# Secure Boot supported/disabled?

**URL:** <https://community.frame.work/t/secure-boot-supported-disabled/4756>\
**Category:** Framework Laptop 13\
**Created:** [August 10, 2021, 6:00am UTC](https://community.frame.work/t/secure-boot-supported-disabled/4756 "2021-08-10T06:00:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Firestar](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/firestar/32/1275_2.png) [@Firestar](https://community.frame.work/u/Firestar)\
**Post date:** [August 10, 2021, 6:00am UTC](https://community.frame.work/t/secure-boot-supported-disabled/4756/1 "2021-08-10T06:00:27Z")

</div>

[Secure Boot](https://docs.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-secure-boot)

If I buy a framework laptop with Windows 10 pre-installed, will the secure boot be opened and can it be turned off?

If I buy a framework laptop with no OS pre-installed, will the secure boot be turned off and will it be automatically turned on if I install a Windows 10 manually by ISO?

PS: As a heavy Manjaro/Arch Linux (which do not support secure boot) user, I do **not** want to see any difference if I disable secure boot when booting. (for example, a bloody-red screen with a lock icon or a sentence reminding you that secure boot is off)

---

<div class="post-metadata">

**Author:** ![Stebalien](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/stebalien/32/854_2.png) [@Stebalien](https://community.frame.work/u/Stebalien)\
**Post date:** [August 10, 2021, 6:59am UTC](https://community.frame.work/t/secure-boot-supported-disabled/4756/2 "2021-08-10T06:59:35Z")

</div>

SecureBoot will be turned on in all cases, but you can turn it off in the bios. If you actually want it to be secure (ish), you’d need to set a bios password (not set by default).

---

<div class="post-metadata">

**Author:** ![jeshikat](https://avatars.discourse-cdn.com/v4/letter/j/e79b87/32.png) [@jeshikat](https://community.frame.work/u/jeshikat)\
**Post date:** [August 10, 2021, 11:11am UTC](https://community.frame.work/t/secure-boot-supported-disabled/4756/3 "2021-08-10T11:11:36Z")

</div>

> [@Firestar](#):
>
> I do **not** want to see any difference if I disable secure boot when booting.

There is no difference in the boot screen with secure boot on/off with either Windows or Linux.

---

<div class="post-metadata">

**Author:** ![darthdomo](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/darthdomo/32/1172_2.png) [@darthdomo](https://community.frame.work/u/darthdomo)\
**Post date:** [August 10, 2021, 2:02pm UTC](https://community.frame.work/t/secure-boot-supported-disabled/4756/4 "2021-08-10T14:02:44Z")

</div>

Just wanted to comment on this:

> [@Firestar](#):
>
> As a heavy Manjaro/Arch Linux (which do not support secure boot)

Arch absolutely supports Secure Boot. It’s not an easy process, but the Arch Wiki has a very good page on how to do it, by signing your own keys.

[https://wiki.archlinux.org/title/Unified\_Extensible\_Firmware\_Interface/Secure\_Boot#Implementing\_Secure\_Boot](https://wiki.archlinux.org/title/Unified_Extensible_Firmware_Interface/Secure_Boot#Implementing_Secure_Boot)

---

<div class="post-metadata">

**Author:** ![JoshuaB](https://avatars.discourse-cdn.com/v4/letter/j/8491ac/32.png) [@JoshuaB](https://community.frame.work/u/JoshuaB)\
**Post date:** [October 4, 2021, 12:53am UTC](https://community.frame.work/t/secure-boot-supported-disabled/4756/5 "2021-10-04T00:53:24Z")

</div>

It’s actually not too hard, but you don’t seem to be able to set the PK using the sbkeysync method on the Framework for some reason. I used **efi-updatevar** and it worked like a champ.

(Arch w/ secure-boot, a sd-tpm2-totp hook, and a unified kernel.)
