Share via

Secure Boot certificates have been updated but are not yet applied

Wilson T 225 Reputation points
2025-12-09T05:17:43.8733333+00:00

Hello,

User's image

What's this? Do I need to take any action about it or just leave it alone?

Thanks very muchπŸ˜€

Windows for home | Windows 11 | Performance and system failures

Answer accepted by question author
  1. Alexandr S 104.6K Reputation points Independent Advisor
    2025-12-09T06:03:24.0433333+00:00

    Hello, Wilson T.

    If the OS is stable, you can ignore these messages. Judging by the information from the screenshot, they relate to updates from Lenovo (the manufacturer of your PC).

    P.S. Even on a fully functional PC and a working OS, there are always similar messages in the Event Viewer. This is the normal behavior of the log collector.

    1 person found this answer helpful.

Answer recommended by moderator
  1. John Westfield 90 Reputation points
    2025-12-25T20:58:31.54+00:00

    With the optional update from October 28 (KB5067036), Microsoft introduced a CLI tool for the WinCS API. Install https://support.microsoft.com/en-us/topic/windows-configuration-system-wincs-apis-for-secure-boot-d3e64aa0-6095-4f8a-b8e4-fbfda254a8fe

    Now install this PowerShell-Module:

    Install-Module UEFIv2 -Force
    

    You can list now the certificates:

    Get-UEFISecureBootCerts db | select SignatureSubject
    
    
    Get-UEFISecureBootCerts kek | select SignatureSubject
    
    
    

    Certificates which are updated are listed here:

    https://support.microsoft.com/en-us/topic/windows-secure-boot-certificate-expiration-and-ca-updates-7ff40d33-95dc-4c3c-8725-a9b95457578e

    WinCsFlags is going to update ALL FOUR certificates listed. Also the one stored in KEK.

    Now set the update configuration:

    WinCsFlags.exe /apply --key "F33E0C8E002"
    
    

    Now, run the Scheduled Task Secure-Boot-Update.

    Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"
    
    
    

    Reboot twice and check again for the certificates and the Event-Log.

    If all is updated, you can set back the update configuration:

    WinCsFlags.exe /apply --key "F33E0C8E001"
    
    
    5 people found this answer helpful.

7 additional answers

Sort by: Most helpful
  1. 2025-12-20T19:23:18.3866667+00:00

    finally i tried it myself and succeeded, for fix that. 1 unistall security on "devices manager" and then restart pc. after back to dekstop windows try open delta force and then not show green screen again.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.