EFI Secure Boot

Parent Previous Next

Google Translate Button


EFI Secure Boot





Grub2Win requires that the EFI Secure Boot facility is disabled.


Disabling "Secure Boot" is required to run any "Non-Microsoft" boot manager such as Grub2Win.



Microsoft controls special "Secure Boot" keys that are embedded in your motherboard's EFI firmware.

Several Linux distributions have also obtained signing keys from Microsoft.

This requires a dedicated development staff to test Linux kernels and submit them to Microsoft for key approval.


Another option is for the user to update keys stored on your motherboard.

This is a complex task requiring the user to complete many steps perfectly.

The update must be done by every user for every machine whenever a bootable kernel is installed or updated.



So as a practical matter, Secure Boot must be disabled or the Grub2Win kernel will not load.


This procedure to disable Secure Boot varies widely and depends on the exact model of your PC or motherboard.




Open the PC BIOS menu. You can often access this menu by pressing a key during the bootup sequence, such as F1, F2 or Del.



Or, from Windows, hold the Shift key while selecting Restart. Go to Troubleshoot > Advanced Options: UEFI Firmware Settings.



Find the Secure Boot setting, and if possible, set it to Disabled. This option is usually in either the Security tab, the Boot tab, or the Authentication tab.



Save changes and exit. The PC reboots.



In some cases, you may need to change other settings in the firmware, such as enabling a Compatibility Support Module (CSM) to support legacy BIOS operating systems.




If you are having trouble disabling Secure Boot after following the steps above, contact your PC or motherboard manufacturer for help.















Created with the Personal Edition of HelpNDoc: Make Documentation Review a Breeze with HelpNDoc's Advanced Project Analyzer