Secure Boot Violation: Invalid signature detected
The UEFI firmware blocks the operating system bootloader because its digital signature has expired, been revoked in the Secure Boot DBX database, or belongs to an unauthenticated secondary OS.
Internal desktop parts run on harmless 12V DC voltage and cannot shock you. Simply unplug the wall power cable first, then touch the unpainted metal case frame to ground static electricity.
Common Symptoms & Tells
- Red or blue banner reading 'Secure Boot Violation: Invalid signature detected'
- PC boots straight into setup instead of Windows
- Occurs after installing a Windows update or swapping graphics cards
Interactive Fix Checklist
0 of 4 steps completedEnter UEFI BIOS and inspect Secure Boot state
Restart and tap Del or F2. Navigate to the Security or Boot tab, open Secure Boot Configuration, and confirm whether OS Type is set to 'Windows UEFI mode' rather than 'Other OS'.
Restore factory Secure Boot keys
Select 'Key Management' in the Secure Boot menu and click 'Restore Factory Default Keys' or 'Install Default Secure Boot Keys'. This refreshes the PK, KEK, and DB databases.
Temporarily switch Secure Boot to Disabled
If boot continues to fail, change Secure Boot from Enabled to Disabled. Save and restart to verify Windows boots normally. Once in Windows, run Windows Update to download the latest signed bootloader.
Update motherboard BIOS firmware
Download the latest from your motherboard manufacturer website onto a FAT32 USB flash drive. Flash the update to receive updated Microsoft revocation lists and re-enable Secure Boot. CRITICAL SAFETY: Never turn off, reset, or unplug the PC while the update is flashing. A power interruption during EEPROM write will corrupt the firmware and brick the motherboard.
Still having trouble with your PC?
Describe what is happening to your AI Technician. We will tailor the fix to your exact hardware setup.