    RX-480
    Sound Card
    In-Built Realtek
    Monitor(s) Displays
    Samsung
    Screen Resolution
    1440p
    Hard Drives
    NVME/SSD's
    PSU
    Thermaltake BX1 550W
    Case
    Some junky thing
    Cooling
    ThermalTake Assassin(?)
    Browser
    FF/Edge
    Antivirus
    Whatever Windows does
    Other Info
    Secure Boot enabled updated to 2023 CA keys, TPM2.0 enabled with system drive Bitlocker'd.
What happened when you reset to factory keys that made you reinstall Windows? Did it have the 2023 boot manager installed?

Separately: how do you manage to edit a post "hours later"? I get about 1 hr. max to make an edit!
Once the factory keys were reset the device would boot but Secure Boot could not be turned on. Switching on Secure Boot in the BIOS would cause the device to not boot. Reinstalling the OS from a USB stick would magically turn on Secure Boot.

Can't speak to the precise amount of time that elapsed between the initial post and followup edits, it was a long day and struggle.

I found this post on a different forum that has similarities to the difficulties and frustrations I experienced while attempting to use Mosby. The poster has more advanced skills than I, perhaps you would understand and appreciate what they went through:

 

My Computer

System One

  • OS
    Windows 11
Once the factory keys were reset the device would boot but Secure Boot could not be turned on. Switching on Secure Boot in the BIOS would cause the device to not boot. Reinstalling the OS from a USB stick would magically turn on Secure Boot.

Can't speak to the precise amount of time that elapsed between the initial post and followup edits, it was a long day and struggle.

I found this post on a different forum that has similarities to the difficulties and frustrations I experienced while attempting to use Mosby. The poster has more advanced skills than I, perhaps you would understand and appreciate what they went through:

The Gentoo poster was trying to do far more advanced things than I could... they were (attempting) to set it up for a custom boot manager file for instance. MOSBY can do that but it's way beyond my meager skills. For me, it would entail a lot of experimenting to get it right even for fully UEFI standards compliant hardware and firmware.

But it appears HP has done what HP, Dell and Lenovo do best. And that is to turn industry standards inside out to force you to either go back to them for "fixes", or scrap old systems and buy new when they decide to abandon it.

And also, these three companies make their best money selling systems into large corporate and government markets. They also doubtless sell the documentation and software, and maybe even seminars and courses they send their IT techs too in order to manage the systems securely and properly. That's a gravy train they don't want to derail by making it easy for us to do it.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 5800X
    Motherboard
    Gigabyte B550M Aorus Pro
    Memory
    GSkill 3200, 2x8GB
    Graphics Card(s)
    MSI RX 6800 XT Gaming Z
    Sound Card
    on-board Realtek
    Monitor(s) Displays
    MSI 180hz
    Screen Resolution
    1440p
    Hard Drives
    Samsung 980 Pro, Samsung 870 Evo, generic PCIe NVME, WD 1TB 2.5" laptop spinner
    PSU
    Corsair RM 650
    Case
    mATX
    Cooling
    BeQuiet 240mm AIO and a bunch of case fans
    Keyboard
    one that clacks softly
    Mouse
    logitech
    Internet Speed
    bunches of bps
    Browser
    Firefox
    Antivirus
    Windows' own
  • Operating System
    Win11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 1700
    Motherboard
    GA-AB350M G-3
    Memory
    16GB DDR4
    Graphics card(s)
    RX-480
    Sound Card
    In-Built Realtek
    Monitor(s) Displays
    Samsung
    Screen Resolution
    1440p
    Hard Drives
    NVME/SSD's
    PSU
    Thermaltake BX1 550W
    Case
    Some junky thing
    Cooling
    ThermalTake Assassin(?)
    Browser
    FF/Edge
    Antivirus
    Whatever Windows does
    Other Info
    Secure Boot enabled updated to 2023 CA keys, TPM2.0 enabled with system drive Bitlocker'd.
The Gentoo poster was trying to do far more advanced things than I could... they were (attempting) to set it up for a custom boot manager file for instance. MOSBY can do that but it's way beyond my meager skills. For me, it would entail a lot of experimenting to get it right even for fully UEFI standards compliant hardware and firmware.

But it appears HP has done what HP, Dell and Lenovo do best. And that is to turn industry standards inside out to force you to either go back to them for "fixes", or scrap old systems and buy new when they decide to abandon it.

And also, these three companies make their best money selling systems into large corporate and government markets. They also doubtless sell the documentation and software, and maybe even seminars and courses they send their IT techs too in order to manage the systems securely and properly. That's a gravy train they don't want to derail by making it easy for us to do it.
Yeah, it is, what it is. What I was trying to achieve, was to install the KEK 2023 key. I noticed in Mosby that you can set your own keys. I think I saw the download for that key on the Internet. Do you know how to do that?
 

My Computer

System One

  • OS
    Windows 11
1764807643357.webp+
my systems Secure boot is off since I disabled it on original install of Win10 long before I updated to Windows 11..
still waiting on a update some how the certs or wait for Windows a WinUpdate to do it for me?

I didn't want to deal with this security nightmare. having it on.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro (x64)(v25H2)(26200.8524)
    Computer type
    PC/Desktop
    Manufacturer/Model
    [Self-built](custom-build)(June 2020)
    CPU
    AMD Ryzen 9 3900X 12-Core/24-threads
    Motherboard
    Asus PRIME X570-PRO (BIOS_r5044 [01/04/2026])
    Memory
    64GB, 2x G.Skill 32GB (PC3200)(DDR4-2137)
    Graphics Card(s)
    ASUS PRIME GeForce RTX 5070 12GB OC Edition, GPU by NVIDIA.
    Sound Card
    Realtek® ALC1220A 8-Channel High Definition Audio CODEC
    Monitor(s) Displays
    24" DELL Gaming Monitor - G2422HS - DisplayPort used
    Screen Resolution
    1920x1080p at 165Hz (16:9 Aspect Ratio)
    Hard Drives
    2TB Samsung 980 Pro (NVMe)(SSD)
    4TB Samsung 990 Pro (NVMe)(SSD)
    2TB Samsung 870 EVO (SSD)

    NVMe 2TB
    -- OS(Win11 Pro x64),
    -- programs,
    -- programming(MS Visual Studios 2022 Community Ed.),
    -- music

    NVMe 4TB
    video game installs.

    #3 FILE Server!
    PSU
    Thermaltake TOUGHPOWER DPS G RGB Titanium Certified 1250Watt
    Case
    Corsair Graphite Series 780T Full Tower PC Case
    Cooling
    AMD Wraith cooler (stock) & 3x Corsair case fans
    Keyboard
    Redragon K580 VATA RGB LED Backlit Mechanical Gaming Keyboard (brown switches).
    Mouse
    Redragon M602 RGB Wired USB Gaming mouse
    Internet Speed
    2,100Mbps Download, 300Mbps Upload
    Browser
    Firefox & Google Chrome
    Antivirus
    n/a aka "ABOVE TOP SECRET!" lol ;)
    Other Info
    My System is the ULTIMATE GAMING RIG ^_^
    TP-Link BE9300 Tri-Band Wi-Fi 7 Wireless 2.5Gigabit Router
    Model Archer BE550 (v1.0)
    Arris S34 Cable Modem
    Nvidia GFX Drivers: (v596.49)
    Realtek UAD Drivers: (v6.0.9977.1)
    Realtek LAN Drivers:(v1125.29.50.202)(2026-04-19)
    Intel LAN Drivers: (v14.01.24.00)(2025-10-03)
  • Operating System
    Windows 11 Pro x64
    Computer type
    Laptop
    Manufacturer/Model
    DELL G15 Ryzen edition, model 5515
    CPU
    AMD Ryzen 7 5800H
    Motherboard
    DELL G15 Ryzen edition
    Memory
    32GB GSkill DDR4 2x 16GB sticks
    Graphics card(s)
    Ryzen 7 5800H integrated AMD Radeon Graphics and Nvidia GeForce 3060 6GB
    Sound Card
    Realtek ALC3254 with Nahimic 3D Audio for Gamers
    Monitor(s) Displays
    built-in
    Screen Resolution
    1920x1080
    Hard Drives
    512GB NVMe SSD, 1TB Samsung 970 EVO NVMe SSD
    PSU
    unknown
    Case
    laptop
    Keyboard
    built-in
    Mouse
    Logitech B100 USB
    Internet Speed
    2,100Mbps download, 300Mbps upload
    Browser
    Firefox & Google Chrome
View attachment 155498+
my systems Secure boot is off since I disabled it on original install of Win10 long before I updated to Windows 11..
still waiting on a update some how the certs or wait for Windows a WinUpdate to do it for me?

I didn't want to deal with this security nightmare. having it on.
Secure Boot must be enabled for the Windows updates to be able to push updated keys into firmware. If you don't ever want to use Secure Boot (for whatever reason) then it probably doesn't matter whether or not they get updated.

And even if you do want to use secure boot it's only a "nightmare" for a those systems where OEM's have decided not to support. Most of the drama here has been from people with those sorts of systems... or those of us who couldn't wait for the update process that Microsoft is following to conclude .
 

My Computers

System One System Two

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 5800X
    Motherboard
    Gigabyte B550M Aorus Pro
    Memory
    GSkill 3200, 2x8GB
    Graphics Card(s)
    MSI RX 6800 XT Gaming Z
    Sound Card
    on-board Realtek
    Monitor(s) Displays
    MSI 180hz
    Screen Resolution
    1440p
    Hard Drives
    Samsung 980 Pro, Samsung 870 Evo, generic PCIe NVME, WD 1TB 2.5" laptop spinner
    PSU
    Corsair RM 650
    Case
    mATX
    Cooling
    BeQuiet 240mm AIO and a bunch of case fans
    Keyboard
    one that clacks softly
    Mouse
    logitech
    Internet Speed
    bunches of bps
    Browser
    Firefox
    Antivirus
    Windows' own
  • Operating System
    Win11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 1700
    Motherboard
    GA-AB350M G-3
    Memory
    16GB DDR4
    Graphics card(s)
    RX-480
    Sound Card
    In-Built Realtek
    Monitor(s) Displays
    Samsung
    Screen Resolution
    1440p
    Hard Drives
    NVME/SSD's
    PSU
    Thermaltake BX1 550W
    Case
    Some junky thing
    Cooling
    ThermalTake Assassin(?)
    Browser
    FF/Edge
    Antivirus
    Whatever Windows does
    Other Info
    Secure Boot enabled updated to 2023 CA keys, TPM2.0 enabled with system drive Bitlocker'd.
Secure Boot must be enabled for the Windows updates to be able to push updated keys into firmware. If you don't ever want to use Secure Boot (for whatever reason) then it probably doesn't matter whether or not they get updated.
thx for the info..
 

My Computers

System One System Two

  • OS
    Windows 11 Pro (x64)(v25H2)(26200.8524)
    Computer type
    PC/Desktop
    Manufacturer/Model
    [Self-built](custom-build)(June 2020)
    CPU
    AMD Ryzen 9 3900X 12-Core/24-threads
    Motherboard
    Asus PRIME X570-PRO (BIOS_r5044 [01/04/2026])
    Memory
    64GB, 2x G.Skill 32GB (PC3200)(DDR4-2137)
    Graphics Card(s)
    ASUS PRIME GeForce RTX 5070 12GB OC Edition, GPU by NVIDIA.
    Sound Card
    Realtek® ALC1220A 8-Channel High Definition Audio CODEC
    Monitor(s) Displays
    24" DELL Gaming Monitor - G2422HS - DisplayPort used
    Screen Resolution
    1920x1080p at 165Hz (16:9 Aspect Ratio)
    Hard Drives
    2TB Samsung 980 Pro (NVMe)(SSD)
    4TB Samsung 990 Pro (NVMe)(SSD)
    2TB Samsung 870 EVO (SSD)

    NVMe 2TB
    -- OS(Win11 Pro x64),
    -- programs,
    -- programming(MS Visual Studios 2022 Community Ed.),
    -- music

    NVMe 4TB
    video game installs.

    #3 FILE Server!
    PSU
    Thermaltake TOUGHPOWER DPS G RGB Titanium Certified 1250Watt
    Case
    Corsair Graphite Series 780T Full Tower PC Case
    Cooling
    AMD Wraith cooler (stock) & 3x Corsair case fans
    Keyboard
    Redragon K580 VATA RGB LED Backlit Mechanical Gaming Keyboard (brown switches).
    Mouse
    Redragon M602 RGB Wired USB Gaming mouse
    Internet Speed
    2,100Mbps Download, 300Mbps Upload
    Browser
    Firefox & Google Chrome
    Antivirus
    n/a aka "ABOVE TOP SECRET!" lol ;)
    Other Info
    My System is the ULTIMATE GAMING RIG ^_^
    TP-Link BE9300 Tri-Band Wi-Fi 7 Wireless 2.5Gigabit Router
    Model Archer BE550 (v1.0)
    Arris S34 Cable Modem
    Nvidia GFX Drivers: (v596.49)
    Realtek UAD Drivers: (v6.0.9977.1)
    Realtek LAN Drivers:(v1125.29.50.202)(2026-04-19)
    Intel LAN Drivers: (v14.01.24.00)(2025-10-03)
  • Operating System
    Windows 11 Pro x64
    Computer type
    Laptop
    Manufacturer/Model
    DELL G15 Ryzen edition, model 5515
    CPU
    AMD Ryzen 7 5800H
    Motherboard
    DELL G15 Ryzen edition
    Memory
    32GB GSkill DDR4 2x 16GB sticks
    Graphics card(s)
    Ryzen 7 5800H integrated AMD Radeon Graphics and Nvidia GeForce 3060 6GB
    Sound Card
    Realtek ALC3254 with Nahimic 3D Audio for Gamers
    Monitor(s) Displays
    built-in
    Screen Resolution
    1920x1080
    Hard Drives
    512GB NVMe SSD, 1TB Samsung 970 EVO NVMe SSD
    PSU
    unknown
    Case
    laptop
    Keyboard
    built-in
    Mouse
    Logitech B100 USB
    Internet Speed
    2,100Mbps download, 300Mbps upload
    Browser
    Firefox & Google Chrome
here is the secure-boot state for my old DELL laptop after running the update script
1764903003681.webp

it updated in windows but didn't push the update to the UEFI BIOS..
bummer..
what should I try next?

I just let DELL know they should update the BIOS on my laptop model..
 

My Computers

System One System Two

  • OS
    Windows 11 Pro (x64)(v25H2)(26200.8524)
    Computer type
    PC/Desktop
    Manufacturer/Model
    [Self-built](custom-build)(June 2020)
    CPU
    AMD Ryzen 9 3900X 12-Core/24-threads
    Motherboard
    Asus PRIME X570-PRO (BIOS_r5044 [01/04/2026])
    Memory
    64GB, 2x G.Skill 32GB (PC3200)(DDR4-2137)
    Graphics Card(s)
    ASUS PRIME GeForce RTX 5070 12GB OC Edition, GPU by NVIDIA.
    Sound Card
    Realtek® ALC1220A 8-Channel High Definition Audio CODEC
    Monitor(s) Displays
    24" DELL Gaming Monitor - G2422HS - DisplayPort used
    Screen Resolution
    1920x1080p at 165Hz (16:9 Aspect Ratio)
    Hard Drives
    2TB Samsung 980 Pro (NVMe)(SSD)
    4TB Samsung 990 Pro (NVMe)(SSD)
    2TB Samsung 870 EVO (SSD)

    NVMe 2TB
    -- OS(Win11 Pro x64),
    -- programs,
    -- programming(MS Visual Studios 2022 Community Ed.),
    -- music

    NVMe 4TB
    video game installs.

    #3 FILE Server!
    PSU
    Thermaltake TOUGHPOWER DPS G RGB Titanium Certified 1250Watt
    Case
    Corsair Graphite Series 780T Full Tower PC Case
    Cooling
    AMD Wraith cooler (stock) & 3x Corsair case fans
    Keyboard
    Redragon K580 VATA RGB LED Backlit Mechanical Gaming Keyboard (brown switches).
    Mouse
    Redragon M602 RGB Wired USB Gaming mouse
    Internet Speed
    2,100Mbps Download, 300Mbps Upload
    Browser
    Firefox & Google Chrome
    Antivirus
    n/a aka "ABOVE TOP SECRET!" lol ;)
    Other Info
    My System is the ULTIMATE GAMING RIG ^_^
    TP-Link BE9300 Tri-Band Wi-Fi 7 Wireless 2.5Gigabit Router
    Model Archer BE550 (v1.0)
    Arris S34 Cable Modem
    Nvidia GFX Drivers: (v596.49)
    Realtek UAD Drivers: (v6.0.9977.1)
    Realtek LAN Drivers:(v1125.29.50.202)(2026-04-19)
    Intel LAN Drivers: (v14.01.24.00)(2025-10-03)
  • Operating System
    Windows 11 Pro x64
    Computer type
    Laptop
    Manufacturer/Model
    DELL G15 Ryzen edition, model 5515
    CPU
    AMD Ryzen 7 5800H
    Motherboard
    DELL G15 Ryzen edition
    Memory
    32GB GSkill DDR4 2x 16GB sticks
    Graphics card(s)
    Ryzen 7 5800H integrated AMD Radeon Graphics and Nvidia GeForce 3060 6GB
    Sound Card
    Realtek ALC3254 with Nahimic 3D Audio for Gamers
    Monitor(s) Displays
    built-in
    Screen Resolution
    1920x1080
    Hard Drives
    512GB NVMe SSD, 1TB Samsung 970 EVO NVMe SSD
    PSU
    unknown
    Case
    laptop
    Keyboard
    built-in
    Mouse
    Logitech B100 USB
    Internet Speed
    2,100Mbps download, 300Mbps upload
    Browser
    Firefox & Google Chrome
what should I try next?

I just let DELL know they should update the BIOS on my laptop model..
Good luck with that!
If more users put pressure on Dell support, maybe they will do something about updating the Bios on older machines to support CA 2023 update.
 

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell XPS 8930
    CPU
    Intel I9-9900K
    Memory
    64GB
    Graphics Card(s)
    NVIDIA RTX 2060
    Sound Card
    NVIDIA High Definition Audio
    Monitor(s) Displays
    4k Samsung
    Screen Resolution
    3840 x 2160
    Hard Drives
    512GB NVMe, ADATA SU 800, 2TB HDD

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC12WSHi7
    CPU
    12th Gen Core i7-1260P
    Motherboard
    NUC12WSBi7
    Memory
    64 GB Micron PC4-25600
    Graphics Card(s)
    Intel Iris Xe Graphics
    Sound Card
    on-board Realtek HD Audio
    Monitor(s) Displays
    Dell U3219Q
    Screen Resolution
    3840 x 2160
    Hard Drives
    Samsung SSD 990 PRO 1TB
    Crucial MX500 2 TB
    Antivirus
    Microsoft Defender

My Computers

System One System Two

  • OS
    Windows 11 Pro (x64)(v25H2)(26200.8524)
    Computer type
    PC/Desktop
    Manufacturer/Model
    [Self-built](custom-build)(June 2020)
    CPU
    AMD Ryzen 9 3900X 12-Core/24-threads
    Motherboard
    Asus PRIME X570-PRO (BIOS_r5044 [01/04/2026])
    Memory
    64GB, 2x G.Skill 32GB (PC3200)(DDR4-2137)
    Graphics Card(s)
    ASUS PRIME GeForce RTX 5070 12GB OC Edition, GPU by NVIDIA.
    Sound Card
    Realtek® ALC1220A 8-Channel High Definition Audio CODEC
    Monitor(s) Displays
    24" DELL Gaming Monitor - G2422HS - DisplayPort used
    Screen Resolution
    1920x1080p at 165Hz (16:9 Aspect Ratio)
    Hard Drives
    2TB Samsung 980 Pro (NVMe)(SSD)
    4TB Samsung 990 Pro (NVMe)(SSD)
    2TB Samsung 870 EVO (SSD)

    NVMe 2TB
    -- OS(Win11 Pro x64),
    -- programs,
    -- programming(MS Visual Studios 2022 Community Ed.),
    -- music

    NVMe 4TB
    video game installs.

    #3 FILE Server!
    PSU
    Thermaltake TOUGHPOWER DPS G RGB Titanium Certified 1250Watt
    Case
    Corsair Graphite Series 780T Full Tower PC Case
    Cooling
    AMD Wraith cooler (stock) & 3x Corsair case fans
    Keyboard
    Redragon K580 VATA RGB LED Backlit Mechanical Gaming Keyboard (brown switches).
    Mouse
    Redragon M602 RGB Wired USB Gaming mouse
    Internet Speed
    2,100Mbps Download, 300Mbps Upload
    Browser
    Firefox & Google Chrome
    Antivirus
    n/a aka "ABOVE TOP SECRET!" lol ;)
    Other Info
    My System is the ULTIMATE GAMING RIG ^_^
    TP-Link BE9300 Tri-Band Wi-Fi 7 Wireless 2.5Gigabit Router
    Model Archer BE550 (v1.0)
    Arris S34 Cable Modem
    Nvidia GFX Drivers: (v596.49)
    Realtek UAD Drivers: (v6.0.9977.1)
    Realtek LAN Drivers:(v1125.29.50.202)(2026-04-19)
    Intel LAN Drivers: (v14.01.24.00)(2025-10-03)
  • Operating System
    Windows 11 Pro x64
    Computer type
    Laptop
    Manufacturer/Model
    DELL G15 Ryzen edition, model 5515
    CPU
    AMD Ryzen 7 5800H
    Motherboard
    DELL G15 Ryzen edition
    Memory
    32GB GSkill DDR4 2x 16GB sticks
    Graphics card(s)
    Ryzen 7 5800H integrated AMD Radeon Graphics and Nvidia GeForce 3060 6GB
    Sound Card
    Realtek ALC3254 with Nahimic 3D Audio for Gamers
    Monitor(s) Displays
    built-in
    Screen Resolution
    1920x1080
    Hard Drives
    512GB NVMe SSD, 1TB Samsung 970 EVO NVMe SSD
    PSU
    unknown
    Case
    laptop
    Keyboard
    built-in
    Mouse
    Logitech B100 USB
    Internet Speed
    2,100Mbps download, 300Mbps upload
    Browser
    Firefox & Google Chrome
yeah I already installed the latest BIOS update for my Dell laptop...
v1.28.1
must have missed that info since it was not listed above it where the change log is..
but its not showing up in that script..
the script results are showing false..
This screenshot below is what I get on my DELL XPS 8940 desktop. After I did the CA 2023 Update procedure as suggested on post #1.
Unfortunately, I cannot get the same results on the older Dell XPS 8930 because it does not complete the same update as the XPS 8940. 😵‍💫🤬🤷‍♂️

DELL XPS 8940 with BIOS 2.27.21 dated 2025-04-03.
1764917748240.webp
 

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell XPS 8930
    CPU
    Intel I9-9900K
    Memory
    64GB
    Graphics Card(s)
    NVIDIA RTX 2060
    Sound Card
    NVIDIA High Definition Audio
    Monitor(s) Displays
    4k Samsung
    Screen Resolution
    3840 x 2160
    Hard Drives
    512GB NVMe, ADATA SU 800, 2TB HDD
This is the reply I got from Dell Corporation support email.

We understand your concern regarding the current Secure Boot certs expiring in 2026 and your request for an updated BIOS containing the 2023 certificate set. Dell works closely with Microsoft on Secure Boot implementation, and any future firmware updates related to certificate alignment will be delivered through official BIOS releases.

At this time, no additional action is required on your end. Please continue keeping your system updated through:
 

My Computers

System One System Two

  • OS
    Windows 11 Pro (x64)(v25H2)(26200.8524)
    Computer type
    PC/Desktop
    Manufacturer/Model
    [Self-built](custom-build)(June 2020)
    CPU
    AMD Ryzen 9 3900X 12-Core/24-threads
    Motherboard
    Asus PRIME X570-PRO (BIOS_r5044 [01/04/2026])
    Memory
    64GB, 2x G.Skill 32GB (PC3200)(DDR4-2137)
    Graphics Card(s)
    ASUS PRIME GeForce RTX 5070 12GB OC Edition, GPU by NVIDIA.
    Sound Card
    Realtek® ALC1220A 8-Channel High Definition Audio CODEC
    Monitor(s) Displays
    24" DELL Gaming Monitor - G2422HS - DisplayPort used
    Screen Resolution
    1920x1080p at 165Hz (16:9 Aspect Ratio)
    Hard Drives
    2TB Samsung 980 Pro (NVMe)(SSD)
    4TB Samsung 990 Pro (NVMe)(SSD)
    2TB Samsung 870 EVO (SSD)

    NVMe 2TB
    -- OS(Win11 Pro x64),
    -- programs,
    -- programming(MS Visual Studios 2022 Community Ed.),
    -- music

    NVMe 4TB
    video game installs.

    #3 FILE Server!
    PSU
    Thermaltake TOUGHPOWER DPS G RGB Titanium Certified 1250Watt
    Case
    Corsair Graphite Series 780T Full Tower PC Case
    Cooling
    AMD Wraith cooler (stock) & 3x Corsair case fans
    Keyboard
    Redragon K580 VATA RGB LED Backlit Mechanical Gaming Keyboard (brown switches).
    Mouse
    Redragon M602 RGB Wired USB Gaming mouse
    Internet Speed
    2,100Mbps Download, 300Mbps Upload
    Browser
    Firefox & Google Chrome
    Antivirus
    n/a aka "ABOVE TOP SECRET!" lol ;)
    Other Info
    My System is the ULTIMATE GAMING RIG ^_^
    TP-Link BE9300 Tri-Band Wi-Fi 7 Wireless 2.5Gigabit Router
    Model Archer BE550 (v1.0)
    Arris S34 Cable Modem
    Nvidia GFX Drivers: (v596.49)
    Realtek UAD Drivers: (v6.0.9977.1)
    Realtek LAN Drivers:(v1125.29.50.202)(2026-04-19)
    Intel LAN Drivers: (v14.01.24.00)(2025-10-03)
  • Operating System
    Windows 11 Pro x64
    Computer type
    Laptop
    Manufacturer/Model
    DELL G15 Ryzen edition, model 5515
    CPU
    AMD Ryzen 7 5800H
    Motherboard
    DELL G15 Ryzen edition
    Memory
    32GB GSkill DDR4 2x 16GB sticks
    Graphics card(s)
    Ryzen 7 5800H integrated AMD Radeon Graphics and Nvidia GeForce 3060 6GB
    Sound Card
    Realtek ALC3254 with Nahimic 3D Audio for Gamers
    Monitor(s) Displays
    built-in
    Screen Resolution
    1920x1080
    Hard Drives
    512GB NVMe SSD, 1TB Samsung 970 EVO NVMe SSD
    PSU
    unknown
    Case
    laptop
    Keyboard
    built-in
    Mouse
    Logitech B100 USB
    Internet Speed
    2,100Mbps download, 300Mbps upload
    Browser
    Firefox & Google Chrome
This is the reply I got from Dell Corporation support email.
That is exactly the same reply I got from Dell about this desktop DELL XPS 8930. Sounds like a canned answer. 😂


DELL XPS 8930 with BIOS 1.1.31 dated 2023-11-21, which gives me these results.
("Microsoft Corporation KEK 2K CA 2023" is missing in the UEFI KEK Certs list.) 🤬🤷‍♂️
1764918776927.webp
 

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell XPS 8930
    CPU
    Intel I9-9900K
    Memory
    64GB
    Graphics Card(s)
    NVIDIA RTX 2060
    Sound Card
    NVIDIA High Definition Audio
    Monitor(s) Displays
    4k Samsung
    Screen Resolution
    3840 x 2160
    Hard Drives
    512GB NVMe, ADATA SU 800, 2TB HDD

Latest Support Threads

Back
Top Bottom