[qubes-users] Secure Boot Violation

Hi Ulrich,

Indeed, secure boot is not supported by Qubes OS 4.3, nor any prior version to my knowledge, mainly because it is not supported by Xen; but also because secure boot is not an amazing system. Quoting the Heads developer:
"What's wrong with UEFI Secure Boot?
Can't audit it, signing keys are controlled by vendors, doesn't handle hand off in all cases, depends on possible leaked keys."

If you want an alternative, you have Heads (https://trmm.net/Heads/,https://osresearch.net/) or Anti evil maid (Anti evil maid (AEM) — Qubes OS Documentation).

You may want to check the following:

Kindly,
Shuos Jedao

3 Likes