TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

User discussion and information resource forum for TeraByte Drive Image products, including TBNetManage.
OldNavyGuy
Posts: 237
Joined: Mon Apr 17, 2023 4:08 am

Re: TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Post by OldNavyGuy »

Brian K wrote: Tue Feb 17, 2026 10:58 pm
Aren't you both saying the same thing? MS UEFI CA 2011 certificate is needed for IFL UFD to boot.
No.

I revoked the 2011 cert (mentioned above), and the IFL UFD boots with no issues.
TeraByte Support
Posts: 4105
Joined: Thu May 05, 2011 10:37 pm

Re: TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Post by TeraByte Support »

There was two different certificates MS signed UEFI with, the one for MS stuff, and the one for the 3rd party stuff. Windows (TBWinPE/RE) is signed by MS for MS, IFL is signed by the 3rd party certificate.
OldNavyGuy
Posts: 237
Joined: Mon Apr 17, 2023 4:08 am

Re: TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Post by OldNavyGuy »

Yeah, it looks like the 3rd party cert did not get revoked...

EFI Files
---------
Disk 0: Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.

Registry: WindowsUEFICA2023Capable = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

Disk 0: SkuSiPolicy.p7b (for VBS) is CURRENT.

Bootable Media
--------------
DVD Drive D:
USB Drive E: "IFL_4_10"
Boot File [Microsoft Corporation UEFI CA 2011] is ALLOWED.

STATUS REPORT
-------------
Registry: UEFICA2023Status = Updated

SUCCESS: NO UPDATES ARE REQUIRED.
Fracso
Posts: 108
Joined: Fri Nov 08, 2013 12:37 am

Re: TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Post by Fracso »

Comment from member garlin in the Windows Eleven Forums. garlin has developed a set of scripts to manage the update, and has provided a lot of support about this topic.

https://www.elevenforum.com/t/garlins-p ... ost-712348

"We don't revoke the Microsoft UEFI CA 2011 because that cert is reserved for booting Linux. Windows PCA 2011 covers Windows releases.

The cert names may be confusing. Microsoft owns the UEFI CA 2011 cert, because MS provided it on behalf of Linux distros since no OEM is going to bundle every distro's unique signing certs in the BIOS. So they share a generic one to get past the UEFI security check.

Any cert that includes the word "Windows" manages Windows boot files.

I'm avoiding anything that would impact a Linux setup. Most Linuxes use the SBAT file on the EFI partition as their equivalent method of banning outdated boot files."
Post Reply