Can I re-enable Secure Boot, Fast Start-up, or Bitlocker on Win10 on Dual boot (Grub default) Ubuntu18.4 system?Unable to mount Windows (NTFS) filesystem due to hibernationUse (Windows) BitLocker-encrypted drive on Ubuntu 14.04 LTSIs re-enabling Secure Boot in UEFI secure?Dual Boot with Windows 8 UEFI - Ubuntu/GRUB Being BypassedHow to enable Secure Boot without issue?Dual booting Win10/Ubuntu 15.04 starts in grub bashdual-boot with secure boot: invalid signaturesecure boot issue : win10 & ubuntu16.04No Grub, no boot after accidental “Secure boot enable”; dual bootI have dual-boot Ubuntu and Win10, what happens if i reinstall Win?Dual boot Ubuntu 17 with windows 10 - Grub doesn't startChainload from windows boot manager to Grub with Secure Boot enabledInstall Ubuntu 16.04 on HDD of a computer with Secure Boot that has Win10 on SSD

Infinitely many hats

Can I use the Shadow Step feature to effectively teleport into a Darkness spell I cast upon myself?

I unknowingly submitted plagiarised work

Is it possible to change original filename of an exe?

What is the most important source of natural gas? coal, oil or other?

Is this resistor leaking? If so, is it a concern?

Why colon to denote that a value belongs to a type?

Is there any use case for the bottom type as a function parameter type?

Under what law can the U.S. arrest International Criminal Court (ICC) judges over war crimes probe?

What F1 in name of seeds/varieties means?

Can someone walk us through Nielsen proof's on a circuit for quantum teleportation?

How do I subvert the tropes of a train heist?

Is it ok to put a subplot to a story that is never meant to contribute to the development of the main plot?

How to verify sticky delta property on a stochastic volatility model

Help to draw software architecture stack diagrams?

What does the behaviour of water on the skin of an aircraft in flight tell us?

Modern approach to radio buttons

Crossword gone overboard

Can a wire having a 610-670 THz (frequency of blue light) AC frequency supply, generate blue light?

What are the benefits of cryosleep?

File globbing pattern, !(*example), behaves differently in bash script than it does in bash shell

Apparent Ring of Craters on the Moon

Is my router's IP address really public?

Can a Beholder use rays in melee range?



Can I re-enable Secure Boot, Fast Start-up, or Bitlocker on Win10 on Dual boot (Grub default) Ubuntu18.4 system?


Unable to mount Windows (NTFS) filesystem due to hibernationUse (Windows) BitLocker-encrypted drive on Ubuntu 14.04 LTSIs re-enabling Secure Boot in UEFI secure?Dual Boot with Windows 8 UEFI - Ubuntu/GRUB Being BypassedHow to enable Secure Boot without issue?Dual booting Win10/Ubuntu 15.04 starts in grub bashdual-boot with secure boot: invalid signaturesecure boot issue : win10 & ubuntu16.04No Grub, no boot after accidental “Secure boot enable”; dual bootI have dual-boot Ubuntu and Win10, what happens if i reinstall Win?Dual boot Ubuntu 17 with windows 10 - Grub doesn't startChainload from windows boot manager to Grub with Secure Boot enabledInstall Ubuntu 16.04 on HDD of a computer with Secure Boot that has Win10 on SSD






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty margin-bottom:0;








0















Can I re-enable Secure Boot, Fast Start-up, or Bitlocker on Win10 on a Dell Inspiron 15 3567 Dual boot (Grub default) Ubuntu18.4 Windows10 system? What are risks or implications.










share|improve this question



















  • 2





    Welcome to Ask Ubuntu. This is a question answer site. Please see site help for how to ask questions in this site. Please ask one question at a time.

    – user68186
    Apr 13 at 16:29






  • 1





    "peppermint9" off topic.

    – Rinzwind
    Apr 13 at 17:25











  • If you think the answer is correct (the problem is solved) then put the green check mark (✔️) on the left margin of the answer. This will help others.

    – user68186
    Apr 13 at 22:02

















0















Can I re-enable Secure Boot, Fast Start-up, or Bitlocker on Win10 on a Dell Inspiron 15 3567 Dual boot (Grub default) Ubuntu18.4 Windows10 system? What are risks or implications.










share|improve this question



















  • 2





    Welcome to Ask Ubuntu. This is a question answer site. Please see site help for how to ask questions in this site. Please ask one question at a time.

    – user68186
    Apr 13 at 16:29






  • 1





    "peppermint9" off topic.

    – Rinzwind
    Apr 13 at 17:25











  • If you think the answer is correct (the problem is solved) then put the green check mark (✔️) on the left margin of the answer. This will help others.

    – user68186
    Apr 13 at 22:02













0












0








0








Can I re-enable Secure Boot, Fast Start-up, or Bitlocker on Win10 on a Dell Inspiron 15 3567 Dual boot (Grub default) Ubuntu18.4 Windows10 system? What are risks or implications.










share|improve this question
















Can I re-enable Secure Boot, Fast Start-up, or Bitlocker on Win10 on a Dell Inspiron 15 3567 Dual boot (Grub default) Ubuntu18.4 Windows10 system? What are risks or implications.







dual-boot windows-10 secure-boot






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Apr 13 at 22:08







mako34

















asked Apr 13 at 15:32









mako34mako34

12




12







  • 2





    Welcome to Ask Ubuntu. This is a question answer site. Please see site help for how to ask questions in this site. Please ask one question at a time.

    – user68186
    Apr 13 at 16:29






  • 1





    "peppermint9" off topic.

    – Rinzwind
    Apr 13 at 17:25











  • If you think the answer is correct (the problem is solved) then put the green check mark (✔️) on the left margin of the answer. This will help others.

    – user68186
    Apr 13 at 22:02












  • 2





    Welcome to Ask Ubuntu. This is a question answer site. Please see site help for how to ask questions in this site. Please ask one question at a time.

    – user68186
    Apr 13 at 16:29






  • 1





    "peppermint9" off topic.

    – Rinzwind
    Apr 13 at 17:25











  • If you think the answer is correct (the problem is solved) then put the green check mark (✔️) on the left margin of the answer. This will help others.

    – user68186
    Apr 13 at 22:02







2




2





Welcome to Ask Ubuntu. This is a question answer site. Please see site help for how to ask questions in this site. Please ask one question at a time.

– user68186
Apr 13 at 16:29





Welcome to Ask Ubuntu. This is a question answer site. Please see site help for how to ask questions in this site. Please ask one question at a time.

– user68186
Apr 13 at 16:29




1




1





"peppermint9" off topic.

– Rinzwind
Apr 13 at 17:25





"peppermint9" off topic.

– Rinzwind
Apr 13 at 17:25













If you think the answer is correct (the problem is solved) then put the green check mark (✔️) on the left margin of the answer. This will help others.

– user68186
Apr 13 at 22:02





If you think the answer is correct (the problem is solved) then put the green check mark (✔️) on the left margin of the answer. This will help others.

– user68186
Apr 13 at 22:02










1 Answer
1






active

oldest

votes


















0














Secure Boot



  1. Ubuntu installs differently when secure boot is disabled.

When Ubuntu is installed in the UEFI mode with secure boot disabled, it installs EFIubuntugrubx64.efi.



When Ubuntu is installed in the UEFI mode with secure boot enabled, it installs EFIubuntushimx64.efi.



If you enable secure boot after installing Ubuntu, the Ubuntu will not not boot if the shimx64.efi does not exist.



The difference between shimx64.efi and grubx64.efi is that shimx64 is the actual Microsoft signed binary that works with Secure Boot enabled while grubx64 is the normal grub binary (Not signed).



  1. Some third party device drivers can only be installed when secure boot is disabled.

The third party device drivers may not load and thus, some specific devices will not work.



See Is re-enabling Secure Boot in UEFI secure? for more.



Fast Start-up



Fast Start-Up or fast-boot can mean two things.



I assume this is the option in Windows 10.



This is not the UEFI option that skips the boot setup and boot device select menu when the computer boots.



Fast Start-up does not shut down Windows properly, and puts it in a hibernate state when Windows is shut down. This means all the partitions that are accessible by Windows (C:, D:, etc) are not properly shut down. Ubuntu will not be able access these drives properly in this state. In particular, you will not be able write files, including copy, move, etc., to these partitions when you use Ubuntu. This will be an issue if you have a common partition that you share between Windows and Ubuntu.



See Unable to mount Windows (NTFS) filesystem due to hibernation this answer for more explanation.



Bitlocker



Enabling Bitlocker in Windows will also make the Windows partition inaccessible from Ubuntu.



There may be ways to get around it. See Use (Windows) BitLocker-encrypted drive on Ubuntu 14.04 LTS



Disclaimer: I have not tried any of these things. So, there may be other consequences of enabling Secure Boot, Fast Start-up, and Bitlocker I am unaware of. Use at your own risk.






share|improve this answer

























  • As long as GRUB loads or Windows does that's OK cause I can just reenter BIOS and shut off Sure Boot. The question is, does Windows try to interrogate GRUB for "integrity" (which I suppose it can't), or does it just ignore it to analyze the Windows boot (or is that bypassed by GRUB?)

    – mako34
    Apr 13 at 21:48











  • Are you saying if you install Ubuntu with SB OFF,then it can't really be turned back on since it wasn't installed under proper SB protocols? As I understand it, only problems are with non-standard proprietary drivers so Ubuntu could have problems but Windows should be fine. Fast Start-Up obviously is unnecessary and risky; and Bitlocker scared me from first contact (ship computer with it enabled, where just booting up in Safe Mode can trigger a lock-out??), but I am in an insane threat environment & likely target, so would like Secure Boot, if possible, if it can give any additional protection

    – mako34
    Apr 13 at 22:04











  • An install with secure boot disabled will install the unsigned versions of the bootloader grubx64.efi. Turning secure boot on will then prevent grubx64.efi from booting, and there is no shimx64 either. That's why I like to install with secure boot on, then turn it off if necessary to install third party drivers. The system would then boot with secure boot in either state.

    – ubfan1
    Apr 14 at 1:18











  • @ubfan1 Thanks! I edited the text to make it clearer.

    – user68186
    Apr 14 at 1:27











  • Oh God, so it was stupid to install with SB Off, Ubuntu could say "dual install with SB on but then shut it off if there are boot problems!!" Can I convert grubx64 to shimx64 or delete it and load the latter? Can you elucidate on SB action with shimx64 - does it actually examine (integrity) the GRUB boot at all, or just ignore it; does it ignore the Windows boot sector (in which case viruses too would be bypassed) and go directly to Win startup?

    – mako34
    Apr 14 at 2:41











Your Answer








StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "89"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);

else
createEditor();

);

function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);



);













draft saved

draft discarded


















StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2faskubuntu.com%2fquestions%2f1133563%2fcan-i-re-enable-secure-boot-fast-start-up-or-bitlocker-on-win10-on-dual-boot%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown

























1 Answer
1






active

oldest

votes








1 Answer
1






active

oldest

votes









active

oldest

votes






active

oldest

votes









0














Secure Boot



  1. Ubuntu installs differently when secure boot is disabled.

When Ubuntu is installed in the UEFI mode with secure boot disabled, it installs EFIubuntugrubx64.efi.



When Ubuntu is installed in the UEFI mode with secure boot enabled, it installs EFIubuntushimx64.efi.



If you enable secure boot after installing Ubuntu, the Ubuntu will not not boot if the shimx64.efi does not exist.



The difference between shimx64.efi and grubx64.efi is that shimx64 is the actual Microsoft signed binary that works with Secure Boot enabled while grubx64 is the normal grub binary (Not signed).



  1. Some third party device drivers can only be installed when secure boot is disabled.

The third party device drivers may not load and thus, some specific devices will not work.



See Is re-enabling Secure Boot in UEFI secure? for more.



Fast Start-up



Fast Start-Up or fast-boot can mean two things.



I assume this is the option in Windows 10.



This is not the UEFI option that skips the boot setup and boot device select menu when the computer boots.



Fast Start-up does not shut down Windows properly, and puts it in a hibernate state when Windows is shut down. This means all the partitions that are accessible by Windows (C:, D:, etc) are not properly shut down. Ubuntu will not be able access these drives properly in this state. In particular, you will not be able write files, including copy, move, etc., to these partitions when you use Ubuntu. This will be an issue if you have a common partition that you share between Windows and Ubuntu.



See Unable to mount Windows (NTFS) filesystem due to hibernation this answer for more explanation.



Bitlocker



Enabling Bitlocker in Windows will also make the Windows partition inaccessible from Ubuntu.



There may be ways to get around it. See Use (Windows) BitLocker-encrypted drive on Ubuntu 14.04 LTS



Disclaimer: I have not tried any of these things. So, there may be other consequences of enabling Secure Boot, Fast Start-up, and Bitlocker I am unaware of. Use at your own risk.






share|improve this answer

























  • As long as GRUB loads or Windows does that's OK cause I can just reenter BIOS and shut off Sure Boot. The question is, does Windows try to interrogate GRUB for "integrity" (which I suppose it can't), or does it just ignore it to analyze the Windows boot (or is that bypassed by GRUB?)

    – mako34
    Apr 13 at 21:48











  • Are you saying if you install Ubuntu with SB OFF,then it can't really be turned back on since it wasn't installed under proper SB protocols? As I understand it, only problems are with non-standard proprietary drivers so Ubuntu could have problems but Windows should be fine. Fast Start-Up obviously is unnecessary and risky; and Bitlocker scared me from first contact (ship computer with it enabled, where just booting up in Safe Mode can trigger a lock-out??), but I am in an insane threat environment & likely target, so would like Secure Boot, if possible, if it can give any additional protection

    – mako34
    Apr 13 at 22:04











  • An install with secure boot disabled will install the unsigned versions of the bootloader grubx64.efi. Turning secure boot on will then prevent grubx64.efi from booting, and there is no shimx64 either. That's why I like to install with secure boot on, then turn it off if necessary to install third party drivers. The system would then boot with secure boot in either state.

    – ubfan1
    Apr 14 at 1:18











  • @ubfan1 Thanks! I edited the text to make it clearer.

    – user68186
    Apr 14 at 1:27











  • Oh God, so it was stupid to install with SB Off, Ubuntu could say "dual install with SB on but then shut it off if there are boot problems!!" Can I convert grubx64 to shimx64 or delete it and load the latter? Can you elucidate on SB action with shimx64 - does it actually examine (integrity) the GRUB boot at all, or just ignore it; does it ignore the Windows boot sector (in which case viruses too would be bypassed) and go directly to Win startup?

    – mako34
    Apr 14 at 2:41















0














Secure Boot



  1. Ubuntu installs differently when secure boot is disabled.

When Ubuntu is installed in the UEFI mode with secure boot disabled, it installs EFIubuntugrubx64.efi.



When Ubuntu is installed in the UEFI mode with secure boot enabled, it installs EFIubuntushimx64.efi.



If you enable secure boot after installing Ubuntu, the Ubuntu will not not boot if the shimx64.efi does not exist.



The difference between shimx64.efi and grubx64.efi is that shimx64 is the actual Microsoft signed binary that works with Secure Boot enabled while grubx64 is the normal grub binary (Not signed).



  1. Some third party device drivers can only be installed when secure boot is disabled.

The third party device drivers may not load and thus, some specific devices will not work.



See Is re-enabling Secure Boot in UEFI secure? for more.



Fast Start-up



Fast Start-Up or fast-boot can mean two things.



I assume this is the option in Windows 10.



This is not the UEFI option that skips the boot setup and boot device select menu when the computer boots.



Fast Start-up does not shut down Windows properly, and puts it in a hibernate state when Windows is shut down. This means all the partitions that are accessible by Windows (C:, D:, etc) are not properly shut down. Ubuntu will not be able access these drives properly in this state. In particular, you will not be able write files, including copy, move, etc., to these partitions when you use Ubuntu. This will be an issue if you have a common partition that you share between Windows and Ubuntu.



See Unable to mount Windows (NTFS) filesystem due to hibernation this answer for more explanation.



Bitlocker



Enabling Bitlocker in Windows will also make the Windows partition inaccessible from Ubuntu.



There may be ways to get around it. See Use (Windows) BitLocker-encrypted drive on Ubuntu 14.04 LTS



Disclaimer: I have not tried any of these things. So, there may be other consequences of enabling Secure Boot, Fast Start-up, and Bitlocker I am unaware of. Use at your own risk.






share|improve this answer

























  • As long as GRUB loads or Windows does that's OK cause I can just reenter BIOS and shut off Sure Boot. The question is, does Windows try to interrogate GRUB for "integrity" (which I suppose it can't), or does it just ignore it to analyze the Windows boot (or is that bypassed by GRUB?)

    – mako34
    Apr 13 at 21:48











  • Are you saying if you install Ubuntu with SB OFF,then it can't really be turned back on since it wasn't installed under proper SB protocols? As I understand it, only problems are with non-standard proprietary drivers so Ubuntu could have problems but Windows should be fine. Fast Start-Up obviously is unnecessary and risky; and Bitlocker scared me from first contact (ship computer with it enabled, where just booting up in Safe Mode can trigger a lock-out??), but I am in an insane threat environment & likely target, so would like Secure Boot, if possible, if it can give any additional protection

    – mako34
    Apr 13 at 22:04











  • An install with secure boot disabled will install the unsigned versions of the bootloader grubx64.efi. Turning secure boot on will then prevent grubx64.efi from booting, and there is no shimx64 either. That's why I like to install with secure boot on, then turn it off if necessary to install third party drivers. The system would then boot with secure boot in either state.

    – ubfan1
    Apr 14 at 1:18











  • @ubfan1 Thanks! I edited the text to make it clearer.

    – user68186
    Apr 14 at 1:27











  • Oh God, so it was stupid to install with SB Off, Ubuntu could say "dual install with SB on but then shut it off if there are boot problems!!" Can I convert grubx64 to shimx64 or delete it and load the latter? Can you elucidate on SB action with shimx64 - does it actually examine (integrity) the GRUB boot at all, or just ignore it; does it ignore the Windows boot sector (in which case viruses too would be bypassed) and go directly to Win startup?

    – mako34
    Apr 14 at 2:41













0












0








0







Secure Boot



  1. Ubuntu installs differently when secure boot is disabled.

When Ubuntu is installed in the UEFI mode with secure boot disabled, it installs EFIubuntugrubx64.efi.



When Ubuntu is installed in the UEFI mode with secure boot enabled, it installs EFIubuntushimx64.efi.



If you enable secure boot after installing Ubuntu, the Ubuntu will not not boot if the shimx64.efi does not exist.



The difference between shimx64.efi and grubx64.efi is that shimx64 is the actual Microsoft signed binary that works with Secure Boot enabled while grubx64 is the normal grub binary (Not signed).



  1. Some third party device drivers can only be installed when secure boot is disabled.

The third party device drivers may not load and thus, some specific devices will not work.



See Is re-enabling Secure Boot in UEFI secure? for more.



Fast Start-up



Fast Start-Up or fast-boot can mean two things.



I assume this is the option in Windows 10.



This is not the UEFI option that skips the boot setup and boot device select menu when the computer boots.



Fast Start-up does not shut down Windows properly, and puts it in a hibernate state when Windows is shut down. This means all the partitions that are accessible by Windows (C:, D:, etc) are not properly shut down. Ubuntu will not be able access these drives properly in this state. In particular, you will not be able write files, including copy, move, etc., to these partitions when you use Ubuntu. This will be an issue if you have a common partition that you share between Windows and Ubuntu.



See Unable to mount Windows (NTFS) filesystem due to hibernation this answer for more explanation.



Bitlocker



Enabling Bitlocker in Windows will also make the Windows partition inaccessible from Ubuntu.



There may be ways to get around it. See Use (Windows) BitLocker-encrypted drive on Ubuntu 14.04 LTS



Disclaimer: I have not tried any of these things. So, there may be other consequences of enabling Secure Boot, Fast Start-up, and Bitlocker I am unaware of. Use at your own risk.






share|improve this answer















Secure Boot



  1. Ubuntu installs differently when secure boot is disabled.

When Ubuntu is installed in the UEFI mode with secure boot disabled, it installs EFIubuntugrubx64.efi.



When Ubuntu is installed in the UEFI mode with secure boot enabled, it installs EFIubuntushimx64.efi.



If you enable secure boot after installing Ubuntu, the Ubuntu will not not boot if the shimx64.efi does not exist.



The difference between shimx64.efi and grubx64.efi is that shimx64 is the actual Microsoft signed binary that works with Secure Boot enabled while grubx64 is the normal grub binary (Not signed).



  1. Some third party device drivers can only be installed when secure boot is disabled.

The third party device drivers may not load and thus, some specific devices will not work.



See Is re-enabling Secure Boot in UEFI secure? for more.



Fast Start-up



Fast Start-Up or fast-boot can mean two things.



I assume this is the option in Windows 10.



This is not the UEFI option that skips the boot setup and boot device select menu when the computer boots.



Fast Start-up does not shut down Windows properly, and puts it in a hibernate state when Windows is shut down. This means all the partitions that are accessible by Windows (C:, D:, etc) are not properly shut down. Ubuntu will not be able access these drives properly in this state. In particular, you will not be able write files, including copy, move, etc., to these partitions when you use Ubuntu. This will be an issue if you have a common partition that you share between Windows and Ubuntu.



See Unable to mount Windows (NTFS) filesystem due to hibernation this answer for more explanation.



Bitlocker



Enabling Bitlocker in Windows will also make the Windows partition inaccessible from Ubuntu.



There may be ways to get around it. See Use (Windows) BitLocker-encrypted drive on Ubuntu 14.04 LTS



Disclaimer: I have not tried any of these things. So, there may be other consequences of enabling Secure Boot, Fast Start-up, and Bitlocker I am unaware of. Use at your own risk.







share|improve this answer














share|improve this answer



share|improve this answer








edited Apr 14 at 1:25

























answered Apr 13 at 16:49









user68186user68186

17.2k85074




17.2k85074












  • As long as GRUB loads or Windows does that's OK cause I can just reenter BIOS and shut off Sure Boot. The question is, does Windows try to interrogate GRUB for "integrity" (which I suppose it can't), or does it just ignore it to analyze the Windows boot (or is that bypassed by GRUB?)

    – mako34
    Apr 13 at 21:48











  • Are you saying if you install Ubuntu with SB OFF,then it can't really be turned back on since it wasn't installed under proper SB protocols? As I understand it, only problems are with non-standard proprietary drivers so Ubuntu could have problems but Windows should be fine. Fast Start-Up obviously is unnecessary and risky; and Bitlocker scared me from first contact (ship computer with it enabled, where just booting up in Safe Mode can trigger a lock-out??), but I am in an insane threat environment & likely target, so would like Secure Boot, if possible, if it can give any additional protection

    – mako34
    Apr 13 at 22:04











  • An install with secure boot disabled will install the unsigned versions of the bootloader grubx64.efi. Turning secure boot on will then prevent grubx64.efi from booting, and there is no shimx64 either. That's why I like to install with secure boot on, then turn it off if necessary to install third party drivers. The system would then boot with secure boot in either state.

    – ubfan1
    Apr 14 at 1:18











  • @ubfan1 Thanks! I edited the text to make it clearer.

    – user68186
    Apr 14 at 1:27











  • Oh God, so it was stupid to install with SB Off, Ubuntu could say "dual install with SB on but then shut it off if there are boot problems!!" Can I convert grubx64 to shimx64 or delete it and load the latter? Can you elucidate on SB action with shimx64 - does it actually examine (integrity) the GRUB boot at all, or just ignore it; does it ignore the Windows boot sector (in which case viruses too would be bypassed) and go directly to Win startup?

    – mako34
    Apr 14 at 2:41

















  • As long as GRUB loads or Windows does that's OK cause I can just reenter BIOS and shut off Sure Boot. The question is, does Windows try to interrogate GRUB for "integrity" (which I suppose it can't), or does it just ignore it to analyze the Windows boot (or is that bypassed by GRUB?)

    – mako34
    Apr 13 at 21:48











  • Are you saying if you install Ubuntu with SB OFF,then it can't really be turned back on since it wasn't installed under proper SB protocols? As I understand it, only problems are with non-standard proprietary drivers so Ubuntu could have problems but Windows should be fine. Fast Start-Up obviously is unnecessary and risky; and Bitlocker scared me from first contact (ship computer with it enabled, where just booting up in Safe Mode can trigger a lock-out??), but I am in an insane threat environment & likely target, so would like Secure Boot, if possible, if it can give any additional protection

    – mako34
    Apr 13 at 22:04











  • An install with secure boot disabled will install the unsigned versions of the bootloader grubx64.efi. Turning secure boot on will then prevent grubx64.efi from booting, and there is no shimx64 either. That's why I like to install with secure boot on, then turn it off if necessary to install third party drivers. The system would then boot with secure boot in either state.

    – ubfan1
    Apr 14 at 1:18











  • @ubfan1 Thanks! I edited the text to make it clearer.

    – user68186
    Apr 14 at 1:27











  • Oh God, so it was stupid to install with SB Off, Ubuntu could say "dual install with SB on but then shut it off if there are boot problems!!" Can I convert grubx64 to shimx64 or delete it and load the latter? Can you elucidate on SB action with shimx64 - does it actually examine (integrity) the GRUB boot at all, or just ignore it; does it ignore the Windows boot sector (in which case viruses too would be bypassed) and go directly to Win startup?

    – mako34
    Apr 14 at 2:41
















As long as GRUB loads or Windows does that's OK cause I can just reenter BIOS and shut off Sure Boot. The question is, does Windows try to interrogate GRUB for "integrity" (which I suppose it can't), or does it just ignore it to analyze the Windows boot (or is that bypassed by GRUB?)

– mako34
Apr 13 at 21:48





As long as GRUB loads or Windows does that's OK cause I can just reenter BIOS and shut off Sure Boot. The question is, does Windows try to interrogate GRUB for "integrity" (which I suppose it can't), or does it just ignore it to analyze the Windows boot (or is that bypassed by GRUB?)

– mako34
Apr 13 at 21:48













Are you saying if you install Ubuntu with SB OFF,then it can't really be turned back on since it wasn't installed under proper SB protocols? As I understand it, only problems are with non-standard proprietary drivers so Ubuntu could have problems but Windows should be fine. Fast Start-Up obviously is unnecessary and risky; and Bitlocker scared me from first contact (ship computer with it enabled, where just booting up in Safe Mode can trigger a lock-out??), but I am in an insane threat environment & likely target, so would like Secure Boot, if possible, if it can give any additional protection

– mako34
Apr 13 at 22:04





Are you saying if you install Ubuntu with SB OFF,then it can't really be turned back on since it wasn't installed under proper SB protocols? As I understand it, only problems are with non-standard proprietary drivers so Ubuntu could have problems but Windows should be fine. Fast Start-Up obviously is unnecessary and risky; and Bitlocker scared me from first contact (ship computer with it enabled, where just booting up in Safe Mode can trigger a lock-out??), but I am in an insane threat environment & likely target, so would like Secure Boot, if possible, if it can give any additional protection

– mako34
Apr 13 at 22:04













An install with secure boot disabled will install the unsigned versions of the bootloader grubx64.efi. Turning secure boot on will then prevent grubx64.efi from booting, and there is no shimx64 either. That's why I like to install with secure boot on, then turn it off if necessary to install third party drivers. The system would then boot with secure boot in either state.

– ubfan1
Apr 14 at 1:18





An install with secure boot disabled will install the unsigned versions of the bootloader grubx64.efi. Turning secure boot on will then prevent grubx64.efi from booting, and there is no shimx64 either. That's why I like to install with secure boot on, then turn it off if necessary to install third party drivers. The system would then boot with secure boot in either state.

– ubfan1
Apr 14 at 1:18













@ubfan1 Thanks! I edited the text to make it clearer.

– user68186
Apr 14 at 1:27





@ubfan1 Thanks! I edited the text to make it clearer.

– user68186
Apr 14 at 1:27













Oh God, so it was stupid to install with SB Off, Ubuntu could say "dual install with SB on but then shut it off if there are boot problems!!" Can I convert grubx64 to shimx64 or delete it and load the latter? Can you elucidate on SB action with shimx64 - does it actually examine (integrity) the GRUB boot at all, or just ignore it; does it ignore the Windows boot sector (in which case viruses too would be bypassed) and go directly to Win startup?

– mako34
Apr 14 at 2:41





Oh God, so it was stupid to install with SB Off, Ubuntu could say "dual install with SB on but then shut it off if there are boot problems!!" Can I convert grubx64 to shimx64 or delete it and load the latter? Can you elucidate on SB action with shimx64 - does it actually examine (integrity) the GRUB boot at all, or just ignore it; does it ignore the Windows boot sector (in which case viruses too would be bypassed) and go directly to Win startup?

– mako34
Apr 14 at 2:41

















draft saved

draft discarded
















































Thanks for contributing an answer to Ask Ubuntu!


  • Please be sure to answer the question. Provide details and share your research!

But avoid


  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.

To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2faskubuntu.com%2fquestions%2f1133563%2fcan-i-re-enable-secure-boot-fast-start-up-or-bitlocker-on-win10-on-dual-boot%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Distance measures on a map of a game The 2019 Stack Overflow Developer Survey Results Are Inmin distance in a graphShortest distance path on contour plotHow to plot a tilted map?Finding points outside of a diskDelaunay link distanceAnnulus from GeoDisks: drawing a ring on a mapNegative Correlation DistanceFind distance along a path (GPS coordinates)Finding position at given distance in a GeoPathMathematics behind distance estimation using camera

How to get a smooth, uniform ParametricPlot of a 2D Region?How to plot a complicated Region?How to exclude a region from ParametricPlotHow discretize a region placing vertices on a specific non-uniform gridHow to transform a Plot or a ParametricPlot into a RegionHow can I get a smooth plot of a bounded region?Smooth ParametricPlot3D with RegionFunction?Smooth border of a region ParametricPlotSmooth region boundarySmooth region plot from list of pointsGet minimum y of a certain x in a region

Genealogie vun de Merowenger Vum Merowech bis zum Chilperich I. | Navigatiounsmenü