Secure Boot Download Fails
-
Seeing this in on my XCP-ng host running 8.2.1:
No arguments provided to command install, default arguments will be used: - PK: default - KEK: default - db: default - dbx: latestDownloading https://www.microsoft.com/pkiops/certs/MicCorKEKCA2011_2011-06-24.crt...error: unable to retrieve certificate from URL: https://www.microsoft.com/pkiops/certs/MicCorKEKCA2011_2011-06-24.crt. Error message: HTTP Error 403: Forbidden.If the failure can't be fixed at the network configuration level, consider downloading the certificates manually and then loading one or more of them with secureboot-certs install <PK-filename>|default <KEK-filename>|default <db-filename>|default <dbx-filename>|latest. Check secureboot-certs install -h for usage details as well as a list of the download links used by secureboot-certs install.I can validate that the URL is correct and even download the cert from another machine.
I also can verify the XCP-ng host has internet access and can resolve DNS.
Any ideas as to what would cause this?
-
@planedrop Hi,
Look at my last answer here this should solve your issue.
https://xcp-ng.org/forum/topic/5789/windows-update-fails-on-windows-2019-servers-kb4535680/7?_=1652772403114 -
@Darkbeldin Thanks! I followed this response here, which is changing the same line: https://xcp-ng.org/forum/topic/5200/secureboot-certs-install-fails/6
Works fine now!
-
O olivierlambert marked this topic as a question on
-
O olivierlambert has marked this topic as solved on
-
Update candidate available to fix certificate download: https://xcp-ng.org/forum/post/49373
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login