Skip to content

Secure Boot

If you have the option to enable and enroll custom keys, it is highly recommended that you do so in order to protect your encrypted data from boot-chain attacks.

Detailed Guide: Arch Wiki

Enter the following command to check for devices with OpROM: If so, look at the Detailed Guide in the Arch Wiki to determine if any Microsoft keys are used.

Terminal window
find /sys/devices/ -name rom

In order for the option to enroll AstrOS’s own keys to appear, the system’s Secure Boot needs to be in Setup Mode.

To put firmware in Setup Mode, enter firmware setup utility and find an option to delete or clear certificates.

To enroll the keys, navigate to the Enroll Secure Boot Keys option in Systemd-Boot. You will receive a warning that this could soft-break your machine. This is the previously mentioned problem of some ROMs being signed with Microsoft’s keys.