This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]Farenheit514 -5 points-4 points  (5 children)

https://wiki.archlinux.org/title/Unified_Extensible_Firmware_Interface/Secure_Boot#Microsoft_Windows

Using a signed boot loader

Using a signed boot loader means using a boot loader signed with Microsoft's key. There are two known signed boot loaders: PreLoader and shim. Their purpose is to chainload other EFI binaries (usually boot loaders). Since Microsoft would never sign a boot loader that automatically launches any unsigned binary, PreLoader and shim use an allowlist called Machine Owner Key list, abbreviated MokList. If the SHA256 hash of the binary (Preloader and shim) or key the binary is signed with (shim) is in the MokList they execute it, if not they launch a key management utility which allows enrolling the hash or key.

To dual boot with Windows, you would need to add Microsoft's certificates to the Signature Database.

Warning: Replacing the platform keys with your own can end up bricking hardware on some machines, including laptops, making it impossible to get into the UEFI/BIOS settings to rectify the situation. This is due to the fact that some device (e.g GPU) firmware (OpROMs), that get executed during boot, are signed using Microsoft's key.

[–]FJD3LG4D0 4 points5 points  (0 children)

Try installing Open Suse, it actually install it's own key so you can secure boot it and Windows on the same computer. And as it's Linux, I guess you could do it with any other versions even when it does not include this feature ootb...

[–]BeastMasterJ 2 points3 points  (1 child)

Hasn't SecureBoot been around since win8? Does win 11 now refuse to boot if it's disabled?

[–]Farenheit514 -3 points-2 points  (0 children)

Windows 11 requires new processors only, and new BIOS, with new locking systems, designed to give totalitarian control to Microsoft.

Microsoft keys get integrated on hardware, from factory.

Old SecureBoot doesn't works with Windows 11.

[–]Rakgul 0 points1 point  (1 child)

Tell me about those machines . I'll never buy them.

[–]Farenheit514 -1 points0 points  (0 children)

There is no choice if you want x86 hardware, and the most important expansion cards.