You are not logged in.

#1 2018-07-15 13:35:18

runner_675
Member
Registered: 2018-07-15
Posts: 2

Enroll own keys issue

Hello,

i am new to arch and just installed it on my system (Razer Blade 13 2017: i7-8550u) everything forks fine so far. But since I want to use secure boot and only with my own keys (I don't have Windows installed and I don't trust  MS/Razer/Intel/YourFavoriteElectronicsCompany) i ran into my first real issue.

Razer provides no Interface in the Blade for delteing Keys, so i use KeyTool

I have successfully setup secure-boot with rEFInd and shim.

- I followed the tutorials on enroll your own keys: https://wiki.archlinux.org/index.php/Se … n_firmware and http://www.rodsbooks.com/efi-bootloader … ng-sb.html

- Have generated and signed everything

When i start MokManager or KeyTool and want to delete the Platform Key, my Bios asks me for the remove .auth file, then i provide the rem_PK.auth file which i extracted with KeyTool in previous steps, but I only get a warning: "security violation".

If I cannot delete the Platform Key, there is no possibility to enter the KeyTool in Setup Mode and enroll my own Keys.

Have anybody had similar issues? Also on Google you can barely find any useful information about secure boot, which is strange since it exists since 2005 and every PC ships with it. No forum guides. Are there only around 100 people on this planet who care about that stuff?

Offline

#2 2018-07-15 14:40:59

runner_675
Member
Registered: 2018-07-15
Posts: 2

Re: Enroll own keys issue

Thread can be closed. After 2 days of trying and 1 hour after posting, I discovered this blog post https://lukegb.com/posts/2016-11-11-sec … enanigans/. Looks like i have to modify my firmware to achieve this.

Offline

Board footer

Powered by FluxBB