Forbidden Signature in Secure Boot Area of BIOS

User discussion and information resource forum for BootIt Bare Metal, BootIt UEFI and PartWork for Windows
plain
Posts: 72
Joined: Tue Dec 18, 2012 6:33 pm

Forbidden Signature in Secure Boot Area of BIOS

Post by plain »

I recently purchased a G-byte board B650 AORUS Elite AX Rev 1.2 and hoped to install a new BIU to the board and dual-boot Win 10 and Win 11.
Got BootIt setup, installed Win 10 disabling "fast start" then reboot and reactivate BootIt.
In Partition Work made sure "flag" 55 is set and "fast start" is disabled.
Went to Boot Edit and made partition "hide" in prep for Win 11 install later.

Then sometimes Windows boots and sometimes it doesn't. Mostly doesn't.
In the BIOS there are many options in Secure Boot and one "Modify" presents with a multitude of selections
one of which shows Secure Boot key status for several categories in BIOS
The one that always shows something is "Forbidden Signature(dbx)" that always shows up after I try unsucessfully to boot Windows 10 through BootIt.
This Signature shows the certificate (at least most of it)...
"1|SHA256 | 33| 32|77FA9ABD-...|69DB480..."

I've wiped the entire drive (Samsung SSD 970 EVO Plus) several times to prevent stray 1's or 0's from gumming up the works and although everything looks promising initially, things go downhill from there.

I had read or watched a BIUEFI video or literature that indicates Terabyte's certificate might not work unless one does a workaround invoking a sequence of numbers, letters, etc. to get the BIOS to allow older certs. which is fine except I can find no way to get to this particular code in the MoBo.
I have been at this several days now with no success and wondered if Terabyte might recognize this hash above to determine if it belongs to BootIt.

I assume BootIt offers it's own SecureBoot key and when the key is accepted the machine allows BootIt to choose the operating system to boot. But I could be wrong.

This board has been a real nightmare and doesn't seem to be able to update the BIOS no matter what I do so I may send it back and get a replacement if I can figure out whether or not this "Forbidden Signature" thing is something I can overcome. Otherwise I'm going with a different board.

Thanks for any help. I think I like MBR better...:)
Brian K
Posts: 2720
Joined: Fri Aug 12, 2011 1:11 am

Re: Forbidden Signature in Secure Boot Area of BIOS

Post by Brian K »

Plain, I have a GigaByte B660M Aurus Pro motherboard. But our BIOS updates are different. I downloaded your update and noted there are no instructions. What issue are you having with updating the BIOS?
Last edited by Brian K on Sun Apr 19, 2026 6:25 am, edited 1 time in total.
TeraByte Support
Posts: 4105
Joined: Thu May 05, 2011 10:37 pm

Re: Forbidden Signature in Secure Boot Area of BIOS

Post by TeraByte Support »

If BootIt UEFI boots with secure boot enabled, then you have the correct MS certificate installed. If not, ensure you're using the latest version of BIU which has the latest MS signatures (it is signed by MS). As far as Windows itself, they control all that and what goes in your dbx. There would typically be a message saying something was refused or signature missing if related to secure boot (even if it only flashed for a second).
plain
Posts: 72
Joined: Tue Dec 18, 2012 6:33 pm

Re: Forbidden Signature in Secure Boot Area of BIOS

Post by plain »

Thank You Guys so much for replying.

I finally was able to update BIOS last night. (I finally had to start updating sequentially from the BIOS that came on the board). Gigabyte's documentation... well you know. Not like in the past.

I updated only to the point that Windows 10 was still being supported (like July, 2025), knowing MS and board mfgr.s commit various skullduggeries to prevent MS operating systems from being convenient and trusted once a new OS comes out (I'm still in love with Windows 7).
I did get a message in a couple of attempts:
"Warning: Unable to point UEFI to current boot item (1h 98EB3978h)"

Good to know BIU will load and it has done so every time if I remember correctly. Version is 2.10, USB installed with "makedisk.exe". Some failures were my own fault but your video helped a lot (Thinking about it ALL failures are my own fault LOL). At first, I wasn't wiping the drive with BIU but started doing that to make sure.

This board does have provisions for CSM so it may be I can go to MBR instead but I would really like to make
UEFI work if possible. Ultimately, I would like to be able to triple boot with Ubuntu if I can get over this bump.

Again, Thanks
Brian K
Posts: 2720
Joined: Fri Aug 12, 2011 1:11 am

Re: Forbidden Signature in Secure Boot Area of BIOS

Post by Brian K »

Plain, you mentioned that Hide was used for the Win10 partition. Was this in the pending Win11 Boot Item?

Is Win10 booting everytime now?
plain
Posts: 72
Joined: Tue Dec 18, 2012 6:33 pm

Re: Forbidden Signature in Secure Boot Area of BIOS

Post by plain »

Windows 10 is not booting just the dots in a circle.
So I went into BIOS after each step and found the "Forbidden Signatures" status as "Mixed" right after the OS install using a Rufus created USB. Up to this time the Secure Boot Signature area all had "Factory" in their values including "Forbidden Signatures" except the last two which had "No Keys" as status.
This was at the point I inserted the Bootit USB but had not yet reactivated Bootit and set it up to boot Wiindows 10.
I had disabled Fast Start in the OS at the time it had completed the install so that didn't show up in Bootit when I reactivated and it showed to be "disabled". I then set the 55 flag, named the partition Win10,in Partition Work and marked it as hidden in Boot Edit.

I'm wondering now if Rufus pollutes the Secure Boot area when you make its choices about how to install the OS? I used Rufus on both 10 and 11.
Do you have a suggestion as to what might be better to set up the USB? I was going to use MS Media Creation tool but don't have one for 22H2, only 21H2.
I tried putting up a picture but since we both have similar boards maybe yours looks the same.
I forgot to mention once I was faced with this problem at the start I only kept trying to install Windows 10 because there was no need to go further.
plain
Posts: 72
Joined: Tue Dec 18, 2012 6:33 pm

Re: Forbidden Signature in Secure Boot Area of BIOS

Post by plain »

I have 6 Secure Boot "variables" as Gigabyte calls them on this board and BIOS revision (FB7):
Platform Key
Key Exchange Keys
Authorized Signatures
Forbidden Signatures
Authorized TimeStamps
OSRecovery Signatures

I started out (before installing BIU)with the top 4 populated as "Factory" including Forbidden Signatures.
These values stayed the same with each step up to accessing the BIOS right after OS install but before reactivating BIU then Forbidden became "mixed".
plain
Posts: 72
Joined: Tue Dec 18, 2012 6:33 pm

Re: Forbidden Signature in Secure Boot Area of BIOS

Post by plain »

Okay, I redid my install USB using Media Creation Tool for Windows 10 22H2 (found it through Google) and still wind up with Forbidden Signature.
Not sure now what to do but wanted to let you know I'm trying anyway. :)

Edit: I don't know what happened but after I got out of the BIOS and reactvated BIU and rebooted guess what?, Windows 10 showed up. I'm going to reboot a few times before trying Windows 11. This is pretty aggravating not knowing WHY it is working like it is meant to now but I guess I should be happy right? Once I get things set up I won't fool with it for years.
Last edited by plain on Sun Apr 19, 2026 8:33 pm, edited 1 time in total.
Brian K
Posts: 2720
Joined: Fri Aug 12, 2011 1:11 am

Re: Forbidden Signature in Secure Boot Area of BIOS

Post by Brian K »

Plain, I'm confused. Do you have the Win10 partition Hidden in the Win10 Boot Item. That will prevent Win10 loading. You will see the spinning dots.
plain
Posts: 72
Joined: Tue Dec 18, 2012 6:33 pm

Re: Forbidden Signature in Secure Boot Area of BIOS

Post by plain »

Ah! That may have been my problem! I will have to boot back into BIU and set up Boot Edit without "hiding" and Partition Works setting the 55 flag.
Post Reply