Page 1 of 2
2023 Secure Boot compliant iflnet.iso
Posted: Wed Jun 03, 2026 1:25 am
by OldNavyGuy
I am unable to create a bootable IFL recovery UFD since the 2023 Secure Boot compliant certs were installed for a Windows 11 25H2 system.
Tried both the IFL makedisk function, and Rufus.
All other UFDs I am using are now compliant.
When is a compliant iflnet.iso expected to be release?
Re: 2023 Secure Boot compliant iflnet.iso
Posted: Wed Jun 03, 2026 5:31 am
by TeraByte Support
You'd only not be able to boot in secure boot mode if they (or you) removed the "Microsoft UEFI CA 2011" certificate.
As far as an update to use 2023 version, once Microsoft signs it.
Re: 2023 Secure Boot compliant iflnet.iso
Posted: Wed Jun 03, 2026 7:43 am
by OldNavyGuy
TeraByte Support wrote: Wed Jun 03, 2026 5:31 am
You'd only not be able to boot in secure boot mode if they (or you) removed the "Microsoft UEFI CA 2011" certificate.
The 2011 cert is there, and it's been banned.
Bootable Media
--------------
USB Drive E: "IFL_4_10"
Boot File [Microsoft Corporation UEFI CA 2011] is BANNED.
E:\EFI\Boot\bootx64.efi
File Version: 0.0, SVN 0.0
That doesn't seem to be the main issue though.
The IFL bootloader complains that it can't find mmx64.efi, which is not included in \EFI\boot.
Ubuntu 26.04 also has a banned 2011 cert, but has mmx64.efi, and it boots fine.
Re: 2023 Secure Boot compliant iflnet.iso
Posted: Wed Jun 03, 2026 2:11 pm
by TeraByte Support
If it's banned it's the same thing as being removed. The mok fall back is always disabled/not included, it wouldn't make a difference unless you had another certificate installed. Frankly if it was banned (in dbx) it shouldn't even run anything at all; I think what you're actually seeing is an SBAT issue, most likely it upgraded either peloader to 2 or grub to 5. That happens if you run anything that is at that level, it blocks everything else, the next release grub is at that level.
Re: 2023 Secure Boot compliant iflnet.iso
Posted: Thu Jun 04, 2026 12:29 am
by OldNavyGuy
Since everything else is working with Secure Boot (including Ubuntu 26.04 on a UFD), we'll wait for a new IFL ISO, and use TBWinRE.
Re: 2023 Secure Boot compliant iflnet.iso
Posted: Thu Jun 04, 2026 2:57 am
by Brian K
OldNavyGuy,
It's certainly confusing. I have 2 IFL UFDs, net and non-net. Made with Makedisk. Not from an ISO. Both boot with Secure Boot enabled.
Win11, Linux Mint and IFL partitions boot with Secure Boot enabled.
I have other bootable partitions.
In the last month or so these partitions don't boot with Secure Boot enabled...
Win10, Win11 LTSC, TBWinRE/PE, Active@Boot.
I see "Could not install security protocol: (0x2) Invalid parameter"
These partitions boot with Secure Boot disabled. Then if I try to boot with Secure Boot enabled, it works for several boots. Weird.
A TBWinRE UFD does boot with Secure Boot enabled. But the TBWinRE partition doesn't.
Re: 2023 Secure Boot compliant iflnet.iso
Posted: Thu Jun 04, 2026 7:04 am
by OldNavyGuy
The current version of IFL failed with UFDs made with Makedisk, and Rufus.
A properly signed bootloader will fix the issue...
Re: 2023 Secure Boot compliant iflnet.iso
Posted: Thu Jun 04, 2026 8:53 am
by Brian K
I assume we are using the same IFL downloads. I don't understand why my IFL boots and yours doesn't.
Re: 2023 Secure Boot compliant iflnet.iso
Posted: Thu Jun 04, 2026 11:53 pm
by OldNavyGuy
IFL 4.10
If you want to do a deep dive on your 2023 certs, check out "garlin" on ElevenForum.
Garlin has a nice set of PowerShell scripts that will not only give you the status of your certs, but help you update, or correct errors, if need be.
There is a looooong thread on ElevenForum.
Garlin's github repository...
https://github.com/garlin-cant-code/Sec ... 23-Updates
If all you want to do is get a status of your system and bootable media, run this script...
.\Check_UEFI-CA2023.ps1 -BootMedia -Verbose
Before running, check the properties on the script(s) and check Unblock, otherwise you'll get an error.
Re: 2023 Secure Boot compliant iflnet.iso
Posted: Fri Jun 05, 2026 5:36 am
by TeraByte Support
it's more likely SBAT. The upgrade should be out within a few days.