I've been playing around with Secure Boot, while working on
the PCA2023 thing.
The 18 page or so document, a high level description of Secure Boot, indicated that it "should not brick the computer", as a response
to not finding all the signing was good or whatever. But, I got
a taste of how it really works, the last couple days.
I brought a disk I haven't used for a year or so, into the computer.
I had several devices loaded. I turn on the power.
The screen stayed black. The four white staging LEDs on the mobo ?
Remained dark. It wouldn't even admit it had finished quick RAM test.
It would not bring up Pop-Up Boot, and let me select the "valid device"!
It seems it is checking all devices for UEFI materials. It is
inspecting the materials on all the drives. If any drive was say,
a PCA2011-related OS (when PCA2011 is revoked on this machine now), the computer won't do squat. I couldn't even get the fucking thing
to enter the BIOS. I couldn't press <Del>, enter the BIOS, turn off
Secure Boot. I had to disconnect all drives, then it would let me
enter the BIOS.
No, the machine is not bricked. I can remove the drives, all of them,
power up, and then I can start.
Paul <nospam@needed.invalid> wrote:
I've been playing around with Secure Boot, while working on
the PCA2023 thing.
The 18 page or so document, a high level description of Secure Boot,
indicated that it "should not brick the computer", as a response
to not finding all the signing was good or whatever. But, I got
a taste of how it really works, the last couple days.
I brought a disk I haven't used for a year or so, into the computer.
I had several devices loaded. I turn on the power.
The screen stayed black. The four white staging LEDs on the mobo ?
Remained dark. It wouldn't even admit it had finished quick RAM test.
It would not bring up Pop-Up Boot, and let me select the "valid device"!
It seems it is checking all devices for UEFI materials. It is
inspecting the materials on all the drives. If any drive was say,
a PCA2011-related OS (when PCA2011 is revoked on this machine now), the
computer won't do squat. I couldn't even get the fucking thing
to enter the BIOS. I couldn't press <Del>, enter the BIOS, turn off
Secure Boot. I had to disconnect all drives, then it would let me
enter the BIOS.
No, the machine is not bricked. I can remove the drives, all of them,
power up, and then I can start.
Did you have to remove ALL the drives, or would just removing the one
you added have been enough?
I ask, because on some systems - notably laptops, but not limited to laptops - it is not easy, or even (nearly or fully) impossible to remove
the main 'disk'.
I.e., do we have to be worried when we try/need to boot from a Macrium Reflect Rescue Media USB memory-stick, which probably has a
"PCA2011-related OS"?
[...]
| Sysop: | Jacob Catayoc |
|---|---|
| Location: | Pasay City, Metro Manila, Philippines |
| Users: | 4 |
| Nodes: | 4 (0 / 4) |
| Uptime: | 494930:47:22 |
| Calls: | 162 |
| Files: | 568 |
| D/L today: |
14 files (349K bytes) |
| Messages: | 75,011 |