Questions tagged [secure-boot]
For questions on “Secure Boot” and “Restricted Boot” the new bios feature that is in computers with the “Windows 8” logo.
234
questions
0
votes
1
answer
1k
views
Is there anyway to ignore the CMOS Check during Startup? [closed]
I have broken my CMOS battery seat while replacing the battery, and I want to my pc to Ignore Cmos check during startup.
I have already turned on fast boot, but everytime I turn off the switch, fast ...
1
vote
0
answers
142
views
USB Windows 11 for TPM/SB created on non-TPM/SB system
What option is needed to install Windows 11 to a live persistent USB on a non-TPM/Secure Boot system, if the USB will be used on a TPM/Secure Boot system. I assume it is the Standard with TPM & ...
1
vote
1
answer
494
views
Machine owner key (MOK) details and predeployment options
Currently I am trying to get into the mechanisms behind Secure Boot, shim and machine owner keys.
What I observed is the fact, that the key, that I've imported via mokutil is permanent even if:
the ...
0
votes
0
answers
125
views
Is it possible to customize an Ubuntu or Debian live system while keeping the secure boot (microsoft keys) compatibility?
I would like to create a customized live system of either ubuntu or debian while keeping it compatible with the microsoft secure-boot keys, allowing computers to boot this live-system without fiddling ...
1
vote
1
answer
5k
views
Unable to access BIOS after enabling secure boot (no screen output)
I disabled CSM and enabled secure boot on my Gigabyte Aorus b550 AC with a EVGA GTX 1080.
Every time I boot up my machine, it boots straight into Windows (dual-boot system with ReFind as bootloader) ...
0
votes
0
answers
501
views
Cause for EFI Signature Change on PopOS Linux
I have a system with popos 21.10 installed. I had added the vmlinuz.efi signature to the secure boot list. Today I tried to boot the system after a week idle and it gave me an error saying the ...
0
votes
0
answers
146
views
I have an HP pavillion 1178 convertible and I was messing with secure boot and now my load HP factory default keys button is greyed out
What should I do?
I was trying to install mint and it said to disable secure boot, it was greyed out so I cleared the keys and then the load hp factory defaults keys option got grayed out.
_
2
votes
1
answer
2k
views
Secure Boot support on a custom-made PC with Windows 10 Pro
As part of my Windows 11 upgrade activities, MS says my PC does not support Secure Boot. Something also confirmed by msinfo32.exe:
msinfo32 snapshot
Strangely enough, when I entered BIOS it states ...
1
vote
1
answer
1k
views
Secure boot with unified kernel image on openSuSE?
I am trying to install OpenSuSE Tumbleweed on a system with encrypted root partition. At first i tried to set up GRUB, but it refused to recognize a LUKS-encrypted partition.
Currently I am trying to ...
0
votes
1
answer
4k
views
How do I sign kernel modules in Linux to successfully install NVIDIA drivers using dkms?
I use Kubuntu 18.04 and I'm trying to install NVIDIA driver using the run file provided by NVIDIA itself instead of using package managers.
I first Installed the following packages:
$ sudo nano /etc/...
1
vote
1
answer
3k
views
PC won't boot or display after activating Secure Boot
Specs:
CPU: AMD Ryzen 9 5900X,
Motherboard: Gigabyte Aorus X570 Elite Wifi,
RAM: 2x16GB DDR4 Trident G-Skill Neo,
GPU: Asus RTX 3080,
PSU: Gamemax 850W,
OS: Windows 11
So I've updated to Windows 11, ...
0
votes
2
answers
3k
views
[Solved]How can I enable secure boot on my laptop
I have an Asus ROG strix g513ih laptop but in BIOS menu I can't select secure boot. It's greyed out
5
votes
2
answers
6k
views
Secure boot - How to append custom certificate to db if BIOS has no such option?
I have HP 245G7 notebook. The BIOS is very basic and there does not seem to be any option from within to append my own custom certificate to db database of secure boot.
If there is an option in this ...
0
votes
1
answer
9k
views
Can disabling secure boot affect Windows?
Can disabling secure boot affect Windows OS? I want to disable it to install Linux. I use Windows 10 as my main OS now so all my data would be potentially lost if there is some problem with Windows ...
0
votes
0
answers
178
views
Will Windows 11 require secure boot is enabled, or just requires secure boot capable UEFI motherboard? [duplicate]
I am planning to fresh install Windows 11 to a ASUS Prime Z590 motherboard with 11th generation intel CPU
My question, will Windows 11 require secure boot is enabled, or just requires secure boot ...
2
votes
3
answers
6k
views
turning on secure boot gives only a black screen
I have installed Windows 10 with secure boot off and now I want to install Windows 11. So I turned secure boot back on but, only a black screen shows after computer boots.
What I see - I can see POST ...
0
votes
2
answers
1k
views
How can I get secure boot working after manually creating EFI partition with diskpart?
motherboard: ASUS ROG STRIX X570-E GAMING Rev X.0x
I successfully enabled secure boot and installed Windows 11. Because of issues I decided to go back to Windows 10 and experiment on another machine. ...
0
votes
1
answer
2k
views
Secure Boot is Unsupported while Bios Mode is set to UEFI on Lenovo T520 Laptop on System Information
My Lenovo T520 laptop bios is set to UEFI and currently running Windows 10. Under System Information I can see UEFI for Bios Mode but Secure Boot is shown as unsupported. Does UEFI enable mean secure ...
0
votes
2
answers
3k
views
No signal on monitor after secure boot
I want to install windows 11
So i open the bios and enable tpm (intel ppm) and then disable csm and enable secure boot after use default key
After restart i got blank screen no signal
And no bios
I ...
2
votes
3
answers
9k
views
PC won't boot when having the GPU connected after enabling Secure Boot
I wanted to upgrade to Windows 11 on my machine which worked perfectly up until now, so I checked the requirements and saw that I needed to enable Secure Boot in order to do so.
Since I have a ...
0
votes
0
answers
2k
views
Can't see HDD after enabling Secure Boot for Windows 11
Windows 11 is coming out, and according to the diagnostic tool I need to enable Secure Boot and TPM in order to upgrade. The TPM part was easy enough, however, the Secure Boot doesn't really work.
I ...
3
votes
2
answers
3k
views
Where is the data used in secure boot process stored?
I am spent a lot of time researching and reading about this topic but I am now very confused.
I have read that computer manufacturers include some Microsoft keys. For example, Microsoft Corporation ...
1
vote
1
answer
89
views
Do x64 machines differ in their secure boot implementations and ROM certificates?
I'm trying to understand secure boot and the key requirements in ROM firmware for x86 machines
I'm coming from this definition of secure boot:
The PCs are sold with certain certificates embedded in ...
0
votes
1
answer
108
views
Windows 8.1 to Windows 10 and back, playing with secure boot
On a Samsung NP900X3C, Windows 8.1 is installed. I would like to test Windows 10 on this machine and for that, I purchased a separate disk so that if it fails, I can just revert to the previous ...
0
votes
1
answer
343
views
Install Debian Linux on a Fujitsu Esprimo D7010
After installing Debian Linux on a Fujitsu Esprimo D7010, there is no corresponding boot entry visible. The new Debian installation cannot be booted. It appears the problem is related to secure boot.
...
1
vote
1
answer
415
views
Every time I eneble secure boot for windows 11 my pc doesnt boot and I have to reset bios settings by removing battary. Why is that?
So basically I want to update to windows 11 and I have to eneble 2 security settings TPM and secure boot I succesfully enebled Tpm but each time I try to do the same with secure boot my screen, ...
1
vote
1
answer
4k
views
When using Secure Boot can other drives still be MBR?
I recently read:
If Secure Boot is enabled in BIOS, then your System will need your hard drive to be GPT …
But what about the other drives? Can they still be MBR?
2
votes
0
answers
857
views
Windows 11 no sound in secure boot
I have Windows 11, but I have no sound in secure boot. WHen it's enabled, I went to Device Manager, and all the sound drivers said: "Windows cannot verify the digital signature for this device.&...
3
votes
2
answers
9k
views
How to install a windows guest in qemu/kvm with secure boot enabled
My host machine is archlinux and I am using virt-manager as a frontend of qemu.
I just have no idea about how to enabling secure boot for windows qemu guests. I have tried using the OVMF_CODE.secboot....
1
vote
1
answer
2k
views
Cannot boot to Windows with Secure Boot enabled
I have an Aorus x470 Gaming Ultra motherboard with a Ryzen 7 2700 CPU and an Evo 970 NVME with Windows 10.
Windows was installed as UEFI without problem about 2 years ago.
To get my PC ready for ...
0
votes
0
answers
679
views
Cannot access the BIOS while CSM is disabled
I've disabled CSM in the BIOS of the DS3H B450 motherboard, because it is required for secure boot (which in turn is required to update to Windows 11) but doing so has locked me out of the rest of the ...
2
votes
6
answers
38k
views
Computer doesn't POST after enabling Secure Boot
I wanted to enable Secure Boot to check if my PC Is compatible with Windows 11, and in order to do that, the UEFI firmware asked me to choose a Protocol/Publisher/Platform key (I don't remember ...
0
votes
2
answers
2k
views
Windows fails to boot after deploying a signed WDAC policy
I am trying to deploy a signed WDAC policy on a windows machine. On the first boot after deployment everything is fine but on the next boot I am sent to the UEFI firmware configuration screen
I have ...
0
votes
1
answer
2k
views
Will TPM and Secure boot complicate hardware upgrades and changes? [closed]
Along with the new requirements of Windows 11 to have TPM and Secure Boot https://www.microsoft.com/en-us/windows/windows-11-specifications, as well as the complications highlighted from this article ...
0
votes
1
answer
2k
views
Does dkms in Ubuntu 18.04 and later sign modules/drivers automatically?
According to DisplayLink website:
Since Ubuntu 18.04 signing modules is handled automatically by dkms
package, remember to reboot to finalize
However when secure boot was enabled in order for the ...
4
votes
1
answer
5k
views
How to disable Windows Defender Application Control once and for all?
(Please read before marking this as a duplicate, thanks.)
Description
I am developing my own Win32 x86_64 application which interferes heavily with the system, is able to communicate with drivers ...
2
votes
0
answers
710
views
How more secure is using Shim/PreLoader than having Secure Boot disabled?
I have my doubts on how secure is using Shim/PreLoader to allow booting Linux with Secure Boot enabled.
My doubt comes from the fact that it seems to me Shim's MokManager and PreLoader's HashTool can ...
0
votes
0
answers
486
views
Linux usb live cd not starting due to secure boot error
Greeting to you all, I'm having the following issue.
I've received a notebook (acer Aspire 3 A315-23) and
I'm trying to install a linux distribution on the system (namely a devuan beowulf).
I created ...
0
votes
1
answer
179
views
Unable to load signed modules on a signed custom kernel
I'm using Fedora 33. In order to boot a custom kernel, I had to generate an X.509 certificate to sign the kernel. This part works just fine.
I can also sign a custom kernel module with the same ...
1
vote
2
answers
6k
views
How to create an unattended Windows installation medium/iso/usb supporting Secure Boot and resulting in a UEFI-Windows installation?
Creating a medium from which a system can boot while Secure Boot
remains active, is possible with the default Windows iso from Media
Creator, but what about edited images?
Creating a unattended ...
0
votes
0
answers
371
views
Two Drives Dual Boot with Secure Boot
I'm going to build a PC with two SSD’s. I want to have Windows on one SSD and Ubuntu on the other. Why? This pc is going to be for educational and private use. I'm planning to use Ubuntu for school ...
1
vote
1
answer
363
views
BitLocker not accepting correct recovery keys
As a test before upgrading to Windows 10 20H2, I disabled Secure Boot and rebooted. I was shown a BitLocker Recovery screen and prompted for the recovery keys. I tried both keys I was given (there are ...
0
votes
2
answers
1k
views
Start BIOS settings on Samsung 700T //BUILD when secure boot violation is shown
I found the Samsung 700T slate that we got at the Microsoft Build conference. Unfortunately, upon switching it on, it shows the error message 'Secure Boot Violation'. I don't have the docking station ...
4
votes
4
answers
12k
views
Black BIOS screen after enabling Secure Boot?
I am not sure if I have understood the underlying concept clearly. I have MSI B450M Pro board and MSI GT710 GPU based graphics card. Windows 10 installed in UEFI Boot mode on an SSD.
I thought to ...
2
votes
0
answers
95
views
Can I use my own driver on Windows without having to ask MS for permission while keeping Secure Boot on?
As per the subject :
I want to write my own kernel mode driver
I want to be able to use it with Secure Boot on
I don't want to ask for permission to use it (no WHQL testing or attestation signing)
...
2
votes
1
answer
4k
views
What does "factory default" mean regarding UEFI keys stored in a TPM, in a PC built from scratch?
I built a PC from scratch a while ago, and after learning the recommended requirements for UEFI Secure Boot and Microsoft's Bitlocker, I installed an Infineon TPM in my motherboard. My understanding ...
0
votes
0
answers
44
views
Wiped hard disk completely removing all partitions - now computer won't start from Ubuntu live stick or Windows ISO
Today I wiped the hard disk of an Asus Windows computer from 2015. It has Secure Boot. I used an Ubuntu Live stick, opened the Disks app and removed all partitions, then used Shred to wipe the entire ...
1
vote
0
answers
42
views
Unable to easily switch os after dual booting
I got a new laptop ((Asus vivobook 14)https://www.flipkart.com/asus-vivobook-14-ryzen-5-hexa-core-4500u-8-gb-512-gb-ssd-windows-10-home-m413ia-ek582t-thin-light-laptop/p/itm8d1c44556be49?pid=...
0
votes
1
answer
51
views
Windows cannnot be installed after using Diskpart to convert to MBR
ok so long story short simply trying to reinstall Windows 10 on a disk in a dual boot setup (Linux is on a physically separate drive and launches without issue).
First issue was when using Rufus USB ...
1
vote
2
answers
789
views
When does Bitlocker unlock the drive?
I want to set up a Windows 10 Pro + Debian dual-boot configuration on my TPM-enabled laptop. The thing is that I want both Windows and Linux partitions to be fully encrypted by Bitlocker. I found a ...