Secure Boot Download Fails
-
Seeing this in on my XCP-ng host running 8.2.1:
No arguments provided to command install, default arguments will be used: - PK: default - KEK: default - db: default - dbx: latestDownloading https://www.microsoft.com/pkiops/certs/MicCorKEKCA2011_2011-06-24.crt...error: unable to retrieve certificate from URL: https://www.microsoft.com/pkiops/certs/MicCorKEKCA2011_2011-06-24.crt. Error message: HTTP Error 403: Forbidden.If the failure can't be fixed at the network configuration level, consider downloading the certificates manually and then loading one or more of them with secureboot-certs install <PK-filename>|default <KEK-filename>|default <db-filename>|default <dbx-filename>|latest. Check secureboot-certs install -h for usage details as well as a list of the download links used by secureboot-certs install.
I can validate that the URL is correct and even download the cert from another machine.
I also can verify the XCP-ng host has internet access and can resolve DNS.
Any ideas as to what would cause this?
-
@planedrop Hi,
Look at my last answer here this should solve your issue.
https://xcp-ng.org/forum/topic/5789/windows-update-fails-on-windows-2019-servers-kb4535680/7?_=1652772403114 -
@Darkbeldin Thanks! I followed this response here, which is changing the same line: https://xcp-ng.org/forum/topic/5200/secureboot-certs-install-fails/6
Works fine now!
-
-
-
Update candidate available to fix certificate download: https://xcp-ng.org/forum/post/49373