secure boot failed,

Dimutha Jayasinghe 0 Reputation points
2026-09-22T19:19:40.3766667+00:00

Because of the windows security shows secure boot error showing hardware limitations, longer all the updates, so I went to bios and reinstall the keys, by factory resetting, but after I save and exit, PC went restarting, but boot is failed, showing secure boot failed, so I disabled the secure boot, Can't I enable it again, so I can get updates (ACER A315 57G)

Windows for home | Windows 11 | Security and privacy
0 comments No comments

2 answers

Sort by: Most helpful
  1. Hendrix-V 19,120 Reputation points Microsoft External Staff Moderator
    2026-09-23T05:56:19.4+00:00

    Hi Dimutha Jayasinghe,

    Since Windows is currently able to start when Secure Boot is disabled, the issue may be related to how the firmware is handling the Secure Boot key database after the key reset. Based on your Acer model, it may be worth checking whether a newer BIOS version is available from Acer before making further Secure Boot changes. Updating the BIOS can help ensure compatibility with the latest Secure Boot certificates.

    You can try the following checks:

    1. Visit Acer Support and check for the latest BIOS/UEFI update for your exact Acer Aspire A315-57G model.
    2. Install the BIOS update while Secure Boot remains disabled.
    3. Restart and enter BIOS setup.
    4. Look for an option such as Install Default Secure Boot Keys, Restore Secure Boot Keys, or Key Management.
    5. Save the changes and then try enabling Secure Boot again.

    If Secure Boot still fails after the BIOS update, I recommend contacting Acer Support for model-specific firmware guidance, as Secure Boot key management can vary between manufacturers and BIOS versions.

    I hope this helps point you in the right direction.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-09-22T19:20:02.3333333+00:00

    Yes, it can often be recovered, but resetting Secure Boot keys to firmware defaults can remove the certificates needed to trust the installed Windows boot manager. That matches the symptom where the PC boots only when Secure Boot is disabled.

    Try this in order:

    1. Recover the missing Secure Boot certificate
      • On a second Windows PC that has the July 2024 or newer Windows update installed, copy SecureBootRecovery.efi from C:\Windows\Boot\EFI\.
      • Format a USB drive as FAT32.
      • Create this folder path on the USB drive: \EFI\BOOT\
      • Copy SecureBootRecovery.efi into that folder and rename it to bootx64.efi.
      • Boot the affected PC from that USB drive and let the recovery utility run.
      • This restores the Windows UEFI CA 2023 certificate to the Secure Boot DB.
      • After restart, Windows should boot normally.
    2. Update firmware from the PC manufacturer
      • After recovery, install the latest available BIOS/UEFI firmware from the device manufacturer.
      • This is important because some firmware incorrectly overwrites or clears the Secure Boot database.
    3. Re-enable Secure Boot
      • Enter BIOS/UEFI.
      • Find Secure Boot under the Security, Boot, or Authentication tab.
      • Set it to Enabled.
      • On some PCs, select Custom and load the built-in Secure Boot keys.
      • Save changes and restart.
    4. If Secure Boot still will not enable
      • Reset BIOS/UEFI settings back to factory defaults, then try enabling Secure Boot again.
      • If Windows Security shows that Secure Boot is blocked by hardware or firmware limitations, or updates are paused for the device, the next step is to check the OEM’s Secure Boot support page or contact the device manufacturer.
    5. If the PC becomes unbootable again after enabling Secure Boot
      • Disable Secure Boot so Windows can start.
      • Then use the recovery utility again and make sure firmware is updated before trying to enable Secure Boot another time.

    Important:

    • Do not reset Secure Boot to firmware defaults again unless the OEM firmware already includes updated Secure Boot defaults that trust the 2023 certificates.
    • If Windows Security shows a yellow badge, that indicates an actionable hardware or firmware issue and manufacturer assistance is required.
    • If it shows a red badge, follow the guidance shown in Windows Security.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.