Formatting disc and Secure Boot - new Win 10 installation.

Page 4 of 10 FirstFirst ... 23456 ... LastLast

  1. Posts : 130
    Windows 10 Home 64bit 22H2
    Thread Starter
       #31

    Well so what about my mobo? Is necessary have CSM disabled for secure boot? Manual here: https://dlcdnets.asus.com/pub/ASUS/m..._ug_v2_WEB.pdf
      My Computer


  2. Posts : 18,432
    Windows 11 Pro
       #32

    TheOwner said:
    Well so what about my mobo? Is necessary have CSM disabled for secure boot? Manual here: https://dlcdnets.asus.com/pub/ASUS/m..._ug_v2_WEB.pdf
    Well on page 3-47 it says, "Microsoft Secure Boot only supports Windows UEFI Mode."

    Formatting disc and Secure Boot - new Win 10 installation.-capture1.jpg

    Secure Boot is strictly, 100%, a UEFI function. You cannot enable secure boot and boot in legacy BIOS or CSM mode. No motherboard will do that.

    And if anybody thinks they are booting in legacy BIOS (CSM) mode with secure boot enabled, they need to run msinfo32....

    Formatting disc and Secure Boot - new Win 10 installation.-capture2.jpg
      My Computer


  3. Posts : 130
    Windows 10 Home 64bit 22H2
    Thread Starter
       #33

    So i have to set CSM to disabled right? I am still little confused...if i boot from UEFI win installer, it creates GPT partition for me even with CSM enabled, so windows will check during post both options legacy and uefi or not?
      My Computer


  4. Posts : 5,899
    Win 11 Pro (x64) 22H2
       #34

    TheOwner said:
    So i have to set CSM to disabled right? I am still little confused...if i boot from UEFI win installer, it creates GPT partition for me even with CSM enabled, so windows will check during post both options legacy and uefi or not?
    It's been stated many times... yes "disable" CSM to enable secure boot.

    And yes, if choosing the UEFI install, yes you will get a GPT partition. It does not matter the CSM mode (enable/disable).
      My Computers


  5. Posts : 21,421
    19044.1586 - 21H2 Pro x64
       #35

    TheOwner said:
    So i have to set CSM to disabled right? I am still little confused...if i boot from UEFI win installer, it creates GPT partition for me even with CSM enabled, so windows will check during post both options legacy and uefi or not?
    Do you have a reason to keep CSM enabled (which will mean secure boot is disabled)?
      My Computer


  6. Posts : 130
    Windows 10 Home 64bit 22H2
    Thread Starter
       #36

    steve108 said:
    Do you have a reason to keep CSM enabled (which will mean secure boot is disabled)?
    CSM for compatibility if i want boot from USB (linux live CD, recovery media etc....). In this case i have to each time enable CSM. Now i have CSM enabled and my UEFI says Secure boot enabled, pk keys loaded. I am on Win 7 now MBR/legacy. You probably dont understand me. I think CSM is independend on secure boot, i can boot from UEFI even with CSM! I tried some UEFI USB linux. I just press F8 during post and i can choose legacy or UEFI boot. If i disable CSM, only UEFI are offered.
      My Computer


  7. Posts : 21,421
    19044.1586 - 21H2 Pro x64
       #37

    TheOwner said:
    CSM for compatibility if i want boot from USB (linux live CD, recovery media etc....). In this case i have to each time enable CSM. Now i have CSM enabled and my UEFI says Secure boot enabled, pk keys loaded. I am on Win 7 now MBR/legacy. You probably dont understand me. I think CSM is independend on secure boot, i can boot from UEFI even with CSM! I tried some UEFI USB linux. I just press F8 during post and i can choose legacy or UEFI boot. If i disable CSM, only UEFI are offered.
    Okay, it will be interesting if you install Windows 10 UEFI and can show the screenshot like here: Formatting disc and Secure Boot - new Win 10 installation.

    where it confirms UEFI and Secure Boot if your BIOS has CSM enabled.
    Last edited by steve108; 30 Nov 2021 at 21:53.
      My Computer


  8. Posts : 18,432
    Windows 11 Pro
       #38

    In order for secure boot to be enabled, you must boot in UEFI mode. I have never seen a BIOS that would even let you enable Secure Boot with CSM enabled. But, even if it did allow you to enable both, in order for Secure Boot to be used when booting, it must be booting in UEFI mode.
      My Computer


  9. Posts : 1,079
    10 + Linux
       #39

    Secure Boot


    For our ThinkPad, enabling secure boot removes CSM supports (greydout): Unselectable for secure boot.

    It is not all distros that support secure boot. Ubuntu's does even for a fresh install or dual boot. Arch Linux doesn't and it must be disabled, otherwise it won't boot. Also, it is not all Windows 10/11 builds that support secure boot when doing a clean install.

    All dev builds support secure boot and usually the first build of a series will support it during installation. As soon as a CU(s) is added, you must disable secure boot for a clean install. Example, the first Windows 11 ISO 22000.1 supports secure boot during installation, all subsequent build numbers (CU added) won't. You will have to disable it and re-enable it after.

    For all Ubuntu flavors or LTS distros, it is possible to bypass at boot secure boot momentarily for unsigned Kernels with the help of Mok Utility.This is for adventurous-enthusiast only:

    Code:
    sudo mokutil --disable-validation
    Despite the fact that it is recommended to turn it off during the install, we tend to keep secure boot on as much as we can, except for Arch and other distros using its mainframe.

    All the best,
      My Computer


  10. Posts : 18,432
    Windows 11 Pro
       #40

    All Windows 10/11 ISOs will support Secure Boot during/after installation as long as the USB flash drive is created properly.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 18:56.
Find Us




Windows 10 Forums