Windows 10: One for Kari - Secure boot with HYPER-V question

Discus and support One for Kari - Secure boot with HYPER-V question in Windows 10 Virtualization to solve the problem; Hi there I see that although VMware and VBOX can't do it (they can use UEFI) it seems HYPER-V CAN create a level 2 (type 2) VM which can enable... Discussion in 'Windows 10 Virtualization' started by jimbo45, Mar 24, 2015.

  1. jimbo45 Win User

    One for Kari - Secure boot with HYPER-V question


    Hi there

    I see that although VMware and VBOX can't do it (they can use UEFI) it seems HYPER-V CAN create a level 2 (type 2) VM which can enable secure boot.

    I want to have a go with this on a W2012 Server HOST. Anything special needed for setting up the VM -- want to run a W10 VM where I have the serial number - and I've got a W8 enterprise system too I can use.

    Will the same HYPER-V system work on a W10 Host.

    Cheers
    jimbo

    :)
     
    jimbo45, Mar 24, 2015
    #1
  2. JTDemag12 Win User

    Boot up fail after PC sleep/hybernate

    Not sure how to provide a link to my other issue removing Hyper-V. I think this will be able to copy and paste into a new web page:

    How do I uninstall Hyper-V

    I did look into the Troubleshoot Blue Screen link. check for updates are all ok/up to date.

    Remove hardware: Have added no new hardware. Only activated Virtualization on my processor then disabled it due to my issues with hyper-v and Virtual box.

    Remove Software: Only Microsoft software is of the latest dates. I did install F-Secure from my Charter Spectrum account for PC security but this was before trying out hyper-v. I do believe this security program makes my system slower.

    Clean boot: no have not done this one!!

    Review of info by etylo Sept 2, 2017, I also went intt Device Mgr. and found hyper-v adapters, deleted them. Then looked at the Ethernet adapters, only one there was for Virtual box, left it.
     
    JTDemag12, Mar 24, 2015
    #2
  3. After 32 years is it time to give up on Windows?

    No Hyper-V and no virus checker running on this system. Malwarebytes is the only additional security program running and I've never traced any problem back to it.
     
    Morden2004, Mar 24, 2015
    #3
  4. adamf Win User

    One for Kari - Secure boot with HYPER-V question

    If you set up a type 2 machine you tick Enable secure boot in the firmware tab of settings.

    Works on Windows 10 also.

    In case you are interested (I was looking at your other posts) in Hyper-V the firmware is always user mode so you can add whatever keys you want to allow VM to boot in secure mode (assuming it supports it). TechNet Blogs
     
    adamf, Mar 24, 2015
    #4
  5. jimbo45 Win User
    Hi there

    Thanks for the info.

    However if one can enter any key it rather IMO defeats the whole process !!!!. Presumably IMO the whole point of protected boot is to ONLY allow the OS'es with the requisite key to boot. Otherwise it's a waste of time !!!.

    Seems also Guest non Windows OS'es won't work either then as part of the security is maintained on the HOST.

    Cheers
    jimbo
     
    jimbo45, Mar 24, 2015
    #5
  6. adamf Win User
    It depends whether you are talking about booting a VM or not.

    What MS has suggested recently (although details are still unclear) is to remove the restriction that OEMs must deliver the ability to turn off secure boot on new devices if they want the "designed for Windows" logo. This would mean that if you bought such hardware you could be tied into whatever operating systems they see fit (if and only if the OEM decided to do that). Previously MS said the ability to turn off secure boot was required. That is your host.

    With a VM there are 2 layers - your host and the guest. Assuming you have booted your host you can then define valid keys to allow your guest to run (assuming your guest supports secure boot) as the firmware (seen by the guest) is in user space on the host. By default the host keys will be passed to the guest but you can add more if you want.

    Long and short, for VM's it doesn't (currently) make any difference. For bare metal it is only interesting if you were to buy a new Windows 10 machine where the OEM has decided to restrict secure boot (as is currently the case if you buy a phone) and you wanted to boot something not on the their list. As such devices don't exist yet and MS may change their mind it is a little pointless to discuss that side of it.
     
    adamf, Mar 24, 2015
    #6
  7. Kari Win User
    I have never tried Secure Boot on Hyper-V. Theoretically it should work with Windows 8 and later or Windows Server 2012 and later guests. I have and have had a lot of 2nd generation virtual machines which makes secure boot possible, but as normal Windows 8 or 10 second generation vm fails to boot when the option is selected ("EFI SCSI Device failed secure boot verification"), I always untick the box in vm settings.

    This is one Hyper-V guestion I am totally unable to answer due lack of experience. I read what Adam already posted and have unfortunately nothing to add. Please post about your findings, I at least would be very interested to hear how it went.
     
  8. jimbo45 Win User

    One for Kari - Secure boot with HYPER-V question

    Hi there

    Am travelling tomorrow (Brussels ==>home) but when I get back I'll have a play with it over the weekend if I have enough time.

    Seems an interesting concept of "securing" a VM - however I really want to try if any old key will work and if it's simple to change these. If the user can change these then as I said before it seems a waste of time. By user in this case I mean someone who has access to the HOST HYPER-V machine not the VM.

    I'll probably create a Vanilla VM -- with nothing apart from the default Ms applications and have a play. I think I'll run it first on a W2012 server Host as I know that system is working correctly. W10 might just be to "new" to play with this.

    Cheers
    jimbo
     
    jimbo45, Mar 25, 2015
    #8
  9. adamf Win User
    If you create a new type 2 VM in Hyper-V then secure boot is the default. I just installed 9841 Server (latest version I could find) and it works fine (my host is 10041 Pro).

    I also migrated an Arch installation from VBox (converted the disk to vhdx) and it will not boot with secure boot but whether this is because of the migration or the secure boot I don't know yet. According to their Wiki you can self-sign certificates for secure boot but I've not tried yet as it seems a lot of effort for no benefit I can think of to be honest.
     
    adamf, Apr 5, 2018
    #9
Thema:

One for Kari - Secure boot with HYPER-V question

Loading...
  1. One for Kari - Secure boot with HYPER-V question - Similar Threads - Kari Secure boot

  2. HYPER-V pass thru question (probably for Kari)

    in Windows 10 Virtualization
    HYPER-V pass thru question (probably for Kari): Hi there Question on HYPER-V -- I've a machine with 2 Display port outputs and a standard old fashioned RGB (video type monitor) output -- all 3 are selectable. The 2 Display port outputs are connected via an HDMI switchbox to one monitor with Displayport->HDMI connectors....
  3. Hyper-V questions

    in Windows 10 Virtualization
    Hyper-V questions: In Hyper-V, is there any way to change NEWCOMP to a different name after it's already being used? [img] When I run one of the VMs it shows [img] which I don't like. 139498
  4. Hyper-V Questions

    in Windows 10 Virtualization
    Hyper-V Questions: I've had windows 10 installed on my computer and was running some virtual machines with virtualbox. I heard hyper-v gets better performance, so I enabled it and created virtual machines. I understand that hyper-v is a type 1 hypervisor. Does this mean that since enabling...
  5. HYPER-V question for probably Kari

    in Windows 10 Virtualization
    HYPER-V question for probably Kari: Hi there quick question on HYPER-V probably for @Kari as he's the undisputed champion of HYPER-V around here !!! If I have a VM powered on under HYPER-V can I log off as the Windows user and still have people able to access the HYPER-V VM - assuming of course they have an...
  6. Questions on Windows 10 licensing for a Hyper-V VM

    in Windows 10 Virtualization
    Questions on Windows 10 licensing for a Hyper-V VM: I have a Windows 10 Pro machine which supports virtualization. I want to create a hyper-V VM running Windows 10 as the guest host. I have some questions on licensing and any activation issues that might occur I expect I'll need to buy a 2nd Win 10 license Does it need...
  7. @KARI access Linux HDD's in HYPER-V VM

    in Windows 10 Virtualization
    @KARI access Linux HDD's in HYPER-V VM: Hi there particularly @Kari. I'm playing around now with HYPER-V. I want to access 1 X 9 TB and 1 X 7 TB Linux internal HDD's from a HYPER-V VM (Centos 7). I'm running HOST W10 pro x-64. I've taken the two HDD's offline to the HOST but can't seem to get the VM to...
  8. HYPER-V and ESXI Kari - have you tried this

    in Windows 10 Virtualization
    HYPER-V and ESXI Kari - have you tried this: Hi there has anybody especially @Kari tried creating an ESXI VM on HYPER-V and then attaching VM's to the Esxi VM. I'd imagine if possible the response time would be quite good as Esxi is such a TINY OS. Running esxi as a VM would also get round some of its pickier...
  9. @Kari Hyper-V boot from USB / Micro SD card to load OS from SSD

    in Windows 10 Virtualization
    @Kari Hyper-V boot from USB / Micro SD card to load OS from SSD: Hi there Specially question for Kari -- I've added an SSD to a Microserver (HP gen 8) to the ODD slot. The Bios of this server in AHCI mode only allows boot from USB/Micro SD card or HDD's in slot 1/2. I want all 4 HDD's as data disks so I was wondering if I could use GRUB...
  10. Hyper-V - Native Boot VHD

    in Windows 10 Tutorials
    Hyper-V - Native Boot VHD: How to: Hyper-V - Native Boot VHD [img] Information First a quote from Microsoft Developer Network's (MSDN) support article: Native Boot allows you to create a virtual hard disk (VHD), install Windows to it, and then boot it up, either on your PC side-by-side with...
Tags: