Just learned of the expiring keys for Secure Boot and that I need a BIOS upgrade. Note that I am NOT a power user. Found and installed the upgrade, checked that my driver bundle is in fact current. Windows Security still says Secure Boot cannot be enabled.
QUESTION 1: If all is well and ready, do I need t wait for the next Win11 update for the new files to be recognized before Secure Boot is enabled?
After the update, there are no updated KEK files. Only two entries:
KEK Signature List:
- [PKCS7] Microsoft Corporation KEK CA 2011
- [PKCS7] frame.work-LaptopKEK
Also post-update, the following shows up on the DB page:
DB Signature List:
- [PKCS7] Microsoft Windows Production PCA 2011
- [PKCS7] Microsoft Corporation UEFI CA 2011
- [PKCS7] frame.work-LaptopDB
- [PKCS7] Windows UEFI CA 2023
- [PKCS7] Microsoft Option ROM UEFI CA 2023
- [PKCS7] Microsoft UEFI CA 2023
QUESTION 2: Do these files look correct, or is there something missing (like a 2023 KEK file or files)?
QUESTION 3: If all is not well, how do I go about correcting it?