Windows secure boot 2023 certificate verification discrepancies on vSphere Virtual Machines
search cancel

Windows secure boot 2023 certificate verification discrepancies on vSphere Virtual Machines

book

Article ID: 436896

calendar_today

Updated On:

Products

VMware vCenter Server VMware vSphere ESXi

Issue/Introduction

  • After updating Microsoft Secure Boot certificates (PK and KEK) in a Windows Virtual Machine, the registry key WindowsUEFICA2023Capable remains at a value of 1 instead of transitioning to 2 (where 2 indicates a successful transition to the 2023 CA).



  • PowerShell command Get-AuthenticodeSignature S:\EFI\Microsoft\Boot\bootmgfw.efi | fl Status,SignerCertificate shows 2011 Secure Boot certificate is active.

Environment

 



Cause

The WindowsUEFICA2023Capable registry key and the Get-AuthenticodeSignature PowerShell command may provide inaccurate status reporting regarding the active Secure Boot Certificate.

Resolution

Additional Information

Reference :-