Jip-Hop / sedunlocksrv-pba

Conveniently unlock your Self Encrypting Drive on startup (via HTTPS) without the need to attach monitor and keyboard
GNU General Public License v3.0
37 stars 8 forks source link

Does this work with secure boot enabled? #2

Closed ChubbyAnt closed 1 year ago

ChubbyAnt commented 3 years ago

Does this work with secure boot enabled?

Jip-Hop commented 3 years ago

I don't know... Please let me know if you tried 🙂

Jip-Hop commented 1 year ago

Since this is a question and I don't know the answer I'm closings this issues. It can be reopened if someone tries and reports it's not working with secure boot.

don-dolarson commented 10 months ago

How can I properly test the Secure Boot? I've already flashed MBR shadow with this PBA build and set up sedutil from RESCUE64 in UEFI mode (CSM enabled), Secure Boot disabled, to a nicely working PBA.

Simply switch Secure Boot to enabled and try to boot the PBA and then let it chainload the UEFI operating system or do I need to set everything up from scratch in different mode?

Jip-Hop commented 10 months ago

I think it won't boot when you enable Secure Boot without additional configuration. But you can try or course. However I don't know what you have to do exactly to make this PBA work with Secure Boot.

don-dolarson commented 10 months ago

I'll test switch Secure Boot to enabled and boot as fast as I can. I just wanted to help and give an answer to this thread.

Jip-Hop commented 10 months ago

Much appreciated :) The OS I boot after unlocking the SED with the sedunlocksrv-pba, TrueNAS SCALE, doesn't support Secure Boot (out of the box) so I have to disable it anyway.

don-dolarson commented 10 months ago

I should be able to test it in a couple of days when home. This time I'll boot an UEFI OpenWrt x86 Intel J4125 based router. Do the OS must support Secure Boot as well? I doubt OpenWrt does but need check it. However later this year I can test it on Ryzen 1700X B450 and Ryzen 2400G A320 UEFI based machines running Fedora/RHEL and an Arch distro.