WindowsUEFICA2023Capable=0 と Event ID 1797 が発生しているが、OEMは「Secure Bootが有効なので正常」と回答しています

西村 浩行 40 評価のポイント
2026-06-17T03:27:57.3733333+00:00

Secure Boot CA2023 の適用状況を確認しています。

以下の環境で Microsoft の公開手順に従い Secure Boot 更新を実施しました。

機種:

NEC VersaPro PC-VJV47GZGF

BIOS:

SMBIOSBIOSVersion /951A0503

ReleaseDate 2024/12/24

OS:

Windows 11 Pro

Build 26200

更新後の状態は以下です。

WindowsUEFICA2023Capable : 0

UEFICA2023Status : NotStarted

BootMgrLastUpdateErrorReason : PCA2023NotFoundInDB

イベントログ:

Event ID 1797

"Windows UEFI CA 2023 certificate is not present in DB"

また Event ID 1801 も記録されています。

一方、NECサポートからは、

「設定 > プライバシーとセキュリティ > Windows セキュリティ > デバイス セキュリティ」

において、

「セキュア ブート」

「セキュア ブートはオンです」

と表示されているため、CA2023更新は完了しているとの回答を受けています。

Microsoft の資料では、

WindowsUEFICA2023Capable

0 = Windows UEFI CA 2023 certificate is not in the DB

1 = Windows UEFI CA 2023 certificate is in the DB

2 = Windows UEFI CA 2023 certificate is in the DB and the system is starting from the 2023 signed boot manager

と記載されています。 :contentReference[oaicite:0]{index=0}

そこで質問です。

  1. WindowsUEFICA2023Capable = 0
  2. BootMgrLastUpdateErrorReason = PCA2023NotFoundInDB
  3. Event ID 1797

が同時に発生している場合、Microsoftの定義では CA2023 は未適用と判断してよいのでしょうか。

また、

「セキュア ブートはオンです」

という Windows セキュリティ画面の表示だけで、CA2023 の適用完了を判断することは可能でしょうか。

Microsoftとして推奨する確認方法をご教示ください。

ビジネス向け Windows | IT プロフェッショナル用 Windows クライアント | デバイスと展開 | システム管理コンポーネント

質問作成者が受け入れた回答
wanisan 8,200 評価のポイント ボランティア モデレーター
2026-06-17T04:48:54.1+00:00

セキュア ブート証明書は通常であればWindows Updateによって更新されますが、PCによってはBIOSの更新などが必要な場合もあるようです。
確認方法はいろいろありますが、分かりづらい場合もあります。
下のツールを使って確認してみたらどうでしょうか。
  セキュアブート証明書の有効期限を調べる方法

Event ID 1801が記録されていれば、下のサイトの方法で手動更新を行う方法もあります。
下の2つ目のサイトにあるように、時間をかけて進行していくようです。
それ以外のEvent IDについては下の3つ目のサイトを参考にしてください。
  TPM-WMI イベント ID: 1801 について
  エラー 1801が記録される原因と対処法
  セキュア ブート DB と DBX 変数の更新イベント

セキュア ブート証明書の問題は分かりづらいのですが、下のスレッドの回答(コメントを含めて)も参考にしてください。
なお、下の2つ目のサイトにあるように更新されない場合はセキュリティ上の問題が残りますが、すぐにPCが機能しなくなるなどの問題は起きないようなので、少し時間をかけて対応してもいいと思います。
  参考スレッド:ブートローダーの署名期限が更新されない
  セキュア ブート証明書の有効期限が切れた場合

この回答は役に立ちましたか?

1 人がこの回答が役に立ったと思いました。
0 件のコメント コメントはありません

質問作成者が受け入れた回答
VPHAN 44,940 評価のポイント 独立アドバイザー
2026-06-17T04:09:26.5866667+00:00

Hi 西村 浩行,

Your gathered telemetry is highly accurate and definitively proves the 2023 certificate is physically missing from your hardware. Microsoft's primary verification method relies on querying the registry at HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot, where the WindowsUEFICA2023Capable value returning a 0 acts as a direct read of the hardware's capabilities, confirming the new certificate is absent. Coupled with Event ID 1797, which explicitly logs the absence of this certificate, your operating system has deliberately paused the transition to prevent your device from becoming unbootable.

Because your logs unequivocally show the certificate is not in the database, the update is absolutely not applied according to Microsoft's definition. To permanently resolve this, you must wait for NEC to release a validated BIOS update for your VersaPro model that embeds the new Microsoft 2023 certificate directly into the motherboard's firmware.

Hope this answer has brought you some useful information. If it did, please hit “accept answer”. Should you have any questions, feel free to leave a comment.

VPHAN

この回答は役に立ちましたか?

1 人がこの回答が役に立ったと思いました。
0 件のコメント コメントはありません

0 件の追加の回答

並べ替え方法: 新しい順

お客様の回答

質問作成者は回答に "承認済み"、モデレーターは "推奨" とマークできます。これにより、ユーザーは作成者の問題が回答によって解決したことを把握できます。