This document discusses the use of the secure boot feature on current UEFI hardware.
GSS 3.3 and later
Starting with Ghost Solution Suite (GSS) 3.1 Win PE 5.1 and 10 automation boot packages support the secure boot feature built in to WinPE while using PXE and automation folders to boot.
Using GSS 3.3 now ISO boot disks and USB boot disks support secure boot.
In order to avoid issues with secure boot with WinPE, disable secure boot in the BIOS/Firmware of the machine you are booting to WinPE (so you can boot to PXE or iPXE).
Creating and restoring an image from systems that are configured for secure boot is now supported also.
It should be noted that using third-party tools to convert an ISO to a USB boot disk is not supported and may not work if the third party tool doesn't support secure boot. Plug the USB boot disk directly into the GSS server so that the boot wizard can directly write the needed files. Additionally using .wim files built outside of the Boot Disk Creator won't support the secure boot feature.