Can't enable secure boot in BIOS without a Platform Key

Status
Not open for further replies.

dc2000

Distinguished
Jan 22, 2012
68
0
18,640
I'm trying to enable secure boot in BIOS before I install Windows 10. I first disable CSM. That part is easy. But then when I try to enable secure boot I get this error:

Secure Boot can be enabled when Platform is in User Mode. Repeat operation after enrolling Platform Key (PM).

Now say, what???

Here's the screenshot:

CtLuD4W.jpg

 
Solution

The Provision Factory Defaults should be the way to reinstall Microsoft keys.


Because these are AMI manufacturer test keys, not intended to secure an operating system, but rather for development/programming purposes. These keys can be available to many people and thus do not secure the boot process.

dc2000

Distinguished
Jan 22, 2012
68
0
18,640


You know if I click "key management" and then "Platform Key (PK)" and then pick "Set new" it creates it but then if click that PK again and go into details, it shows this:

0IkpwtS.jpg


Why is it saying "DO NOT TRUST" there?

And what's that "TEST AMI"?
 

larrycumming

Prominent
Aug 15, 2018
422
0
410
"TEST AMI" are the default keys shipped with your motherboard.

Do you have a TPM installed?

I think you're supposed to change it from Custom back to Standard mode before enabling UEFI boot.



 
Nov 15, 2018
1
0
20

The Provision Factory Defaults should be the way to reinstall Microsoft keys.


Because these are AMI manufacturer test keys, not intended to secure an operating system, but rather for development/programming purposes. These keys can be available to many people and thus do not secure the boot process.
 
Solution
Nov 25, 2018
1
1
10
Problem Solved with my asus.
U have to insert flash drive with OS first. Then enrol platform pk to save the variable into flashdrive so that on bootup the bios can read the bootable usb.
Goodluck to all. Regards nyo nalang ako
 
  • Like
Reactions: Laaurris
Status
Not open for further replies.