Page 2 of 2

Re: TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Posted: Tue Feb 17, 2026 11:30 pm
by OldNavyGuy
Brian K wrote: Tue Feb 17, 2026 10:58 pm
Aren't you both saying the same thing? MS UEFI CA 2011 certificate is needed for IFL UFD to boot.
No.

I revoked the 2011 cert (mentioned above), and the IFL UFD boots with no issues.

Re: TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Posted: Tue Feb 17, 2026 11:51 pm
by TeraByte Support
There was two different certificates MS signed UEFI with, the one for MS stuff, and the one for the 3rd party stuff. Windows (TBWinPE/RE) is signed by MS for MS, IFL is signed by the 3rd party certificate.

Re: TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Posted: Wed Feb 18, 2026 12:44 am
by OldNavyGuy
Yeah, it looks like the 3rd party cert did not get revoked...

EFI Files
---------
Disk 0: Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.

Registry: WindowsUEFICA2023Capable = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.

Disk 0: SkuSiPolicy.p7b (for VBS) is CURRENT.

Bootable Media
--------------
DVD Drive D:
USB Drive E: "IFL_4_10"
Boot File [Microsoft Corporation UEFI CA 2011] is ALLOWED.

STATUS REPORT
-------------
Registry: UEFICA2023Status = Updated

SUCCESS: NO UPDATES ARE REQUIRED.

Re: TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Posted: Sun Feb 22, 2026 12:36 am
by Fracso
Comment from member garlin in the Windows Eleven Forums. garlin has developed a set of scripts to manage the update, and has provided a lot of support about this topic.

https://www.elevenforum.com/t/garlins-p ... ost-712348

"We don't revoke the Microsoft UEFI CA 2011 because that cert is reserved for booting Linux. Windows PCA 2011 covers Windows releases.

The cert names may be confusing. Microsoft owns the UEFI CA 2011 cert, because MS provided it on behalf of Linux distros since no OEM is going to bundle every distro's unique signing certs in the BIOS. So they share a generic one to get past the UEFI security check.

Any cert that includes the word "Windows" manages Windows boot files.

I'm avoiding anything that would impact a Linux setup. Most Linuxes use the SBAT file on the EFI partition as their equivalent method of banning outdated boot files."