Secure Boot Compatibility Guide: Deployment Solution & Ghost Solution Suite
search cancel

Secure Boot Compatibility Guide: Deployment Solution & Ghost Solution Suite

book

Article ID: 163312

calendar_today

Updated On:

Products

Ghost Solution Suite Deployment Solution

Issue/Introduction

Secure Boot compatibility and requirements for current Windows based UEFI systems managed and imaged with Deployment Solution and Ghost Solution Suite

Environment

GSS 3.3.12 and later

DS 8.8 and later

WinPE

Cause

Secure Boot blocks any bootloader without a valid and trusted certificate

Resolution

Secure Boot Compatibility Guide for DS & GSS

All current versions of Deployment Solution (DS) and Ghost Solution Suite (GSS) support Secure Boot across all WinPE delivery methods, including PXE, Automation Folders, and external media.

1. Trust & Certificate Requirements

To ensure a successful boot, verify your BIOS/UEFI settings based on your chosen method:

  • PXE / iPXE Booting: You must enable the "Microsoft 3rd Party UEFI CA" trust. The PXE bootloaders are signed by this specific authority.

  • USB, ISO, or Automation Folders: While these can function with the 3rd Party CA trust disabled, keeping it enabled is recommended to prevent issues with unsigned drivers.

2. Imaging & Maintenance

DS and GSS are fully equipped to capture and restore images on Secure Boot-enabled Windows devices.

Pro Tip: To maintain seamless compatibility, ensure both your hardware BIOS/UEFI and Windows security patches are kept up to date.


3. Media Creation Best Practices

To avoid boot failures, follow these strict requirements for media creation:

  • Use Native Tools: Always use the built-in Boot Disk Creator. Plug your USB drive directly into the DS or GSS server for external media creation.

  • Avoid Third-Party Utilities: Tools like Rufus or Etcher often fail to write the necessary signatures required for Secure Boot validation.

  • WIM Compatibility: Custom .WIM files generated outside of the GSS environment which do not support Secure Boot and may fail to load.

Additional Information

PXE Boot Fails on Secure Boot Enabled Devices after Upgrading to ITMS 8.8.1

Deployment Solution 8.x and GSS 3.3.x – Microsoft Secure Boot Changes and BlackLotus Vulnerability (CVE-2023-24932)