Thread Rating:
  • 3 Vote(s) - 4.67 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Hasleo Backup Suite V5.8.2.2 Released!
Is it no longer possible to create an ISO or USB stick with the free version?

   

or is it because the Enterprise version is running here?
Reply
(Yesterday, 01:13 PM)Zombo Wrote:
(06-27-2026, 12:51 PM)admin Wrote: @all,

Now that UEFI firmware checks the Security Version Number (SVN) of boot files during startup, a practical issue arises: Windows security updates may raise the minimum allowed SVN recorded in the firmware, causing any Emergency Disk created before that update to become unbootable because its boot loader is too old. This means we can no longer guarantee that an Emergency Disk will always boot properly with Secure Boot enabled. In such cases, users must either recreate the Emergency Disk or temporarily disable Secure Boot to boot from the old one.

Best regards,

The SVN is only checked if the 2011 cert is revoked.

To make sure you are always using the latest boot files for making rescue media using 2023 is to copy the file from C:\Windows\Boot\EFI_EX as that will always have the latest update to secure boot after Windows Updates.

What I was doing before 5.8.2.2 was just copying the file to Hasleo then creating rescue media within the Hasleo GUI and even if 2011 was revoked this would boot without any SVN mismatch error.

copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi "C:\Program Files\Hasleo\Hasleo Backup Suite\bin\WADK\Boot\EFI_EX\bootmgfw.efi"

You're right. SVN is only checked when the 2011 certificate is revoked. For a Emergency USB Drive, replace X:\EFI\Boot\bootx64.efi (or bootaa64.efi for ARM64) with C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi, where X: is the drive letter of the USB drive.
Reply
(Yesterday, 03:28 PM)sugram Wrote: Is it no longer possible to create an ISO or USB stick with the free version?



or is it because the Enterprise version is running here?

The free version still supports creating emergency media. The issue is caused by the fact that you are using the Enterprise edition. Thanks.
Reply
(Yesterday, 04:59 PM)admin Wrote:
(Yesterday, 01:13 PM)Zombo Wrote: The SVN is only checked if the 2011 cert is revoked.

To make sure you are always using the latest boot files for making rescue media using 2023 is to copy the file from C:\Windows\Boot\EFI_EX as that will always have the latest update to secure boot after Windows Updates.

What I was doing before 5.8.2.2 was just copying the file to Hasleo then creating rescue media within the Hasleo GUI and even if 2011 was revoked this would boot without any SVN mismatch error.

copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi "C:\Program Files\Hasleo\Hasleo Backup Suite\bin\WADK\Boot\EFI_EX\bootmgfw.efi"

You're right. SVN is only checked when the 2011 certificate is revoked. For a Emergency USB Drive, replace X:\EFI\Boot\bootx64.efi (or bootaa64.efi for ARM64) with C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi, where X: is the drive letter of the USB drive.


If there have not been any updates to the program I use but Windows has updated the secure boot variables I just run this command to update the USB media.

In this example F: is the drive letter.

copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi F:\EFI\boot\bootx64.efi
Reply
(Today, 12:18 AM)Zombo Wrote:
(Yesterday, 04:59 PM)admin Wrote: You're right. SVN is only checked when the 2011 certificate is revoked. For a Emergency USB Drive, replace X:\EFI\Boot\bootx64.efi (or bootaa64.efi for ARM64) with C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi, where X: is the drive letter of the USB drive.


If there have not been any updates to the program I use but Windows has updated the secure boot variables I just run this command to update the USB media.

In this example F: is the drive letter.

copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi F:\EFI\boot\bootx64.efi

So can you make something like this work if you boot using the HBS.ISO from a Ventoy drive? Or if not just turn off Secure Boot?
Reply
(10 hours ago)Epictetus Wrote:
(Today, 12:18 AM)Zombo Wrote: If there have not been any updates to the program I use but Windows has updated the secure boot variables I just run this command to update the USB media.

In this example F: is the drive letter.

copy C:\Windows\Boot\EFI_EX\bootmgfw_EX.efi F:\EFI\boot\bootx64.efi

So can you make something like this work if you boot using the HBS.ISO from a Ventoy drive? Or if not just turn off Secure Boot?
This is uncharted territory as MS only updates the SVN when a vulnerability in the Boot Manager has been fixed. This has not been a common activity. It is possible that an update to Ventoy or HBS is all that may be required. Until these occur you may need to turn off Secure Boot. An alternate may be to use the above to update Ventoy.

We will know better when MS next updates the Boot Manager. It could be months or years.
Reply
(9 hours ago)Bespoken Wrote:
(10 hours ago)Epictetus Wrote: So can you make something like this work if you boot using the HBS.ISO from a Ventoy drive? Or if not just turn off Secure Boot?
This is uncharted territory as MS only updates the SVN when a vulnerability in the Boot Manager has been fixed. This has not been a common activity. It is possible that an update to Ventoy or HBS is all that may be required. Until these occur you may need to turn off Secure Boot. An alternate may be to use the above to update Ventoy.

We will know better when MS next updates the Boot Manager. It could be months or years.

If you load Hasleo ED directly through the UEFI firmware (not via Ventoy or other tools), then you need to update the boot files. Since modifying the files inside the ISO is rather complicated, I think it would be simpler to just recreate the ISO from scratch.

I am not very familiar with Ventoy. Technically speaking, if Ventoy's boot files can be loaded by the UEFI firmware, then Ventoy should be able to load the unmodified Hasleo ISO normally.
Reply


Forum Jump:


Users browsing this thread: 9 Guest(s)