Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Hasleo Offine WinPE.OPE and 2023 Secure Boot Certificates
#1
Today I was successfully able to salvage my 2019 Dell XPS 8930 SE, which was destined to lose Secure Boot status because the 2011 Secure Boot Certificates are expiring at the end of the month.  Dell refused to provide a solution to update the Certificates for any of its computers sold more than five years ago.

I therefore had to learn how to manually add the necessary 2023 Secure Boot Certificates to the BIOS.  I was greatly assisted by a Guru at another Forum.

That brings up a question: does the Hasleo Offline WinPE.OPE file have to be recreated as a result?  My .OPE file dates back to 2026-04-23.

Have a great day.

Regards,
Phil
Reply
#2
(06-16-2026, 04:04 AM)garioch7 Wrote: That brings up a question: does the Hasleo Offline WinPE.OPE file have to be recreated as a result?  My .OPE file dates back to 2026-04-23.

That OPE file you downloaded is just the Microsoft base image that is used for building your HBS WinPE.
You can download a newer version from time to time, but MS rarely offers new versions anyway.

The important part is that you check "Enable support for 'Windows UEFI CA 2023'" during the WinPE creation process:

[Image: FeJEtKHh_t.png]

In the last step before exporting your final ISO or copying over to USB it will also show this text in red:
"The current WinPE image ISO supports 'Windows UEFI CA 2023'"

If you can read this, your ISO will support the CA 2023 certificate.

Once MS has revoked the old 2011 certificate sometime later this year, you'll be able to test this by booting from your USB drive.
At the moment it doesn't matter what you've selected during the creation because MS currently still allows both certificates in BIOS.
Reply
#3
@al3x,

Thank you for your prompt and informative reply.  I will continue using my April .OPE file when building Emergency Disks, but will make sure that I check that option.

Have a great day.

Regards,
Phil
Reply
#4
@al3x,

Thanks for your professional and detailed reply.

Best regards,
Reply
#5
Following up on the above; an interesting situation developed after the BIOS and Win 11 was updated for CA 2023 and the old CA 2011 revoked, and Secure Boot enabled in the BIOS.

1. An HBS-ED created with CA 2023
- boots normally from the Windows Menu
- boots normally from a USB
- fails when launched from Ventoy (Secure Boot version check failed)

2. An HBS-ED created without CA 2023
- boots normally from the Windows Menu
- fails to boot from a USB (Secure Boot failure)
- boots normally when launched from Ventoy

Both both normally when Secure Boot is off.

The results from booting from Ventoy is unexpected, and strange.

Get-SecureBootSVN returns 9.0 for all SVN's.
Reply
#6
Did you setup Ventoy to boot from Secure Boot?

About Secure Boot in UEFI mode
https://www.ventoy.net/en/doc_secure.html
Reply
#7
Looks like this might be a Ventoy problem unfortunately. If Ventoy with 2011 HBS ISO works then Ventoy probably replaces the 2011 cert during boot with its own cert that you inserted in BIOS previously.

Maybe Ventoy has problems with the injection of its own cert with 2023 ISOs? Have you tried any other ISOs via Ventoy that already have the new 2023 cert? If those work, maybe HBS can change something that helps Ventoy. If those don’t work as well, I hope that Ventoy will fix that soon Undecided

*Edit: There’s already a GitHub issue for this, might be related:
https://github.com/ventoy/Ventoy/issues/3639

Quote:The current version of shim is only signed with the 2011 UEFI certs so verification fails on machines with only 2023 certs.
Reply
#8
(06-18-2026, 09:31 AM)al3x Wrote: Looks like this might be a Ventoy problem unfortunately. If Ventoy with 2011 HBS ISO works then Ventoy probably replaces the 2011 cert during boot with its own cert that you inserted in BIOS previously.

Maybe Ventoy has problems with the injection of its own cert with 2023 ISOs? Have you tried any other ISOs via Ventoy that already have the new 2023 cert? If those work, maybe HBS can change something that helps Ventoy. If those don’t work as well, I hope that Ventoy will fix that soon Undecided

*Edit: There’s already a GitHub issue for this, might be related:
https://github.com/ventoy/Ventoy/issues/3639

Quote:The current version of shim is only signed with the 2011 UEFI certs so verification fails on machines with only 2023 certs.


The HBS 5.8.2.1 ISO (with 2023 certs) works OK for me on two separate Ventoy-boot SSDs on a Dell XPS13 (9310) with Secure Boot enabled and Win 11 with all updates.
Reply
#9
But was the 2011 cert already revoked for your XPS? Normally this will happen later this year unless you already force this manually.
Reply
#10
(06-18-2026, 10:43 AM)al3x Wrote: But was the 2011 cert already revoked for your XPS? Normally this will happen later this year unless you already force this manually.

When I check the SB status on my XPS, I get the green tick. That means the 2023 certs are in place, but not I guess, that the 2011 certs have necessarily been revoked. So .... ?
Reply


Forum Jump:


Users browsing this thread: 3 Guest(s)