Forbidden Signature in Secure Boot Area of BIOS
Posted: Sat Apr 18, 2026 11:59 pm
I recently purchased a G-byte board B650 AORUS Elite AX Rev 1.2 and hoped to install a new BIU to the board and dual-boot Win 10 and Win 11.
Got BootIt setup, installed Win 10 disabling "fast start" then reboot and reactivate BootIt.
In Partition Work made sure "flag" 55 is set and "fast start" is disabled.
Went to Boot Edit and made partition "hide" in prep for Win 11 install later.
Then sometimes Windows boots and sometimes it doesn't. Mostly doesn't.
In the BIOS there are many options in Secure Boot and one "Modify" presents with a multitude of selections
one of which shows Secure Boot key status for several categories in BIOS
The one that always shows something is "Forbidden Signature(dbx)" that always shows up after I try unsucessfully to boot Windows 10 through BootIt.
This Signature shows the certificate (at least most of it)...
"1|SHA256 | 33| 32|77FA9ABD-...|69DB480..."
I've wiped the entire drive (Samsung SSD 970 EVO Plus) several times to prevent stray 1's or 0's from gumming up the works and although everything looks promising initially, things go downhill from there.
I had read or watched a BIUEFI video or literature that indicates Terabyte's certificate might not work unless one does a workaround invoking a sequence of numbers, letters, etc. to get the BIOS to allow older certs. which is fine except I can find no way to get to this particular code in the MoBo.
I have been at this several days now with no success and wondered if Terabyte might recognize this hash above to determine if it belongs to BootIt.
I assume BootIt offers it's own SecureBoot key and when the key is accepted the machine allows BootIt to choose the operating system to boot. But I could be wrong.
This board has been a real nightmare and doesn't seem to be able to update the BIOS no matter what I do so I may send it back and get a replacement if I can figure out whether or not this "Forbidden Signature" thing is something I can overcome. Otherwise I'm going with a different board.
Thanks for any help. I think I like MBR better...
Got BootIt setup, installed Win 10 disabling "fast start" then reboot and reactivate BootIt.
In Partition Work made sure "flag" 55 is set and "fast start" is disabled.
Went to Boot Edit and made partition "hide" in prep for Win 11 install later.
Then sometimes Windows boots and sometimes it doesn't. Mostly doesn't.
In the BIOS there are many options in Secure Boot and one "Modify" presents with a multitude of selections
one of which shows Secure Boot key status for several categories in BIOS
The one that always shows something is "Forbidden Signature(dbx)" that always shows up after I try unsucessfully to boot Windows 10 through BootIt.
This Signature shows the certificate (at least most of it)...
"1|SHA256 | 33| 32|77FA9ABD-...|69DB480..."
I've wiped the entire drive (Samsung SSD 970 EVO Plus) several times to prevent stray 1's or 0's from gumming up the works and although everything looks promising initially, things go downhill from there.
I had read or watched a BIUEFI video or literature that indicates Terabyte's certificate might not work unless one does a workaround invoking a sequence of numbers, letters, etc. to get the BIOS to allow older certs. which is fine except I can find no way to get to this particular code in the MoBo.
I have been at this several days now with no success and wondered if Terabyte might recognize this hash above to determine if it belongs to BootIt.
I assume BootIt offers it's own SecureBoot key and when the key is accepted the machine allows BootIt to choose the operating system to boot. But I could be wrong.
This board has been a real nightmare and doesn't seem to be able to update the BIOS no matter what I do so I may send it back and get a replacement if I can figure out whether or not this "Forbidden Signature" thing is something I can overcome. Otherwise I'm going with a different board.
Thanks for any help. I think I like MBR better...