Page 1 of 2

TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Posted: Sat Feb 14, 2026 11:30 pm
by OldNavyGuy
TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs on Win 11 25H2 system.

Message is one of the files has an invalid signature.

Remade the UFD and still got the message

Re: TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Posted: Sun Feb 15, 2026 2:26 am
by OldNavyGuy
Fixed it by doing the following (where E: is the drive letter for the UFD)...

copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi E:\EFI\boot\bootx64.efi

Re: TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Posted: Mon Feb 16, 2026 3:22 am
by Brian K
OldNavyGuy,

The default TBWinRE UFD boots in my computer with Secure Boot enabled. Why do we have a difference?

I have the 2023 Certificates in my BIOS.

Re: TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Posted: Mon Feb 16, 2026 4:50 am
by OldNavyGuy
I revoked the old 2011 certs.

They will formally expire starting in June.

Re: TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Posted: Mon Feb 16, 2026 3:52 pm
by Fracso
OldNavyGuy wrote: Mon Feb 16, 2026 4:50 am I revoked the old 2011 certs.

They will formally expire starting in June.
And can you boot IFL? IFW in a WinPE?

Re: TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Posted: Mon Feb 16, 2026 5:04 pm
by OldNavyGuy
IFL boots from a UFD.

I don't use WinPE.

Re: TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Posted: Mon Feb 16, 2026 6:41 pm
by OldNavyGuy
Also, note that some bootable UFDs will need to be rebuilt, since the EFI partition may be read-only.

Re: TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Posted: Tue Feb 17, 2026 4:10 pm
by Fracso
OldNavyGuy wrote: Mon Feb 16, 2026 5:04 pm IFL boots from a UFD.

I don't use WinPE.
Strange - my experience is different. If the MS UEFI CA 2011 certificate is disabled (equivalent to being revoked, I think), IFL 4.10 doesn´t boot.

Re: TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Posted: Tue Feb 17, 2026 7:29 pm
by OldNavyGuy
Fracso wrote: Tue Feb 17, 2026 4:10 pm [Strange - my experience is different. If the MS UEFI CA 2011 certificate is disabled (equivalent to being revoked, I think), IFL 4.10 doesn´t boot.
Do a search for "garlin's PowerShell scripts for updating Secure Boot CA 2023" and "Ed Tittel Secure Boot Report Card Perfected"

Re: TBWinRE 4.10 UFD will not boot after installing 2023 secure boot certs

Posted: Tue Feb 17, 2026 10:58 pm
by Brian K
Strange - my experience is different. If the MS UEFI CA 2011 certificate is disabled (equivalent to being revoked, I think), IFL 4.10 doesn´t boot
Aren't you both saying the same thing? MS UEFI CA 2011 certificate is needed for IFL UFD to boot.