Skip to main content

Questions tagged [secure-boot]

For questions on “Secure Boot” and “Restricted Boot” the new bios feature that is in computers with the “Windows 8” logo.

0 votes
1 answer
77 views

Bypassing Secure Boot without disabling it

I've tried archboot, but no luck as I was stuck due to the plymouth missing. Now I want to try to install arch or nixos alongside Win 11. The problem lies in secure boot. I don't have spare linux to ...
Futman's user avatar
  • 21
0 votes
1 answer
61 views

BIOS asks password every time but secure boot is disabled

I had to set a temporary password for both SSDs using secure boot but now, I can't disable it. I tried to restore and revert everything, but it doesn't go away. Here, Admin y User Password only ...
Dani's user avatar
  • 103
-1 votes
0 answers
145 views

Secure Boot Option greyed out in Asus BIOS

I have an ASUS TUF F15 Laptop. Model : FX506LH BIOS VERSION : 310 OS : Windows 10 Home Single Language Secure Boot is ENABLED in the BIOS settings and greyed out and there is no way to disable it. ...
Aditya Sharma's user avatar
1 vote
0 answers
99 views

How can I use unified kernel images with Ubuntu and Debian?

I would like to use unified kernel images (UKIs) and systemd-boot to take advantage of some of the hardware security features it provides (such as measured boot and real secure boot). I think that the ...
rafiki's user avatar
  • 49
0 votes
1 answer
2k views

windows 11 error The Secure Boot update failed

for some reason this error is constantly thrown and logged in the Windows Event Viewer: The Secure Boot update failed to update a Secure Boot variable with error Secure Boot is not enabled on this ...
Semen Shekhovtsov's user avatar
0 votes
1 answer
836 views

How to fix error: "FAIL: Unable to load driver '\efi\rufus\exfat_x64.efi': [26] Security Violation"

I'm trying to reinstall Windows 10 but the short DST test fails and also it states Unable to load driver '\efi\rufus\exfat_x64.efi': [26] Security Violation. My laptop is a HP EliteBook 840 G3 1TB ...
Jer Jonas's user avatar
-2 votes
1 answer
134 views

Why is Windows not booting (boot loop) after accepting a BitLocker PIN after having completed BIOS CMS work?

Occasionally one might need to boot into an application that requires CMS mode in BIOS to be enabled (like SpinRite.) Since most Windows modern installation are UEFI with Secure Boot, this requires ...
A71's user avatar
  • 552
0 votes
0 answers
41 views

How to alternate automatically at boot between my laptop's two installed OSes?

I have Windows 10 and Ubuntu Linux 20.04 installed into separate encrypted partitions on my Dell Latitude 5411 laptop. When I shut down one OS, it's always to boot into the other one. Linux is the ...
patraulea's user avatar
  • 411
1 vote
1 answer
137 views

Why does the kernel reject my self signed module on a secure boot system?

I have a secure boot enabled linux on an Intel NUC. It uses a special distribution (Balena IoT) that doesn't use shim and has only this distribution's keys enrolled (no Microsoft keys). For a test, I ...
Markus Grunwald's user avatar
0 votes
1 answer
1k views

Installing VirtualBox on Debian 12 Bookworm With Errors

I have a Clevo PD70SND-G, fresh from China. Installed Debian 12 Bookworm. I am attempting to install, and use, VirtualBox. I have data on a VirtualBox machine that I need access to. I have attempted ...
Joshua E. Vines's user avatar
0 votes
1 answer
339 views

Delete PK key from terminal when secure boot is disabled

When secure boot is disabled, is it possible to delete the PK key from terminal? I know that to change the keys, you need to enter setup mode. And to enter setup mode, you need to delete the PK key. ...
astroboy's user avatar
  • 101
0 votes
0 answers
277 views

How to get minimal vendor information about the TPM chip installed in my laptop

How do I get some minimal information about the TPM chip in my Linux laptop? Information such as the manufacturer, manufacturer id, manufacturer version. So far I have tried the tpm2_getcap command to ...
a001's user avatar
  • 1
0 votes
1 answer
241 views

Buildroot and secure boot on x86 - can it be done? [closed]

I'm trying to figure out if buildroot can generate a Secure Boot capable system. Secure boot requires a properly signed kernel. The target hardware is an x86-64/AMD64 processor with TPM 2.0 support. ...
Craig S. Anderson's user avatar
-2 votes
2 answers
784 views

Secure Boot switch-off, PK deletion consequences [closed]

I have to disable Secure Boot. To do this, I have to delete the PK keys. Will this affect the loading of my operating system? I am using a "one-time" SSD that is currently connected. But I ...
euclidy's user avatar
  • 21
0 votes
0 answers
14 views

How does the SPK ID provide security in Xilinx secure boot

My understanding of the Xilinx ultra scale secure boot process is that the CSU validates the SPK with the PPK. If the SPK is authenticated, the CSU checks to see if the SPK ID that’s associated with ...
Spencer Work's user avatar
0 votes
1 answer
315 views

Supplemental WDAC policy Doesn't Override Block Rule from Base WDAC Policy (Microsoft Recommended Block Rules)

I'm working on creating a Windows Defender Application Control (WDAC) supplemental policy which supplements a base policy. The base policy is merged with the Microsoft Recommended Block Rules. This ...
TheCyberWarden's user avatar
1 vote
0 answers
174 views

Why the TPM PCRs does not consider a UEFI settings change? If someone resets CMOS, it's undetected

In my laptop I've set up a bios pw when I power on the laptop, and once I enter it the laptop starts my linux distro and decrypts the disk without asking any other password. To do this I've set up TPM ...
Allexj's user avatar
  • 254
2 votes
1 answer
1k views

LUKS encryption using passphrase + TPM

I have questions about secure boot and TPMs and I couldn’t find precise answers on the web, so I’m hoping someone skilled in this domain will be able to answer. In a case of an evil maid attack, what ...
gfaure's user avatar
  • 31
0 votes
0 answers
283 views

Does the Microsoft update for BlackLotus mitigation SKUSiPolicy.p7b require Memory Integrity to be on and working in the Security Center?

In other words is the "Code Integrity feature" on this Microsoft kb5025885 page: The Code Integrity Boot Policy (SKUSiPolicy.p7b) uses the Code Integrity feature of Windows to prevent ...
Eric's user avatar
  • 87
1 vote
1 answer
970 views

Odd message during boot using GRUB

I use Secure Boot, followed by GRUB2, set up to boot Debian 12 and Windows 11 at the choice of a user. Right after the user chooses Windows and hits ⏎, we see a black screen with two white lines on it ...
user avatar
0 votes
0 answers
1k views

Gigabyte b650 DS3H secure boot won't boot from USB

Gigabyte b650 DS3H secure boot won't boot from USB. I'm trying to run clean install for win 11 from USB drive system running on gigabyte b650 DS3H. I've made sure that TMP 2.0 is enabled and CSM is ...
pinegulf's user avatar
  • 101
-2 votes
1 answer
1k views

Why does my computer say "Soft Temporary Disable" at boot after disabling Secure Boot?

I have a HP PC bought less than four years ago. I had several annoying issues with Linux due to this "Secure Boot" junk, so I disabled it in the BIOS/UEFI settings. Then I was able to ...
Stan's user avatar
  • 105
0 votes
0 answers
575 views

Cannot enable Secure boot on Gigabyte H61M-DS2

Trying to help a friend do a fresh install of Windows, but the bootable USB isn't even listed in the BIOS. I realized that Secure Boot is currently disabled, and assume this is the issue. However ...
Ryan's user avatar
  • 1
0 votes
0 answers
640 views

Cannot change my secure boot configuration in BIOS

Device: ASUS Vivobook pro 15 OS: Windows 11 Pro 22H2 As in the image above, the configuration for secure boot has been disabled in my BIOS configuration. How can I change my secure boot configuration?...
임영찬's user avatar
0 votes
0 answers
328 views

Run older kernel on Ubuntu with secure boot

On Ubuntu 20.04, I am trying to run some piece of proprietary software junk that works only with kernel 5.8 instead of the current kernel 5.15. So, I installed the kernel 5.8 using a mainline script ...
phlegmax's user avatar
  • 101
1 vote
1 answer
833 views

Making a MOK-signed GRUB with extra modules

I have a Wake-on-LAN situation where I'd like GRUB to make a network request to decide "should I boot Windows?", perhaps by load_env (http,192.168.1.123)/grubenv (so I can write that file ...
Chris Boyle's user avatar
0 votes
2 answers
507 views

Windows 11 installed on a refurbished HP so that I can't suppress Secure boot mode to boot on USB

I recently bought a refurbished HP Z4 G4 with windows 11 already installed. In order to dual boot, I have to change the bios/UEFI Secure Boot to disable (and legacy to enable). I am able to change it ...
revher's user avatar
  • 181
0 votes
2 answers
2k views

Bypassing TPM/SecureBoot checks when installing Win11 without Rufus

I need to install Windows 11 on an older PC that doesn't support TPM and SecureBoot. According to this article, it's possible by creating DWORDs with the names BypassTPMCheck and BypassSecureBoot (...
Shtole's user avatar
  • 3
0 votes
2 answers
8k views

Secure Boot Violation: Invalid Signature Detected, Check Secure Boot Policy in Setup Error - HackBGRT (how to use secure boot with it)

Update - Go to answer for steps. First off, I am trying to enable secure Boot thus I don't consider disabling secure Boot a solution. I have a Gigabyte B450M DS3H, with AMD Ryzen 5600 and have tried ...
dutspro's user avatar
  • 19
0 votes
1 answer
553 views

Why can Debian 11 no longer load after Windows 10 changed motherboard state?

Note that this question is not a duplicate of the typical dual-boot questions, because I never have the Windows-HDD and Linux-SSD at once in the PC, so they cannot touch each other's (efi) partitions. ...
flugosfutam123's user avatar
2 votes
1 answer
276 views

Build date of bios version - how to check orginality of version ? - used motherboard

I have a used motherboard. Can I make sure that the bios is authentic including the keys (secure bios) ? How can I check it? For example, the build date of the bios is a few days older than the ...
Santa Monica's user avatar
1 vote
1 answer
1k views

Is disabling secureboot that bad?

I want to sometimes use Linux, sometimes windows. I found out that, Puppy Linux is small, I can install it on a USB. But the problem is, if I click on my USB in the boot menu, I have to disable secure ...
slavekrouta's user avatar
0 votes
1 answer
307 views

ASUS X570-PLUS (WIFI) and Samsung 850 EVO SSD, forced to use CSM and Secure Boot not working

New build with an ASUS X570-PLUS and an older Samsung 850 EVO SSD. The drive is not detected by the motherboard unless I enable CSM. Safe Boot is enabled in BIOS but Windows is showing it as disabled. ...
Benjamin M's user avatar
0 votes
0 answers
492 views

PC not booting after enabling secureboot in Linux

I tried to Multiboot my Laptop with secureboot enabled, I installed fedora on one SSD and had Windows 11 on the other one. Then I generated a new key for the UEFI. I enabled secureboot in the UEFI ...
Cron3x's user avatar
  • 1
1 vote
1 answer
753 views

Boot stuck on Dell logo after changing GPU, Secure Boot enabled

I have recently bought and installed an AMD RX Radeon 6600, and now my computer gets stuck at the Dell logo and I cannot get to the BIOS or anything else. After investigating, I found that if I ...
Coffee'd Up Hacker's user avatar
2 votes
0 answers
331 views

How does PCIe card vendors sign option ROMs?

If secure boot is enabled UEFI system would permit to run only signed Option ROMs. I presume PCIe card vendors want their devices to work even if Secure Boot is enabled. Therefore how does PCIe card ...
kostr22's user avatar
  • 163
0 votes
4 answers
3k views

Getting a “Secure Boot Violation” on an MSI Modern 14 after a Windows 11 update failed

Upgraded Windows 10 to Windows 11 on MSI Modern 14 earlier this year via Update assistant. I saw the latest Windows 11 22H2 update and put the MSI modern 14 to upgrade via Windows 11 Installation ...
AndroFan's user avatar
0 votes
1 answer
169 views

Is it possible to "go back" to grub after booting linux

I am trying to enable secureboot so I can forget about it when switching between windows and linux through dualboot. However, grubs newer versions don't allow mods to be inserted after boot, so I need ...
Jark's user avatar
  • 1
0 votes
0 answers
42 views

Bootloop behavior for Win10 installation or Win10 install media

I have a Win10 system I've been using without any issues for ~2.5 years. The mobo is ASUS ROG Crosshair VIII Hero Wifi. The CPU is Ryzen 3950x. Last week I had a weird occurrence where the system ...
The111's user avatar
  • 673
1 vote
2 answers
5k views

Can't enable secure boot in Windows 11

I am using Windows 11 and can't enable secure boot. I tried to enable it in BIOS, but it still doesn't work, and in system information, it's off.
Szymon's user avatar
  • 11
5 votes
2 answers
67k views

How do I turn secure boot off in UEFI BIOS on an ASUS TUF Gaming board?

I've tried following various tutorials. The closest one to displaying similar screens as I have was this: https://www.technorms.com/45538/disable-enable-secure-boot-asus-motherboard-uefi-bios-utility ...
Seph Reed's user avatar
  • 885
1 vote
0 answers
2k views

bcdedit.exe command giving strange error

Until yesterday i could use the command bcdedit /set testsigning on, so that i could start kernel mode drivers that are not signed, and then bcdedit /set testsigning off before shutting down, and i ...
User9387425's user avatar
0 votes
1 answer
1k views

Aptio 2.22 @Asus PN52 - how to enable boot from usb stick and install Linux?

I am trying to install Linux Mint 20.3 from USB stick on my new Asus PN52. USB stick was made with UNetbootin on Linux Mint 19. USB drive and internal NVMe disk - operating system destination - are ...
Marcin Badtke's user avatar
0 votes
0 answers
3k views

Debian 11 - grub: Secure boot forbids loading module from (hd1,gpt5)/grub/x86_ 64-efi/exfat.mod

When booting up, my screen flashes with a bunch of errors, reporting that some grub modules couldn't be loaded due to Secure Boot, e.g.: Secure boot forbids loading module from (hd1,gpt5)/grub/x86_ 64-...
mdx's user avatar
  • 161
1 vote
0 answers
318 views

Is it possible to allow only a certain secure USB boot media to boot an UEFI system?

I want to restrict all USB boot media from my system, except for a certain USB boot drive that I declare secure via a certain key. Is this possible using UEFI/Secure Boot/TPM? Maybe via TPM? TPM gets ...
JohnnyFromBF's user avatar
  • 4,978
0 votes
0 answers
122 views

Error after enabling secure boot

I am using msi motherboard Having windows 11 After i went to bios to enable secure boot for the valorant's requirement. The I saved and exit the bios setting, then the computer starting restarting and ...
Hung Vo's user avatar
0 votes
2 answers
15k views

How to disable secure boot without entering UEFI?

My problem is secure boot. I am trying to boot into Linux using a USB but most distros won't work with secure boot, I already know secure boot can be disabled in the UEFI settings, and I know how to ...
Programmer's user avatar
0 votes
1 answer
1k views

Trying to Disable Secure Boot

I am trying to disable Secure Boot in my Linux Mint OS. My laptop is an Acer Aspire 5. The problem is I can use the arrow keys on all BIOS menus, except Security and Boot. When I navigate to the ...
Lianne Mado's user avatar
5 votes
0 answers
3k views

Kernel lockdown disallows loading of an self-compiled and self-signed in-tree kernel module

I'm having difficulties loading a kernel module that I myself compiled and signed for Secure Boot. The module in question is ec_sys, located within drivers/acpi directory of the kernel tree. I'm using ...
mdx's user avatar
  • 161
0 votes
1 answer
1k views

Is there anyway to ignore the CMOS Check during Startup? [closed]

I have broken my CMOS battery seat while replacing the battery, and I want to my pc to Ignore Cmos check during startup. I have already turned on fast boot, but everytime I turn off the switch, fast ...
RAHUL JAISWAL's user avatar

15 30 50 per page
1
2 3 4 5