[SOLVED] Is it possible to fix missing Secure Boot certificates?

I am trying to setup an 11th generation Framework 13 that was previously deployed and then “factory reset”. I discovered that the Secure Boot setting is permanently set to Disabled in the firmware - it is greyed out and cannot be selected. I saw in the forum that there seems to be a known issue with the Framework firmware borking the Secure Boot certificates. This machine has Windows 11 and firmware 3.25. I’m not a Linux person and I am hoping there are some Instructions for Dummy’s™ somewhere that can walk me through how to fix this.

Edit: Of course forgot to attach photo.

Can somebody please help?

I contacted Framework support and they suggested performing a mainboard reset by removing the battery. I told them the Secure Boot option is Disabled in the firmware and the PK, KEK, and et cetera certificates are missing, and they said they did not understand what the stated problem was and asked for a photo of the Security firmware settings.

What BIOS version are you running?

Have you read this:

Hi Vikram, 3.25 I believe I’ve read through everything on the Forum and if I understand correctly, the solution is to manually install the Frame.work and Microsoft certificates. I do not know in which file format the certificates I need to install should be nor where to obtain them. This is not a Windows issue, but an issue within the Firmware regardless of OS.

Other things I have tried include downgrading the firmware, Erase all…, and Restore Secure Boot…

Framework asked if setting a password in the firmware would help? It seems their support channels are clueless on how Secure Boot, their certificates, and their own firmware works and were dragging the whole troubleshooting steps out because they had no idea how to fix the issue. Framework claimed this was a unique one-off situation and their suggestion after their firmware caused the issue is to buy a new mainboard.

I’m not at all suspicious.

Thank god I found this thread and this post directly from Framework so I at least know I am not delusional. The final post I used was this.

I managed to restore the certificates starting with a downgrade 3.22 ClearVar firmware and got the firmware and Microsoft boot keys all up to date.

Unfortunate moral of the story - don’t trust Framework’s support.