2023 Secure Boot compliant iflnet.iso

User discussion and information resource forum for TeraByte Drive Image products, including TBNetManage.
OldNavyGuy
Posts: 237
Joined: Mon Apr 17, 2023 4:08 am

2023 Secure Boot compliant iflnet.iso

Post by OldNavyGuy »

I am unable to create a bootable IFL recovery UFD since the 2023 Secure Boot compliant certs were installed for a Windows 11 25H2 system.

Tried both the IFL makedisk function, and Rufus.

All other UFDs I am using are now compliant.

When is a compliant iflnet.iso expected to be release?
TeraByte Support
Posts: 4105
Joined: Thu May 05, 2011 10:37 pm

Re: 2023 Secure Boot compliant iflnet.iso

Post by TeraByte Support »

You'd only not be able to boot in secure boot mode if they (or you) removed the "Microsoft UEFI CA 2011" certificate.

As far as an update to use 2023 version, once Microsoft signs it.
OldNavyGuy
Posts: 237
Joined: Mon Apr 17, 2023 4:08 am

Re: 2023 Secure Boot compliant iflnet.iso

Post by OldNavyGuy »

TeraByte Support wrote: Wed Jun 03, 2026 5:31 am You'd only not be able to boot in secure boot mode if they (or you) removed the "Microsoft UEFI CA 2011" certificate.
The 2011 cert is there, and it's been banned.

Bootable Media
--------------
USB Drive E: "IFL_4_10"
Boot File [Microsoft Corporation UEFI CA 2011] is BANNED.
E:\EFI\Boot\bootx64.efi
File Version: 0.0, SVN 0.0

That doesn't seem to be the main issue though.

The IFL bootloader complains that it can't find mmx64.efi, which is not included in \EFI\boot.

Ubuntu 26.04 also has a banned 2011 cert, but has mmx64.efi, and it boots fine.
TeraByte Support
Posts: 4105
Joined: Thu May 05, 2011 10:37 pm

Re: 2023 Secure Boot compliant iflnet.iso

Post by TeraByte Support »

If it's banned it's the same thing as being removed. The mok fall back is always disabled/not included, it wouldn't make a difference unless you had another certificate installed. Frankly if it was banned (in dbx) it shouldn't even run anything at all; I think what you're actually seeing is an SBAT issue, most likely it upgraded either peloader to 2 or grub to 5. That happens if you run anything that is at that level, it blocks everything else, the next release grub is at that level.
OldNavyGuy
Posts: 237
Joined: Mon Apr 17, 2023 4:08 am

Re: 2023 Secure Boot compliant iflnet.iso

Post by OldNavyGuy »

Since everything else is working with Secure Boot (including Ubuntu 26.04 on a UFD), we'll wait for a new IFL ISO, and use TBWinRE.
Brian K
Posts: 2720
Joined: Fri Aug 12, 2011 1:11 am

Re: 2023 Secure Boot compliant iflnet.iso

Post by Brian K »

OldNavyGuy,

It's certainly confusing. I have 2 IFL UFDs, net and non-net. Made with Makedisk. Not from an ISO. Both boot with Secure Boot enabled.
Win11, Linux Mint and IFL partitions boot with Secure Boot enabled.

I have other bootable partitions.
In the last month or so these partitions don't boot with Secure Boot enabled...
Win10, Win11 LTSC, TBWinRE/PE, Active@Boot.
I see "Could not install security protocol: (0x2) Invalid parameter"

These partitions boot with Secure Boot disabled. Then if I try to boot with Secure Boot enabled, it works for several boots. Weird.

A TBWinRE UFD does boot with Secure Boot enabled. But the TBWinRE partition doesn't.
OldNavyGuy
Posts: 237
Joined: Mon Apr 17, 2023 4:08 am

Re: 2023 Secure Boot compliant iflnet.iso

Post by OldNavyGuy »

The current version of IFL failed with UFDs made with Makedisk, and Rufus.

A properly signed bootloader will fix the issue...
Brian K
Posts: 2720
Joined: Fri Aug 12, 2011 1:11 am

Re: 2023 Secure Boot compliant iflnet.iso

Post by Brian K »

I assume we are using the same IFL downloads. I don't understand why my IFL boots and yours doesn't.
OldNavyGuy
Posts: 237
Joined: Mon Apr 17, 2023 4:08 am

Re: 2023 Secure Boot compliant iflnet.iso

Post by OldNavyGuy »

IFL 4.10

If you want to do a deep dive on your 2023 certs, check out "garlin" on ElevenForum.

Garlin has a nice set of PowerShell scripts that will not only give you the status of your certs, but help you update, or correct errors, if need be.

There is a looooong thread on ElevenForum.

Garlin's github repository...

https://github.com/garlin-cant-code/Sec ... 23-Updates

If all you want to do is get a status of your system and bootable media, run this script...

.\Check_UEFI-CA2023.ps1 -BootMedia -Verbose

Before running, check the properties on the script(s) and check Unblock, otherwise you'll get an error.
TeraByte Support
Posts: 4105
Joined: Thu May 05, 2011 10:37 pm

Re: 2023 Secure Boot compliant iflnet.iso

Post by TeraByte Support »

it's more likely SBAT. The upgrade should be out within a few days.
Post Reply