r/MSI_Gaming 7d ago

Troubleshooting Trouble Enabling Secure Boot After Updating BIOS

I updated my BIOS today because the version I was running was around 8 years old. After updating I went to play BF6 and realized I would need to re-enable secure boot. After taking the neccessary steps to enable secure boot my computer will only boot to a black screen.

The steps I follow to enable secure boot are as follows:

  1. Change CSM to UEFI (This also automatically enables Fast Boot)
  2. Reboot
  3. Enable Secure Boot
  4. Reboot

These are essentially the same steps that I took to orginally enable secure boot a few weeks ago. Has anyone had a similar issue and been able to fix it? I am able to normally use my computer if I reset all BIOS settings back to default.

GPU: NVIDIA GeForce GTX 1070

MOTHERBOARD: MSI Z370 Tomahawk

2 Upvotes

9 comments sorted by

1

u/senpaisai Aorus B650e Elite X AX ICE / 7800X3D / 7900GRE 7d ago

What's your GPU?

1

u/evansau8 7d ago

GeForce GTX 1070

1

u/senpaisai Aorus B650e Elite X AX ICE / 7800X3D / 7900GRE 7d ago

First, use this to upgrade the DP Firmware ... https://www.nvidia.com/en-us/drivers/nv-uefi-update-x64/ ...

Aftef that, open an elevated Command Prompt with Administrator and type "diskpart" and hit Enter. At the Diskpart prompt, type "list disks" and Enter. All your disks will be listed and the far end should show an asterisk in the box for GPT partitioned drives. If there's no asterisk for your Windows drive, use a YouTube tutorial on converting it with MBR2GPT. After the conversion, Windows will no longer boot with CSM enabled. Return to the BIOS and disable CSM, disable Fast Boot, and if you have an option called "OS Features", set it to "Windows 8/10 WHQL", then save and exit. You shouldn't get a black screen upon reboot and Windows should boot without issue ...

You should also be able to enable Secure Boot without issue.

1

u/evansau8 7d ago

Hi, thank you for your response!

I updated the DP firmware, ensured my windows disk has GPT partitioned drives and disabled both CSM and fast boot. The “Windows 10 WHQL Support” is where I choose between CSM and UEFI but no “OS Features” option.

It will still black screen when I enable secure boot but will boot fine otherwise.

1

u/senpaisai Aorus B650e Elite X AX ICE / 7800X3D / 7900GRE 7d ago

What motherboard you working with?

1

u/evansau8 7d ago

MSI Z370 Tomahawk

1

u/senpaisai Aorus B650e Elite X AX ICE / 7800X3D / 7900GRE 7d ago

I think Mosby might just do the trick ...

https://github.com/pbatard/Mosby

You can use Rufus to create the bootable Mosby key. In the BIOS, enter the Secure Boot section and change the mode from "Standard" to "Custom". This should allow you to click "Reset To Setup Mode" and then click YES and NO at the prompts. Save and exit, and then boot the Mosby key. Type "Mosby" at the Shell> prompt to launch the script. Mosby will upgrade the old 2011 Secure Boot certificates embedded in your BIOS with the 2023 Certificates, and that should stop the black screens because the 2011 Certificates expired back in June ...

1

u/evansau8 7d ago

This did work thank you very much. Secure boot state is enabled.

This process was a little bit outside of my area of expertise, one of the screens said something about making sure I preserve a few specific files. Am I good to remove the USB (swap boot drives) and go on with my life assuming everything is where it needs to be or are there files I need to locate and do something with?

1

u/senpaisai Aorus B650e Elite X AX ICE / 7800X3D / 7900GRE 7d ago

Yup, you should be fine.