my goal is to set up a full disc encryption with VeraCrypt, but I get an error and can't set up the secure boot bootloader. I hope that somebody can help me. Every little hint is welcome and helpful. Thank you for your support.
Hardware: Acer Extensa 2530-31EQ with UEFI, secure boot set as custom mode
System: Windows 10 Home, Version 1709
VeraCrypt 1.21
Windows Powershell as administrator
Setting KEK-signed MS UEFI cert in db...
Name Bytes Attributes
---- ----- ----------
db {224, 7, 8, 8...} NON VOLATILE...
db {224, 7, 8, 8...} NON VOLATILE...
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
Hello everybody,
my goal is to set up a full disc encryption with VeraCrypt, but I get an error and can't set up the secure boot bootloader. I hope that somebody can help me. Every little hint is welcome and helpful. Thank you for your support.
Hardware: Acer Extensa 2530-31EQ with UEFI, secure boot set as custom mode
System: Windows 10 Home, Version 1709
VeraCrypt 1.21
Windows Powershell as administrator
error:
PS C:\VeraCrypt-DCS-master\SecureBoot> powershell -ExecutionPolicy Bypass .\sb_set_siglists.ps
1
Set-SecureBootUEFI : Falsche Authentifizierungsdaten: 0xC0000022
In C:\VeraCrypt-DCS-master\SecureBoot\sb_set_siglists.ps1:4 Zeichen:1
+ Set-SecureBootUEFI -Name PK -Time 2015-09-11 -Content $null
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : PermissionDenied: (Microsoft.Secur...BootUefiCommand:SetSecure
BootUefiCommand) [Set-SecureBootUEFI], UnauthorizedAccessException
+ FullyQualifiedErrorId : SetFWVarFailed,Microsoft.SecureBoot.Commands.SetSecureBootUefi
Command
Set-SecureBootUEFI : Falsche Authentifizierungsdaten: 0xC0000022
In C:\VeraCrypt-DCS-master\SecureBoot\sb_set_siglists.ps1:5 Zeichen:1
+ Set-SecureBootUEFI -Name KEK -Time 2015-09-11 -Content $null
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : PermissionDenied: (Microsoft.Secur...BootUefiCommand:SetSecure
BootUefiCommand) [Set-SecureBootUEFI], UnauthorizedAccessException
+ FullyQualifiedErrorId : SetFWVarFailed,Microsoft.SecureBoot.Commands.SetSecureBootUefi
Command
Set-SecureBootUEFI : Falsche Authentifizierungsdaten: 0xC0000022
In C:\VeraCrypt-DCS-master\SecureBoot\sb_set_siglists.ps1:6 Zeichen:1
+ Set-SecureBootUEFI -Name db -Time 2015-09-11 -Content $null
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : PermissionDenied: (Microsoft.Secur...BootUefiCommand:SetSecure
BootUefiCommand) [Set-SecureBootUEFI], UnauthorizedAccessException
+ FullyQualifiedErrorId : SetFWVarFailed,Microsoft.SecureBoot.Commands.SetSecureBootUefi
Command
Set-SecureBootUEFI : Falsche Authentifizierungsdaten: 0xC0000022
In C:\VeraCrypt-DCS-master\SecureBoot\sb_set_siglists.ps1:7 Zeichen:1
+ Set-SecureBootUEFI -Name dbx -Time 2015-09-11 -Content $null
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : PermissionDenied: (Microsoft.Secur...BootUefiCommand:SetSecure
BootUefiCommand) [Set-SecureBootUEFI], UnauthorizedAccessException
+ FullyQualifiedErrorId : SetFWVarFailed,Microsoft.SecureBoot.Commands.SetSecureBootUefi
Command
Setting self-signed PK...
Set-SecureBootUEFI : Falsche Authentifizierungsdaten: 0xC0000022
In C:\VeraCrypt-DCS-master\SecureBoot\sb_set_siglists.ps1:10 Zeichen:1
+ Set-SecureBootUEFI -Time 2016-08-08T00:00:00Z -ContentFilePath siglis ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : PermissionDenied: (Microsoft.Secur...BootUefiCommand:SetSecure
BootUefiCommand) [Set-SecureBootUEFI], UnauthorizedAccessException
+ FullyQualifiedErrorId : SetFWVarFailed,Microsoft.SecureBoot.Commands.SetSecureBootUefi
Command
Setting PK-signed KEK...
Set-SecureBootUEFI : Falsche Authentifizierungsdaten: 0xC0000022
In C:\VeraCrypt-DCS-master\SecureBoot\sb_set_siglists.ps1:13 Zeichen:1
+ Set-SecureBootUEFI -Time 2016-08-08T00:00:00Z -ContentFilePath siglis ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : PermissionDenied: (Microsoft.Secur...BootUefiCommand:SetSecure
BootUefiCommand) [Set-SecureBootUEFI], UnauthorizedAccessException
+ FullyQualifiedErrorId : SetFWVarFailed,Microsoft.SecureBoot.Commands.SetSecureBootUefi
Command
Setting KEK-signed DCS cert in db...
Set-SecureBootUEFI : Falsche Authentifizierungsdaten: 0xC0000022
In C:\VeraCrypt-DCS-master\SecureBoot\sb_set_siglists.ps1:16 Zeichen:1
+ Set-SecureBootUEFI -Time 2016-08-08T00:00:00Z -ContentFilePath siglis ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : PermissionDenied: (Microsoft.Secur...BootUefiCommand:SetSecure
BootUefiCommand) [Set-SecureBootUEFI], UnauthorizedAccessException
+ FullyQualifiedErrorId : SetFWVarFailed,Microsoft.SecureBoot.Commands.SetSecureBootUefi
Command
Setting KEK-signed MS cert in db...
Setting KEK-signed MS UEFI cert in db...
Name Bytes Attributes
---- ----- ----------
db {224, 7, 8, 8...} NON VOLATILE...
db {224, 7, 8, 8...} NON VOLATILE...
Same problem here, on a Dell Inspiron 11-3168 (notebook), Windows 10 Home 1709 16299.248.