0

I recently managed to get secure boot working on my system with Arch Linux. I am using custom keys over preloader/shim I would like to blacklist Microsoft's key. Is this possible. If so how?

1 Answer 1

0

This can be surely done via UEFI BIOS. Boot into it and select:

"Delete All Secure Boot Keys" - this option name is BIOS dependent.

Then proceed to install your own MAK key again:

3
  • I would like to add the Microsoft key to the DBx to black list it. Is that possible? Commented Jul 27, 2020 at 15:57
  • If you remove it, there's no need to blacklist it. Commented Jul 27, 2020 at 16:01
  • Some UEFI systems will only provide the option to delete the primary key (PK) - this will enable Secure Boot Setup Mode, which allows replacing all the keys freely until a new PK is installed. If the UEFI BIOS has no other options, you will need another tool for modifying the keys - the keytool in efitools includes a stand-alone keytool.efi. Put it on USB stick as \efi\boot\bootx64.efi then boot from the stick, and you can edit Secure Boot keys on any Secure Boot system, if you first can get the system to Setup Mode. Commented Jul 28, 2020 at 7:15

You must log in to answer this question.

Start asking to get answers

Find the answer to your question by asking.

Ask question

Explore related questions

See similar questions with these tags.