ventoy / Ventoy

A new bootable USB solution.
https://www.ventoy.net
GNU General Public License v3.0
61.85k stars 4.02k forks source link

[issue]: 'Secure Boot support' drive still gives Security Violation error in Lenovo Laptop #1758

Open tezpadhye opened 2 years ago

tezpadhye commented 2 years ago

Official FAQ

Ventoy Version

1.0.79

What about latest release

Yes. I have tried the latest release, but the bug still exist.

BIOS Mode

UEFI Mode

Partition Style

GPT

Disk Capacity

32GB

Disk Manufacturer

HP

Image file checksum (if applicable)

No response

Image file download link (if applicable)

No response

What happened?

Tried installing windows 10 iso using ventoy drive with secure boot support. laptop also had secure boot 'on'. It still gave me security violation error and flagged the device.

ventoy commented 2 years ago

Better with a photo about the error.

xppancho commented 2 years ago

did you install the key? to pass uefi/secureboot

tezpadhye commented 2 years ago

did you install the key? to pass uefi/secureboot

I only ticked the option 'secure boot support' in the ventoy app

steve6375 commented 2 years ago

https://ventoy.net/en/doc_secure.html

tezpadhye commented 2 years ago

did you install the key? to pass uefi/secureboot

I didnt get the further options to enroll key or hash. Only OK option, after which it said it flagged the device and laptop restarted.

MartinVonReichenberg commented 2 years ago

did you install the key? to pass uefi/secureboot

I didnt get the further options to enroll key or hash. Only OK option, after which it said it flagged the device and laptop restarted.

Disabling 'Secure Boot' ?_?

dcasota commented 1 year ago

I have a similar firmware security violation message (it is not a Ventoy screen message) on a HP 250 G8 laptop with the 1.0.80 version. Before that, the laptop never has been booted with a Ventoy (usb) media.

Same laptop usb media booted with the 1.0.78 version, the expected Ventoy 'Verification failed' message appears and the Enroll Key workflows runs successfully.

AndiTails commented 1 year ago

One workaround for this (for Dell, at least) is to ensure in the BIOS, under Secure Boot, you set the Secure Boot to "Audit mode" and not "Deployed Mode". This will allow Ventoy to bypass the restriction, and allow Windows to still utilise Secure Boot (so you don't need to disable it).

naruko-hstk commented 1 month ago

did you install the key? to pass uefi/secureboot

I didnt get the further options to enroll key or hash. Only OK option, after which it said it flagged the device and laptop restarted.

Disabling 'Secure Boot' ?_?

You're right. Secure Boot is NOT a good choice. Everyone should disable it. Don't use UEFI Just use legacy BIOS. It's a good choose for everyone

MartinVonReichenberg commented 1 month ago

did you install the key? to pass uefi/secureboot

I didnt get the further options to enroll key or hash. Only OK option, after which it said it flagged the device and laptop restarted.

Disabling 'Secure Boot' ?_?

You're right. Secure Boot is NOT a good choice. Everyone should disable it. Don't use UEFI Just use legacy BIOS. It's a good choose for everyone

EFI is better for multi-booting as it is easier and more versatile in managing boot entries than BIOS.

„Secure-boot takes away freedom.“