You are not logged in.
I've been recently attempting to enable secure boot with custom keys on my new laptop but I cannot enroll a platform key for the life of me. I was able to setup secure boot on my main desktop PC so the steps leading to setting it up should be correct.
It seems the issue is that the BIOS/UEFI in the laptop just won't let me enroll ONLY the platform key. I can easily add a KEK/db/dbx key but not a platform key. I can delete the platform key though. Additionally, I can't enter setup mode either. There is a greyed out option in the secure boot section saying "User Customized Security: YES" to which I'm not sure if it fully relates here but it may be useful. The only modes I can enter is "Audit mode" and "Deployed Mode" if I reset the keys to factory settings.
Last edited by RetroThief (2022-05-21 02:01:59)
Offline
Have you tried sbkeysync or KeyTool.efi? Be sure to enrol the Platform Key last though.
Jin, Jîyan, Azadî
Offline
I have tried using sbkeysync but it fails to sync the platform key even after running the 'chattr' command. Thanks for reminding me about KeyTool.efi though; I'll try using that.
Edit: Typo
Last edited by RetroThief (2022-05-20 01:54:21)
Offline
Keytool.efi worked wonderfully! Thanks!
Offline