Solved Secure boot update HowTo


Secure Boot task will install any new boot managers (and SVN), if your PC has already reached UEFICA2023Status = Updated. This means a KEK CA 2023 was installed, and the other CA 2023 certs and the current boot manager was copied.

PC's already on SVN 7.0 would be self-updated to SVN 8.0.

But of your PC hasn't gotten there yet, because it's still blocked by "More Data Needed", manual intervention is still needed unless you wait to for MS.
 

My Computer

System One

  • OS
    Windows 7
i have put this together as i had problems updating 2 desktops and 3 laptops.
which have now all had their Secure Boot Certs updated to the new 2023 secure boot cert
also the other post about this were getting very long and confusing.
this is in two parts. part A and part B.
edit by me. please note, your system must be online for part A to update

Part A
.
open a PowerShell as Admin
then copy and paste these two commands in this order.
thanks to @Brink tutorial.

1.


then press enter

2.


press enter and now restart your computer TWICE

##### to check that the 2023 cert is now available #####
to check that the 2023 cert is available after the 2 restarts
open a PowerShell as Admin copy and paste this command

the result of the command should show as 'True'

and then open the Windows registry to this key
Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing

in the right window you will see ..
UEFICA2023Status which will show 'updating'
WindowsUEFICA2023Capable 0x00000001

close the registry and you can now begin part B.

######

Part B.
open a CMD Prompt as Admin
then copy and paste this command
thanks to @Scott

1. at the CMD Prompt as Admin


press enter and now close the CMD Prompt terminal

then open a PowerShell as Admin


2. within the PowerShell


press enter and restart you computer.

Final Check once the system has restarted
open the registry and find this key (again)
Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing

in the right Window you will see ..
UEFICA2023Status which will now show 'Updated'
WindowsUEFICA2023Capable 0x00000002


your system is now updated to the new 2023 certs
if this post is in the wrong part of the Forum please move it to the correct one.

edit by me. missed this out .. your system needs to be online for the update to work
best of luck Steve ..
Is this still the preferred method and does it still work?
 

My Computer

System One

  • OS
    Windows 11
it is one of several ways to update the secure boot certs.
follow this how to, then check to see if its updated

you can decide afterwards if another method is required to update the secure boot certs.
best of luck Steve ..
 

My Computers

System One System Two

  • OS
    Debian 13 KDE .. Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
any idea how to get UEFI DBX fixed up on Gigabyte ga-z170-hd3? I had to manually add the 2023 certs in the bios secure boot keys section but still showing "under observation - more data needed" for confidence level and still showing "failed attestation" in CoD Warzone when i try to play.

---------------------------------------------------

UEFICA2023Status: Updated
WindowsEUFICA2023Capable: 0x00000002 (2)


---------------------------------------------------

Checking for Administrator permission...
Running as administrator - continuing execution...

05 June 2026
Manufacturer: Gigabyte Technology Co., Ltd.
Model: Z170-HD3
BIOS: American Megatrends Inc., F22f, F22f, ALASKA - 1072009
Windows version: 22H2 (Build 19045.7291)

Secure Boot status: Enabled

Current UEFI PK
√ DO NOT TRUST - AMI Test PK

Default UEFI PK
√ DO NOT TRUST - AMI Test PK
Current UEFI KEK
X Microsoft Corporation KEK CA 2011
√ Microsoft Corporation KEK 2K CA 2023 (revoked: False)

Default UEFI KEK
√ Microsoft Corporation KEK CA 2011 (revoked: False)
X Microsoft Corporation KEK 2K CA 2023

Current UEFI DB
X Microsoft Windows Production PCA 2011
X Microsoft Corporation UEFI CA 2011
√ Windows UEFI CA 2023 (revoked: False)
√ Microsoft UEFI CA 2023 (revoked: False)
X Microsoft Option ROM UEFI CA 2023

Default UEFI DB
√ Microsoft Windows Production PCA 2011 (revoked: False)
√ Microsoft Corporation UEFI CA 2011 (revoked: False)
X Windows UEFI CA 2023
X Microsoft UEFI CA 2023
X Microsoft Option ROM UEFI CA 2023

Current UEFI DBX
2025-10-14 (v1.6.0) : FAIL: 404 failures, 27 successes detected
Windows Bootmgr SVN : None
Windows cdboot SVN : None
Windows wdsmgfw SVN : None
 

My Computer

System One

  • OS
    Windows 10
    Computer type
    PC/Desktop
    Manufacturer/Model
    Gigabyte
    CPU
    Intel i7-7700k
    Motherboard
    Gigabyte ga-z170-hd3
    Memory
    64 Gb
    Graphics Card(s)
    Geforce 1080 FTW
any idea how to get UEFI DBX fixed up on Gigabyte ga-z170-hd3? I had to manually add the 2023 certs in the bios secure boot keys section but still showing "under observation - more data needed" for confidence level and still showing "failed attestation" in CoD Warzone when i try to play.
I would ignore "More Data Needed", because the Confidence Level status is derived from a static JSON file that's pushed out in the Monthly Updates. It doesn't reflect your UEFI's current state.

Current UEFI PK
√ DO NOT TRUST - AMI Test PK

Current UEFI KEK
√ Microsoft Corporation KEK 2K CA 2023 (revoked: False)

Current UEFI DB
√ Windows UEFI CA 2023 (revoked: False)
√ Microsoft UEFI CA 2023 (revoked: False)
This is the minimum set of CA 2023 certs required to run Secure Boot mode. Attestation is a fancy security term for "we checked the Windows boot logs and confirmed Secure Boot was running". I'm not sure what COD:WZ considers as the minimum threshold for compliance.

Some observations:

1. You're still running the factory "DO NOT TRUST" PK. BIOS'es running this PK have long been considered insecure, because it's suspected the private signing key for the OEM reference example ("Test PK") was leaked years ago. Most security experts recommend replacing this PK with another one.

2. While it's the minimal set of certs, typically some Windows processes like to see the Option ROM present (even if it's optional). It may get flagged by TPM-WMI in the event logs as noise.

My recommendation is to delete all current Secure Boot keys and drop in the cert bundle from Windows OEM Devices. This gets rid of the "DO NOT TRUST" PK and makes sure your UEFI passes every test, so nothing will complain in the future.

You can try my upgrade script from:
garlin's PowerShell scripts for updating Secure Boot CA 2023

1. Confirm BitLocker is not enabled on system drive, and you're not using Windows Hello PIN for logon. Disable both of them if enabled.

2. From the BIOS menus, Delete All Keys or the equivalent option for Setup Mode (no keys).

3. Run the update script.
Code:
Update-UEFI.bat

If you want to revoke now, instead of waiting for Windows to do this later:
Code:
Update-UEFI.bat -Revoke
 

My Computer

System One

  • OS
    Windows 7
appreciate the quick reply! followed your recommendation and this is where i'm at currently:


Secure Boot: ON
Virtualization Based Security: ON
BitLocker on (C:) OFF

UEFI KEK Certs
--------------
Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 8.0

EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

[OPTIONAL] SkuSiPolicy.p7b (for VBS) is MISSING.


STATUS REPORT
-------------
Registry: "UEFICA2023Status" = Updated

SUCCESS: UPDATES ARE FINISHED.
UEFI CA 2023 certs are present, PCA 2011 cert is revoked.



-----------------------------------------------------------------------------------------------

Checking for Administrator permission...
Running as administrator - continuing execution...

05 June 2026
Manufacturer: Gigabyte Technology Co., Ltd.
Model: Z170-HD3
BIOS: American Megatrends Inc., F22f, F22f, ALASKA - 1072009
Windows version: 22H2 (Build 19045.7291)

Secure Boot status: Enabled

Current UEFI PK
√ Windows OEM Devices PK

Default UEFI PK
√ DO NOT TRUST - AMI Test PK
Current UEFI KEK
X Microsoft Corporation KEK CA 2011
√ Microsoft Corporation KEK 2K CA 2023 (revoked: False)

Default UEFI KEK
√ Microsoft Corporation KEK CA 2011 (revoked: False)
X Microsoft Corporation KEK 2K CA 2023

Current UEFI DB
X Microsoft Windows Production PCA 2011
X Microsoft Corporation UEFI CA 2011
√ Windows UEFI CA 2023 (revoked: False)
√ Microsoft UEFI CA 2023 (revoked: False)
√ Microsoft Option ROM UEFI CA 2023 (revoked: False)

Default UEFI DB
√ Microsoft Windows Production PCA 2011 (revoked: True)
√ Microsoft Corporation UEFI CA 2011 (revoked: False)
X Windows UEFI CA 2023
X Microsoft UEFI CA 2023
X Microsoft Option ROM UEFI CA 2023

Current UEFI DBX
2025-10-14 (v1.6.0) : FAIL: 154 failures, 277 successes detected
Windows Bootmgr SVN : 8.0
Windows cdboot SVN : 3.0
Windows wdsmgfw SVN : 3.0

Press any key to continue . . .
 

My Computer

System One

  • OS
    Windows 10
    Computer type
    PC/Desktop
    Manufacturer/Model
    Gigabyte
    CPU
    Intel i7-7700k
    Motherboard
    Gigabyte ga-z170-hd3
    Memory
    64 Gb
    Graphics Card(s)
    Geforce 1080 FTW
appreciate the quick reply! followed your recommendation and this is where i'm at currently:

Secure Boot: ON
Virtualization Based Security: ON
BitLocker on (C:) OFF

UEFI KEK Certs
--------------
Microsoft Corporation KEK 2K CA 2023

UEFI DB Certs
-------------
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023

UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 8.0

EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

[OPTIONAL] SkuSiPolicy.p7b (for VBS) is MISSING.


STATUS REPORT
-------------
Registry: "UEFICA2023Status" = Updated

SUCCESS: UPDATES ARE FINISHED.
UEFI CA 2023 certs are present, PCA 2011 cert is revoked.
You're done with CA 2023 updates. Hopefully, you can run COD now.
 

My Computer

System One

  • OS
    Windows 7
OMG. I didn't realize they were serious enough about anti-cheat to release a "COD Secure Attestation Wizard". :boom:
 

My Computer

System One

  • OS
    Windows 7
Yep, and I'm still failing it :(

Also, just now seeing that my i7-7700k isn't supported either so that's likely the reason unless MoKiChU can save the day with another Intel ME Consumer FW update!
 

My Computer

System One

  • OS
    Windows 10
    Computer type
    PC/Desktop
    Manufacturer/Model
    Gigabyte
    CPU
    Intel i7-7700k
    Motherboard
    Gigabyte ga-z170-hd3
    Memory
    64 Gb
    Graphics Card(s)
    Geforce 1080 FTW
OK. I'm failing TPM 2.0 (but that's because my test system is a VM). Are you passing the Secure Boot check?

1780699718675.webp
 

My Computer

System One

  • OS
    Windows 7
for anybody still following along with pre-8th generation Intel CPU's and/or older motherboards not receiving updates - the comment from u/lokidvane in this reddit thread fixed my final attestation issue! I only needed to run the SetupME.exe in Main_DCH folder and then rebooted. Fresh issue now is not seeing the initial Failed Attestation in Warzone when i first login but then when i go to start a game, it says i still have that status 🤦🏻‍♂️ another couple steps forward and one back.
 

My Computer

System One

  • OS
    Windows 10
    Computer type
    PC/Desktop
    Manufacturer/Model
    Gigabyte
    CPU
    Intel i7-7700k
    Motherboard
    Gigabyte ga-z170-hd3
    Memory
    64 Gb
    Graphics Card(s)
    Geforce 1080 FTW
Back
Top Bottom