I was curious whether MS Windows 10 could see the key rings on this
computer and apparently it can.  I found the following instructions:

https://www.dell.com/support/kbdoc/en-us/000385747/how-to-check-secure-boot-certificates

I installed the mentioned powershell modules and the commands did return
key summaries:

PS C:\Windows\system32> (Get-UEFISecureBootCerts db).signature
14E62A4905E19189E70828983165939AFC0A331D0B415F3332B0E818A827F436

Thumbprint                                Subject
----------                                -------
46DEF63B5CE61CF8BA0DE2E6639C1019D0ED14F3  CN=Microsoft Corporation UEFI CA 
2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
580A6F4CC4E4B669B9EBDC1B2B3E087B80D0678D  CN=Microsoft Windows Production PCA 
2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
7B9E6CC3C22E2AF24F5BEB27D5DFF73D5D74E166  CN=ThinkPad Product CA 2012, O=Lenovo 
Ltd., L=Yokohama, S=Kanagawa, C=JP
CB0259714826C867D1422C310B88150160398F0B  CN=Lenovo UEFI CA 2014, O=Lenovo, 
S=North Carolina, C=US


PS C:\Windows\system32> (Get-UEFISecureBootCerts dbdefault).signature
14E62A4905E19189E70828983165939AFC0A331D0B415F3332B0E818A827F436

Thumbprint                                Subject
----------                                -------
46DEF63B5CE61CF8BA0DE2E6639C1019D0ED14F3  CN=Microsoft Corporation UEFI CA 
2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
580A6F4CC4E4B669B9EBDC1B2B3E087B80D0678D  CN=Microsoft Windows Production PCA 
2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
7B9E6CC3C22E2AF24F5BEB27D5DFF73D5D74E166  CN=ThinkPad Product CA 2012, O=Lenovo 
Ltd., L=Yokohama, S=Kanagawa, C=JP
CB0259714826C867D1422C310B88150160398F0B  CN=Lenovo UEFI CA 2014, O=Lenovo, 
S=North Carolina, C=US


PS C:\Windows\system32> (Get-UEFISecureBootCerts kek).signature

Thumbprint                                Subject
----------                                -------
A2CC64C8E1FD4B0DCE720B125B8A1F29B2A90567  CN=Lenovo Ltd. KEK CA 2012, O=Lenovo 
Ltd., L=Yokohama, S=Kanagawa, C=JP
31590BFD89C9D74ED087DFAC66334B3931254B30  CN=Microsoft Corporation KEK CA 2011, 
O=Microsoft Corporation, L=Redmond, S=Washington, C=US


PS C:\Windows\system32> (Get-UEFISecureBootCerts pk).signature

Thumbprint                                Subject
----------                                -------
49C6331A4B581010FC63F80617C012F5E04F39FA  CN=Lenovo Ltd. PK CA 2012, O=Lenovo 
Ltd., L=Yokohama, S=Kanagawa, C=JP


PS C:\Windows\system32>


Despite Windows Updater insistence that everything is up to date, no
current keys are installed.

- Nate

-- 
"The optimist proclaims that we live in the best of all
possible worlds.  The pessimist fears this is true."
Web: https://www.n0nb.us
Projects: https://github.com/N0NB
GPG fingerprint: 82D6 4F6B 0E67 CD41 F689 BBA6 FB2C 5130 D55A 8819

Attachment: signature.asc
Description: PGP signature

Reply via email to