Secure Boot Customization Guide
Secure Boot Customization Guide
July 2017 L01780-001
Disclaimer
The information contained in this document, including URL, other web site references, and other specification documents are subject to change without notice and are provided for informational purposes only. No licenses concerning any intellectual property are being granted, expressly or impliedly, by the disclosure of the information contained in this document. Furthermore, neither Hewlett Packard nor any of its subsidiaries makes any warranties of any nature regarding the use of the information contained in this document, and thus the entire risk, if any, resulting from the use of information within this document is the sole responsibility of the user. Also, the names of the technologies, actual companies, and products mentioned in this document may be trademarks of their respective owners. Complying with all applicable copyright and trademark laws is the sole responsibility of the user of this document. Without limiting any rights under copyright, no part of this document may be reproduced, stored, or transmitted in any form or by any means without the express written consent of HP Development Company, L.P.
HP Development Company, L.P. or its subsidiaries may have patents, patent applications, trademarks, copyrights, or other intellectual property rights covering the subject matter in this document. Except where expressly provided in any written license from HP Development Company, L.P. or its subsidiaries, the furnishing of this document, or any ideas contained within, does not grant any license to these ideas, patents, trademarks, copyrights, or other intellectual property.
Technical whitepaper
| Version No. | Revised by | Changes |
|---|---|---|
| 0.1 | Chris Stewart | Initial Baseline |
| 0.2 | Chris Stewart | Augment PK and KEK import procedures to show sample for self-signed keys. |
| 1.0 | Chris Stewart | Add disclaimer |
| 1.1 | Joe David, Jason Aydelotte | Clarifications and formatting revisions |
Table Caption: This table outlines the version history of a document, detailing the version number, who made the revisions, and a summary of the changes implemented in each version.
Table of contents
| 1 Introduction ...........................................................................................................................7 |
|---|
| 2 Setting up a customized Secure Boot environment ..............................................................8 |
| 2.1 Backup existing Secure Boot configuration .....................................................................................................8 |
| 2.2 Place your HP PC in Secure Boot setup mode .................................................................................................9 |
| 2.3 Obtain PK and KEK public keys ......................................................................................................................10 |
| 2.4 Self-signing certificates .................................................................................................................................10 |
| 2.4.1 Generate a new PK ............................................................................................................................11 |
| 2.4.2 Generate a new KEK ..........................................................................................................................13 |
| 2.5 Install the new PK ..........................................................................................................................................13 |
| 2.5.1 PK: Create a valid SetVariable() package ............................................................................................15 |
| 2.5.2 Import PK using Windows tools .........................................................................................................15 |
| 2.6 Install the new PK-signed KEK .......................................................................................................................16 |
| 2.6.1 KEK: Create a valid SetVariable() package ..........................................................................................17 |
| 2.6.2 Import KEK Using Windows Tools ......................................................................................................18 |
| 2.7 Install the New KEK-signed DB and DBX ........................................................................................................19 |
| 2.7.1 DB ......................................................................................................................................................19 |
| 2.7.2 DBX ....................................................................................................................................................22 |
| 2.8 Enable Secure Boot Once More .....................................................................................................................24 |
| 2.9 Add Additional Certificates to DB or DBX .......................................................................................................24 |
| 2.9.1 DB ......................................................................................................................................................25 |
| 2.9.2 DBX ....................................................................................................................................................27 |
| 3 References ..........................................................................................................................28 |
Table Caption: This table outlines a detailed procedure for setting up a customized Secure Boot environment on an HP PC, covering backup, key generation, installation, and management of Platform Key (PK), Key Exchange Key (KEK), Signature Database (DB), and Forbidden Signature Database (DBX).
List of figures
**Table Caption: This table serves as a detailed index for a document, mapping figure numbers to their titles and corresponding page numbers, likely illustrating steps in a technical process related to Secure Boot configuration. The figures range from initial setup
Rejoignez iFixit gratuitement pour lire le document complet (28 pages)
Nous demandons de créer un compte gratuit pour nous aider à bloquer les bots et à préserver iFixit pour la communauté.