# 小米电脑的安全启动是不是集体出问题了？

**URL:** https://meta.appinn.net/t/topic/86367
**Category:** 问题求助
**Tags:** windows, 小米, 安全
**Created:** [2026 年6 月 3 日 08:52 UTC](https://meta.appinn.net/t/topic/86367 "2026-06-03T08:52:27Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### 作者： ![PandaFiredoge](https://meta-edge.appinn.com/user_avatar/meta.appinn.net/pandafiredoge/32/58789_2.png) [@PandaFiredoge](https://meta.appinn.net/u/PandaFiredoge)
#### 发布日期： [2026 年6 月 3 日 08:52 UTC](https://meta.appinn.net/t/topic/86367/1 "2026-06-03T08:52:27Z")

</div>

开启安全启动后，无法引导，显示  
SecureBoot Failure  
Press Enter to continue next boot device.  
只有在BIOS里把安全启动关闭才能进系统

---

<div class="post-metadata">

### 作者： ![chenyiping1995](https://meta-edge.appinn.com/user_avatar/meta.appinn.net/chenyiping1995/32/58814_2.png) [@chenyiping1995](https://meta.appinn.net/u/chenyiping1995)
#### 发布日期： [2026 年6 月 3 日 09:12 UTC](https://meta.appinn.net/t/topic/86367/2 "2026-06-03T09:12:25Z")

</div>

是不是因为没更BIOS导致没有导入2023年的证书更新没有推送进去？

> **[Updating Microsoft Secure Boot keys | Windows IT Pro blog](https://techcommunity.microsoft.com/blog/windows-itpro-blog/updating-microsoft-secure-boot-keys/4055324)**
>
> A new Microsoft Windows UEFI CA 2023 will replace the existing Windows Production 2011 CA.

---

<div class="post-metadata">

### 作者： ![PandaFiredoge](https://meta-edge.appinn.com/user_avatar/meta.appinn.net/pandafiredoge/32/58789_2.png) [@PandaFiredoge](https://meta.appinn.net/u/PandaFiredoge)
#### 发布日期： [2026 年6 月 3 日 09:13 UTC](https://meta.appinn.net/t/topic/86367/3 "2026-06-03T09:13:52Z")

</div>

之前显示已经应用证书更新。

昨天系统出了点问题，我就下载ISO就地重装了一遍，重装之后推了个和当前版本一模一样的更新补丁（我是Insider Beta），更新完就这样了

---

<div class="post-metadata">

### 作者： ![PandaFiredoge](https://meta-edge.appinn.com/user_avatar/meta.appinn.net/pandafiredoge/32/58789_2.png) [@PandaFiredoge](https://meta.appinn.net/u/PandaFiredoge)
#### 发布日期： [2026 年6 月 3 日 10:20 UTC](https://meta.appinn.net/t/topic/86367/4 "2026-06-03T10:20:48Z")

</div>

网络搜索了一下，大概是5月20号开始爆发的

---

<div class="post-metadata">

### 作者： ![Qingwa](https://meta-edge.appinn.com/user_avatar/meta.appinn.net/qingwa/32/58632_2.png) [@Qingwa](https://meta.appinn.net/u/Qingwa)
#### 发布日期： [2026 年6 月 3 日 10:33 UTC](https://meta.appinn.net/t/topic/86367/5 "2026-06-03T10:33:29Z")

</div>

这个时间证书还没过期

---

<div class="post-metadata">

### 作者： ![PandaFiredoge](https://meta-edge.appinn.com/user_avatar/meta.appinn.net/pandafiredoge/32/58789_2.png) [@PandaFiredoge](https://meta.appinn.net/u/PandaFiredoge)
#### 发布日期： [2026 年6 月 3 日 10:35 UTC](https://meta.appinn.net/t/topic/86367/6 "2026-06-03T10:35:34Z")

</div>

然后现在用PowerShell命令检测，显示False，说明证书没有更新

但是证书应该没过期吧，6月底过期

而且小米完全没有为这台电脑发布过任何的BIOS更新，发布即弃子

网络搜索了一下，大概是5月20号开始出现小米电脑安全启动无法进系统的问题，但他们都是更新完BIOS出现的，而我这压根没有BIOS更新

手动更新证书办法没用，因为未开启安全启动的情况下，Windows拒绝进行证书更新，但是开启安全启动之后，又无法进系统

---

<div class="post-metadata">

### 作者： ![Qingwa](https://meta-edge.appinn.com/user_avatar/meta.appinn.net/qingwa/32/58632_2.png) [@Qingwa](https://meta.appinn.net/u/Qingwa)
#### 发布日期： [2026 年6 月 3 日 11:24 UTC](https://meta.appinn.net/t/topic/86367/7 "2026-06-03T11:24:15Z")

</div>

现在应该还没过期

---

<div class="post-metadata">

### 作者： ![fgd](https://meta-edge.appinn.com/letter_avatar_proxy/v4/letter/f/919ad9/32.png) [@fgd](https://meta.appinn.net/u/fgd)
#### 发布日期： [2026 年6 月 3 日 12:22 UTC](https://meta.appinn.net/t/topic/86367/8 "2026-06-03T12:22:49Z")

</div>

~~反正关了安全启动照样用,别折腾了~~

> <https://github.com/microsoft/secureboot_objects/blob/main/PostSignedObjects/Optional/DB/amd64/DBUpdate2024.bin>

linux下手动写进nvram,出错了进bios恢复出厂密钥

---

<div class="post-metadata">

### 作者： ![PandaFiredoge](https://meta-edge.appinn.com/user_avatar/meta.appinn.net/pandafiredoge/32/58789_2.png) [@PandaFiredoge](https://meta.appinn.net/u/PandaFiredoge)
#### 发布日期： [2026 年6 月 3 日 13:25 UTC](https://meta.appinn.net/t/topic/86367/9 "2026-06-03T13:25:48Z")

</div>

所以需要专门装个Linux吗？

---

<div class="post-metadata">

### 作者： ![fgd](https://meta-edge.appinn.com/letter_avatar_proxy/v4/letter/f/919ad9/32.png) [@fgd](https://meta.appinn.net/u/fgd)
#### 发布日期： [2026 年6 月 3 日 13:50 UTC](https://meta.appinn.net/t/topic/86367/10 "2026-06-03T13:50:45Z")

</div>

拿livecd就能用啊,

---

<div class="post-metadata">

### 作者： ![PandaFiredoge](https://meta-edge.appinn.com/user_avatar/meta.appinn.net/pandafiredoge/32/58789_2.png) [@PandaFiredoge](https://meta.appinn.net/u/PandaFiredoge)
#### 发布日期： [2026 年6 月 3 日 13:51 UTC](https://meta.appinn.net/t/topic/86367/11 "2026-06-03T13:51:18Z")

</div>

写完之后不会变砖吧

---

<div class="post-metadata">

### 作者： ![fgd](https://meta-edge.appinn.com/letter_avatar_proxy/v4/letter/f/919ad9/32.png) [@fgd](https://meta.appinn.net/u/fgd)
#### 发布日期： [2026 年6 月 3 日 14:09 UTC](https://meta.appinn.net/t/topic/86367/12 "2026-06-03T14:09:35Z")

</div>

不是说了可以重置吗你自己进bios看有没有恢复安全启动证书选项

---

<div class="post-metadata">

### 作者： ![rt23i950](https://meta-edge.appinn.com/user_avatar/meta.appinn.net/rt23i950/32/27981_2.png) [@rt23i950](https://meta.appinn.net/u/rt23i950)
#### 发布日期： [2026 年6 月 3 日 14:09 UTC](https://meta.appinn.net/t/topic/86367/13 "2026-06-03T14:09:50Z")

</div>

网上有个项目Check-UEFISecureBootVariables，自己更新一下nvarm区

---

<div class="post-metadata">

### 作者： ![PandaFiredoge](https://meta-edge.appinn.com/user_avatar/meta.appinn.net/pandafiredoge/32/58789_2.png) [@PandaFiredoge](https://meta.appinn.net/u/PandaFiredoge)
#### 发布日期： [2026 年6 月 3 日 14:14 UTC](https://meta.appinn.net/t/topic/86367/14 "2026-06-03T14:14:13Z")

</div>

我的意思是会不会连BIOS都进不去（“黑砖”）

---

<div class="post-metadata">

### 作者： ![fgd](https://meta-edge.appinn.com/letter_avatar_proxy/v4/letter/f/919ad9/32.png) [@fgd](https://meta.appinn.net/u/fgd)
#### 发布日期： [2026 年6 月 3 日 14:18 UTC](https://meta.appinn.net/t/topic/86367/15 "2026-06-03T14:18:38Z")

</div>

不会影响bios的，只影响安全启动信任名单

---

<div class="post-metadata">

### 作者： ![PandaFiredoge](https://meta-edge.appinn.com/user_avatar/meta.appinn.net/pandafiredoge/32/58789_2.png) [@PandaFiredoge](https://meta.appinn.net/u/PandaFiredoge)
#### 发布日期： [2026 年6 月 3 日 14:20 UTC](https://meta.appinn.net/t/topic/86367/16 "2026-06-03T14:20:26Z")

</div>

这个？

> **[GitHub - cjee21/Check-UEFISecureBootVariables: PowerShell scripts to check the UEFI KEK, DB and...](https://github.com/cjee21/Check-UEFISecureBootVariables)**
>
> PowerShell scripts to check the UEFI KEK, DB and DBX Secure Boot variables as well as scripts for other Secure Boot related items.

我试一下

---

<div class="post-metadata">

### 作者： ![PandaFiredoge](https://meta-edge.appinn.com/user_avatar/meta.appinn.net/pandafiredoge/32/58789_2.png) [@PandaFiredoge](https://meta.appinn.net/u/PandaFiredoge)
#### 发布日期： [2026 年6 月 3 日 15:12 UTC](https://meta.appinn.net/t/topic/86367/17 "2026-06-03T15:12:52Z")

</div>

非常感谢您的回答（以及原仓库、Issue的作者），完成了

> <https://github.com/cjee21/Check-UEFISecureBootVariables/issues/21>
>
> \> \[!NOTE\]
> \> If the certificate update method involving registry in this reposito…ry does not work, you can try the following method to manually install the certificate update files.
> \---
> \> \[!CAUTION\]
> \> This will bypass security check mechanisms related to set UEFI variables in Windows. Please fully understand the function of the relevant files before installation. You may need to reset the Secure Boot settings in the BIOS to continue booting the system.
> 
> This guide is primarily intended for the proper installation of OEM/Microsoft signed KEK/DB/DBX files, rather than using other workarounds to import them. This might avoid the risks caused by BitLocker.
> This can be used to install the 2023 KEK certificate and other DB certificates. DBX databases are also supported.
> \## 1. Preparation
> On Windows, use the \`Show UEFI PK, KEK, DB and DBX.cmd\` script from this repository.
> Run it to query your PK information.
> \*(Linux users please refer to step 5).\*
> Record the unique PK \*\*thumbprint\*\*. You will use this to check if your OEM has uploaded a signed version of the KEK to the Microsoft repository.
> \## 2. Downloading the KEKUpdate (2023 Certificate)
> Now prepare to install the KEK signed with the 2023 certificate. Visit:
> https://github.com/microsoft/secureboot\_objects/blob/main/PostSignedObjects/KEK/kek\_update\_map.json
> Search for your PK thumbprint.
> \*\*If found:\*\* Download the correct \`.bin\` file based on the brand and filename.
> \*\*If not found:\*\* You cannot install the KEK from the running system under the current PK.
> \*(Skip steps 1 and 2 if you are not installing the KEK).\*
> \## 3. Downloading and Preparing KEK/DB/DBX update files
> Download the required KEK/DB/DBX files from:
> https://github.com/microsoft/secureboot\_objects/tree/main/PostSignedObjects
> \*(Note: DB and DBX update files are currently still signed with the 2011 KEK certificate. You can also find them in the Windows system path \`%SystemRoot%\\System32\\SecureBootUpdates\`).\*
> Obtain the \`SplitDbxContent.ps1\` script to split the \`.bin\` files for use on Windows:
> https://www.powershellgallery.com/packages/SplitDbxContent/1.0
> Execute the following in PowerShell to split the signed package. Replace \`KEKUpdate\_OEMXXX\_PKXXX.bin\` with your actual filename.
> \`\`\`powershell
> SplitDbxContent.ps1 KEKUpdate\_OEMXXX\_PKXXX.bin
> \`\`\`
> This will output \`content.bin\` and \`signature.p7\` files. All KEK, DB, DBX \`XXXUpdate.bin\` files in PostSignedObjects need to be split this way. It is recommended to create a new folder to store them to avoid confusion.
> \*(Linux users can skip the split step).\*
> \## 4. Apply the Update
> \### Windows Users
> Open PowerShell as Administrator and run the following command to install the KEK:
> \`\`\`powershell
> Set-SecureBootUefi -AppendWrite -Name KEK -ContentFilePath content.bin -SignedFilePath signature.p7 -Time 2010-03-06T19:17:21Z
> \`\`\`
> Please replace the file path as needed.
> \* \*\*Note:\*\* The \`-Time\` parameter is fixed and cannot be changed.
> \* \*\*Note:\*\* For DB and DBX, replace the value of the \`-Name\` parameter with the corresponding variable (\`DB\` or \`DBX\`).
> 
> If successful, a table displaying \*\*Name, Bytes, Attributes\*\* will be returned.
> If an error occurs during the entire certificate verification process, the error code will be \`0xC0000022\`, and no changes will be made to the UEFI variables.
> \### Linux Users
> Use \`fwupdtool\` or \`efi-updatevar\` to directly install the \`.bin\` files downloaded from the Microsoft repository. \*\*No splitting is required.\*\*
> They come from the \`fwupd\` and \`efitools\` packages.
> \`\`\`shell
> \# Requires root permissions
> fwupdtool install-blob XXXUpdate.bin
> \# or
> efi-updatevar -f XXXUpdate.bin KEK
> \# (Replace KEK with DB or DBX as needed)
> \`\`\`
> \## 5. Verification
> \*\*Windows Users\*\*
> Use \`Show UEFI PK, KEK, DB and DBX.cmd\` or \`Check UEFI KEK, DB and DBX.cmd\` to check if your certificates were installed successfully. You can view the results without rebooting.
> \*\*Linux Users\*\*
> Use the following commands to view the certificate details for each variable:
> \`\`\`shell
> \# Requires root permissions
> efi-readvar -v KEK # from efitools
> \# (Replace KEK with PK, DB, or DBX as needed)
> \`\`\`
> \## Note
> This guide likely does not apply to any ARM system users, regardless of whether using Windows or Linux.
> The above steps were only tested on my computer and may not apply to all devices.
> \*\*The Linux instructions provided in this guide have not been tested by the author.\*\* They are from the wiki mentioned below.
> Part of the content comes from https://github.com/microsoft/secureboot\_objects/wiki

---

<div class="post-metadata">

### 作者： ![6949](https://meta-edge.appinn.com/letter_avatar_proxy/v4/letter/6/e68b1a/32.png) [@6949](https://meta.appinn.net/u/6949)
#### 发布日期： [2026 年6 月 4 日 00:23 UTC](https://meta.appinn.net/t/topic/86367/18 "2026-06-04T00:23:27Z")

</div>

所以这个到底是谁的问题呀，小米还是系统问题呀

---

<div class="post-metadata">

### 作者： ![hooke007](https://meta-edge.appinn.com/user_avatar/meta.appinn.net/hooke007/32/33051_2.png) [@hooke007](https://meta.appinn.net/u/hooke007)
#### 发布日期： [2026 年6 月 4 日 02:39 UTC](https://meta.appinn.net/t/topic/86367/19 "2026-06-04T02:39:30Z")

</div>

[**关于小米笔记本 Windows 安全启动证书更新的公告说明**](https://www.mi.com/article/detail/0fb9eb94b124.html)

看来主楼说的是这个问题

---

<div class="post-metadata">

### 作者： ![herper](https://meta-edge.appinn.com/letter_avatar_proxy/v4/letter/h/53a042/32.png) [@herper](https://meta.appinn.net/u/herper)
#### 发布日期： [2026 年6 月 7 日 23:39 UTC](https://meta.appinn.net/t/topic/86367/20 "2026-06-07T23:39:14Z")

</div>

小米的工程师回复我的，旧版本机器无法提供KEK，他们不再提供技术支持，也就是说没有BIOS或其他方案更新证书，所以旧版本小米笔记本没有安全启动证书更新！所以笔记本，还是大厂吧！

[下一页](https://meta.appinn.net/t/topic/86367.md?page=2)
