{"id":7361,"date":"2026-06-15T13:48:15","date_gmt":"2026-06-15T20:48:15","guid":{"rendered":"https:\/\/www.terabyteunlimited.com\/kb\/?post_type=lsvr_kba&#038;p=7361"},"modified":"2026-06-15T13:48:15","modified_gmt":"2026-06-15T20:48:15","slug":"windows-will-not-reinstall-the-windows-uefi-ca-2023-certificates","status":"publish","type":"lsvr_kba","link":"https:\/\/www.terabyteunlimited.com\/kb\/kb-articles\/windows-will-not-reinstall-the-windows-uefi-ca-2023-certificates\/","title":{"rendered":"Windows Will Not Reinstall the Windows UEFI CA 2023 Certificates"},"content":{"rendered":"<h2>Problem<\/h2>\r\n<p>Windows does not reinstall the Windows UEFI CA 2023 Secure Boot certificates after the system\u2019s Secure Boot certificate databases have been reverted to the older 2011 certificate set.<\/p>\r\n<h2>Cause<\/h2>\r\n<p>The system was previously updated to boot using the Windows UEFI CA 2023 certificates. However, the firmware Secure Boot certificate databases were later restored or reverted to the 2011 certificate set.<\/p>\r\n<p>As a result, the system may still contain 2023-signed Windows boot files, but the firmware no longer trusts the Windows UEFI CA 2023 certificate required to boot those files with Secure Boot enabled.<\/p>\r\n<h2>Symptoms<\/h2>\r\n<p>When attempting to run the Secure Boot certificate update again:<\/p>\r\n<ul>\r\n\t<li>\r\n<p><code>AvailableUpdates<\/code> is reset to <code>0<\/code>.<\/p>\r\n<\/li>\r\n\t<li>\r\n<p><code>UEFICA2023Status<\/code> is briefly set to <code>InProgress<\/code>.<\/p>\r\n<\/li>\r\n\t<li>\r\n<p>Shortly afterward, <code>UEFICA2023Status<\/code> returns to <code>NotStarted<\/code>.<\/p>\r\n<\/li>\r\n\t<li>\r\n<p>The Windows UEFI CA 2023 certificates are not restored.<\/p>\r\n<\/li>\r\n<\/ul>\r\n<h2>Solution<\/h2>\r\n<p>Temporarily restore Windows boot files signed by the 2011 certificate set, enable Secure Boot, and then run the Windows Secure Boot update process again.<\/p>\r\n<p>At minimum, restore the 2011-signed versions of the following files:<\/p>\r\n<pre><code class=\"language-text\">&#92;EFI&#92;Boot&#92;bootx64.efi\r\n&#92;EFI&#92;Microsoft&#92;Boot&#92;bootmgfw.efi\r\n<\/code><\/pre>\r\n<p>One way to do this from Windows is to use TBOSDT.<\/p>\r\n<h2>Restoring the 2011-Signed Boot Files with TBOSDT<\/h2>\r\n<p>Start TBOSDT as an Administrator.<\/p>\r\n<p>Change to aggressive locking:<\/p>\r\n<pre><code class=\"language-text\">set option locking 2\r\n<\/code><\/pre>\r\n<p>List the hard drives to find the drive containing the EFI System Partition:<\/p>\r\n<pre><code class=\"language-text\">list hd 0\r\nlist hd 1\r\n<\/code><\/pre>\r\n<p>Continue checking drives as needed. Locate the partition with a type similar to:<\/p>\r\n<pre><code class=\"language-text\">EFI System (FAT-32)\r\n<\/code><\/pre>\r\n<p>Note the partition ID shown in parentheses. This ID is needed to mount the EFI System Partition.<\/p>\r\n<p>For example, if the EFI System Partition is on hard drive <code>0<\/code> and has partition ID <code>01<\/code>, mount it with:<\/p>\r\n<pre><code class=\"language-text\">mount 0: 0 0x01\r\n<\/code><\/pre>\r\n<p>Make backup copies of the existing boot files in case they need to be restored later:<\/p>\r\n<pre><code class=\"language-text\">copy 0:&#92;efi&#92;boot&#92;bootx64.efi 0:&#92;efi&#92;boot&#92;bootx64_org.efi\r\ncopy 0:&#92;efi&#92;microsoft&#92;boot&#92;bootmgfw.efi 0:&#92;efi&#92;microsoft&#92;boot&#92;bootmgfw_org.efi\r\n<\/code><\/pre>\r\n<p>Copy the 2011-signed Windows boot file from Windows to the EFI System Partition:<\/p>\r\n<pre><code class=\"language-text\">copy \/y c:&#92;windows&#92;boot&#92;efi&#92;bootmgfw.efi 0:&#92;efi&#92;boot&#92;bootx64.efi\r\ncopy \/y c:&#92;windows&#92;boot&#92;efi&#92;bootmgfw.efi 0:&#92;efi&#92;microsoft&#92;boot&#92;bootmgfw.efi\r\n<\/code><\/pre>\r\n<p>Unmount the EFI System Partition:<\/p>\r\n<pre><code class=\"language-text\">umount 0:\r\n<\/code><\/pre>\r\n<p>Reboot the system and enter the BIOS\/UEFI setup:<\/p>\r\n<pre><code class=\"language-text\">reboot \/b\r\n<\/code><\/pre>\r\n<p>Enable Secure Boot in the BIOS\/UEFI setup.<\/p>\r\n<p>After restoring the 2011-signed boot files and enabling Secure Boot, boot Windows.<\/p>\r\n<h2>Run the Windows Secure Boot Update<\/h2>\r\n<p>From an elevated Command Prompt, run:<\/p>\r\n<pre><code class=\"language-cmd\">reg add HKLM&#92;SYSTEM&#92;CurrentControlSet&#92;Control&#92;SecureBoot \/v AvailableUpdates \/t REG_DWORD \/d 0x5944 \/f\r\nschtasks \/Run \/TN \"&#92;Microsoft&#92;Windows&#92;PI&#92;Secure-Boot-Update\"\r\n<\/code><\/pre>\r\n<p>Reboot the system.<\/p>\r\n<p>After Windows starts again, run the Secure Boot update task a second time:<\/p>\r\n<pre><code class=\"language-cmd\">schtasks \/Run \/TN \"&#92;Microsoft&#92;Windows&#92;PI&#92;Secure-Boot-Update\"\r\n<\/code><\/pre>\r\n<h2>Verification<\/h2>\r\n<p>When the update completes successfully, the following registry value should show:<\/p>\r\n<pre><code class=\"language-text\">UEFICA2023Status = Updated\r\n<\/code><\/pre>\r\n<p>Registry location:<\/p>\r\n<pre><code class=\"language-text\">HKEY_LOCAL_MACHINE&#92;SYSTEM&#92;CurrentControlSet&#92;Control&#92;SecureBoot&#92;Servicing\r\n<\/code><\/pre>\r\n<p>You may also verify that the Windows UEFI CA 2023 certificate has been restored to the firmware Secure Boot database by running the following command from an elevated PowerShell prompt:<\/p>\r\n<pre><code class=\"language-powershell\">Get-SecureBootUEFI -Name db -Decoded\r\n<\/code><\/pre>\r\n<p>Look for an entry for:<\/p>\r\n<pre><code class=\"language-text\">Windows UEFI CA 2023\r\n<\/code><\/pre>\r\n<h2>Notes<\/h2>\r\n<p>Do not attempt to complete the Windows UEFI CA 2023 update while the system can only boot with Secure Boot disabled. The system must be able to boot successfully with Secure Boot enabled, using boot files trusted by the current firmware Secure Boot database, before Windows can reliably apply the Secure Boot certificate update.<\/p>\r\n<p>After the Windows UEFI CA 2023 certificates are restored and the update status shows <code>Updated<\/code>, Windows can again install and use the 2023-signed Windows boot files.<\/p>","protected":false},"excerpt":{"rendered":"<p>Problem Windows does not reinstall the Windows UEFI CA 2023 Secure Boot certificates after the system\u2019s Secure Boot certificate databases have been reverted to the older 2011 certificate set. Cause The system was previously updated to boot using the Windows UEFI CA 2023 certificates. However, the firmware Secure Boot certificate databases were later restored or [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"lsvr_kba_cat":[1817,1780],"lsvr_kba_tag":[],"class_list":["post-7361","lsvr_kba","type-lsvr_kba","status-publish","hentry","lsvr_kba_cat-vista-win7-8-x-10","lsvr_kba_cat-windows"],"_links":{"self":[{"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba\/7361","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba"}],"about":[{"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/types\/lsvr_kba"}],"author":[{"embeddable":true,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/comments?post=7361"}],"version-history":[{"count":3,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba\/7361\/revisions"}],"predecessor-version":[{"id":7364,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba\/7361\/revisions\/7364"}],"wp:attachment":[{"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/media?parent=7361"}],"wp:term":[{"taxonomy":"lsvr_kba_cat","embeddable":true,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba_cat?post=7361"},{"taxonomy":"lsvr_kba_tag","embeddable":true,"href":"https:\/\/www.terabyteunlimited.com\/kb\/wp-json\/wp\/v2\/lsvr_kba_tag?post=7361"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}