Secure Boot is a security function UEFI who checks the signature The purpose of the software is to prevent an unapproved charger from running before the system; its condition depends on the firmware, the start mode and the keys present in the system.UEFI.
Simple definition
Secure Boot checks the signature of the components loaded at start-up UEFI.
Technical definition
Secure Boot checks the signature of the components loaded at start-up UEFI. In the business environment, its configuration must be consistent with the network architecture, security policies and capabilities of the equipment concerned.
Enable Secure Boot without breaking the start
Check the mode first UEFI, compatibility of the operating system and state BitLocker. Save the recovery information and follow the manufacturer’s procedure for keys and firmware. After activation, restart and then control again msinfo32 or Confirm-SecureBootUEFI. If the system depends on a third-party charger, validate its compatibility before forcing activation.
What is it used for?
reduce the risk of bootkit.
Practical example
UEFI Check the Windows charger.
How to check Secure Boot Windows?
In Windows, msinfo32 displays the safe boot status and BIOS/ modeUEFI. PowerShell may also use Confirm-SecureBootUEFI If the control indicates that the platform is not supported, check first that the system actually starts in UEFI and not in the LEG/CSM mode before modifying the firmware.
Common issues
Frequent causes include start-up Õ/CSM, keys Secure Boot missing or customised, an unsigned charger or incompatible firmware configuration. On a machine protected by BitLocker, a change in the start mode or certain parameters UEFI can trigger a request for recovery key. So make sure that recovery BitLocker is controlled before any firmware modification.
FAQ — Secure Boot
Secure Boot is it identical to TPM ?
No. Secure Boot controls the start chain UEFI, while the TPM provides in particular cryptographic storage and certification functions.
Why can’t the company fail?
The machine may not be started in UEFI or the platform may not expose the expected function.
Can we activate Secure Boot without checking BitLocker ?
It is better to have the recovery key and follow the organization’s procedure before any modification of the firmware.