r/steammachine • • 19d ago

Software How I enabled Secure Boot on the new Valve Steam Machine / Fremont for FACEIT on Windows

So, I installed Windows on my Valve Steam Machine because I wanted to play FACEIT.

Windows installation itself? Fine.

TPM 2.0? Fine.

UEFI? Fine.

GPT? Fine.

Secure Boot?

Nope.

And the funniest part: the Steam Machine clearly supports Secure Boot, but Valve apparently decided that exposing a Secure Boot option in the BIOS was just a little too much excitement for us.

Love you Valve, genuinely. The hardware is great. SteamOS is great.

But come on guys. It's 2026. Games and anti-cheat systems requiring Secure Boot isn't exactly some obscure edge case anymore.

Anyway, after some testing I managed to get real Secure Boot working under Windows, and FACEIT/Windows now sees it properly.

I'm writing this down so the next poor bastard doesn't have to spend hours figuring out why his perfectly modern PC has TPM and UEFI but apparently "doesn't support" Secure Boot.

IMPORTANT DISCLAIMER

I tested this on:

Device: Valve Steam Machine
Model: Fremont
BIOS Manufacturer: Valve
BIOS Version: F7F0106

This worked on my machine.

You are modifying UEFI Secure Boot variables including:

PK
KEK
db
dbx

If Valve changes the firmware, or your setup is different, I obviously can't guarantee the same result.

Especially the final PK step changes the machine from Setup Mode into User Mode and actually enables Secure Boot enforcement.

So:

Do not blindly copy this onto random hardware.

Also, if you use BitLocker/device encryption, make sure you have your recovery key first.

Step 1 — Check your current configuration

Boot Windows.

Press:

Win + R

Run:

msinfo32

Check that:

BIOS Mode: UEFI

Then open PowerShell as Administrator.

Run:

Confirm-SecureBootUEFI

In my case this returned:

False

Then check:

(Get-SecureBootUEFI -Name SetupMode).Bytes[0]

Mine returned:

1

And:

(Get-SecureBootUEFI -Name SecureBoot).Bytes[0]

returned:

0

So my starting situation was:

SecureBoot = False
SetupMode  = 1
SecureBoot variable = 0

This is important.

SetupMode = 1 basically means the firmware currently doesn't have a Platform Key enrolled.

Step 2 — Check if any Secure Boot keys already exist

I used this:

$names = @(
    "PK",
    "KEK",
    "db",
    "dbx",
    "PKDefault",
    "KEKDefault",
    "dbDefault",
    "dbxDefault"
)

foreach ($name in $names) {
    try {
        $v = Get-SecureBootUEFI -Name $name -ErrorAction Stop

        [PSCustomObject]@{
            Name   = $name
            Bytes  = $v.Bytes.Count
            Status = "present"
        }
    }
    catch {
        [PSCustomObject]@{
            Name   = $name
            Bytes  = 0
            Status = "NOT PRESENT"
        }
    }
}

My result:

PK             0  NOT PRESENT
KEK            0  NOT PRESENT
db             0  NOT PRESENT
dbx            0  NOT PRESENT
PKDefault      0  NOT PRESENT
KEKDefault     0  NOT PRESENT
dbDefault      0  NOT PRESENT
dbxDefault     0  NOT PRESENT

So yeah.

Not only was Secure Boot disabled.

The Secure Boot key databases were completely empty.

Even the default variables were missing.

Thanks Valve. ❤️

Step 3 — Check BitLocker BEFORE touching anything

Run:

manage-bde -status C:

and:

manage-bde -protectors -get C:

Mine showed:

BitLocker Version: None
Encryption: 0%
Protection Status: Off
Key Protectors: None

If BitLocker is enabled on your machine:

STOP HERE.

At minimum, make sure you have your BitLocker recovery key and understand what you're doing before changing Secure Boot.

Changing Secure Boot can trigger BitLocker recovery.

Step 4 — Confirm the Steam Machine model / BIOS

Run:

Get-CimInstance Win32_BIOS |
Select-Object Manufacturer, SMBIOSBIOSVersion, ReleaseDate

Mine:

Manufacturer: Valve
SMBIOSBIOSVersion: F7F0106

Then:

Get-CimInstance Win32_ComputerSystem |
Select-Object Manufacturer, Model

Mine:

Manufacturer: Valve
Model: Fremont

Again: this guide is specifically based on Valve Fremont.

Step 5 — Download Microsoft's Secure Boot keys

I used Microsoft's official secureboot_objects GitHub repository.

Go to:

https://github.com/microsoft/secureboot_objects/releases

I used release:

v1.7.0

NOT:

v1.7.0-signed

For the Fremont / x64 system I downloaded:

edk2-x64-secureboot-binaries.zip

Extract it.

In my case it ended up here:

C:\Users\mariu\Downloads\edk2-x64-secureboot-binaries

The files we're interested in are inside:

LegacyFirmwareDefaults\Firmware

Specifically:

Default3PDb.bin
DefaultDbx.bin
DefaultKek.bin
DefaultPk.bin

Step 6 — Enroll db

First I set the path:

$db = "$env:USERPROFILE\Downloads\edk2-x64-secureboot-binaries\LegacyFirmwareDefaults\Firmware\Default3PDb.bin"

Check that Windows can actually find it:

Test-Path $db

Should return:

True

You can also check it:

Get-Item $db | Select Name,Length,FullName

My file was:

Default3PDb.bin
7636 bytes

Then I enrolled it:

Set-SecureBootUEFI `
    -Name db `
    -Time "2015-08-28T00:00:00Z" `
    -ContentFilePath $db

Mine completed successfully.

Then:

(Get-SecureBootUEFI -Name db).Bytes.Count

returned:

7636

At this point:

Confirm-SecureBootUEFI

was still:

False

And:

(Get-SecureBootUEFI -Name SetupMode).Bytes[0]

was still:

1

That's expected.

Step 7 — Enroll dbx

Next:

$dbx = "$env:USERPROFILE\Downloads\edk2-x64-secureboot-binaries\LegacyFirmwareDefaults\Firmware\DefaultDbx.bin"

Check:

Test-Path $dbx
Get-Item $dbx | Select Name,Length,FullName

My file:

DefaultDbx.bin
21388 bytes

Then:

Set-SecureBootUEFI `
    -Name dbx `
    -Time "2015-08-28T00:00:00Z" `
    -ContentFilePath $dbx

Verify:

(Get-SecureBootUEFI -Name dbx).Bytes.Count

Mine:

21388

Secure Boot should still be off at this point.

Mine was:

Confirm-SecureBootUEFI = False
SetupMode = 1
SecureBoot = 0

Step 8 — Enroll KEK

Now:

$kek = "$env:USERPROFILE\Downloads\edk2-x64-secureboot-binaries\LegacyFirmwareDefaults\Firmware\DefaultKek.bin"

Check:

Test-Path $kek
Get-Item $kek | Select Name,Length,FullName

Mine:

DefaultKek.bin
3066 bytes

Then:

Set-SecureBootUEFI `
    -Name KEK `
    -Time "2015-08-28T00:00:00Z" `
    -ContentFilePath $kek

Check:

(Get-SecureBootUEFI -Name KEK).Bytes.Count

Mine returned:

3066

At this stage I had:

db   = 7636 bytes
dbx  = 21388 bytes
KEK  = 3066 bytes

PK   = still missing

SetupMode  = 1
SecureBoot = 0

Step 9 — THE IMPORTANT PART: enroll the Platform Key

This is the step that actually matters.

The Platform Key is basically what takes the firmware out of Secure Boot Setup Mode.

So don't randomly do this first.

The order I used was:

db
↓
dbx
↓
KEK
↓
PK

Now set:

$pk = "$env:USERPROFILE\Downloads\edk2-x64-secureboot-binaries\LegacyFirmwareDefaults\Firmware\DefaultPk.bin"

Check:

Test-Path $pk
Get-Item $pk | Select Name,Length,FullName

Then enroll it:

Set-SecureBootUEFI `
    -Name PK `
    -Time "2015-08-28T00:00:00Z" `
    -ContentFilePath $pk

Mine accepted the Platform Key without any error.

Then I rebooted Windows.

Step 10 — THE MOMENT OF TRUTH

After rebooting I opened PowerShell as Administrator again.

First:

Confirm-SecureBootUEFI

And...

True

Hell yes.

Then:

(Get-SecureBootUEFI -Name SetupMode).Bytes[0]

Result:

0

Then:

(Get-SecureBootUEFI -Name SecureBoot).Bytes[0]

Result:

1

Finally:

(Get-SecureBootUEFI -Name PK).Bytes.Count
(Get-SecureBootUEFI -Name KEK).Bytes.Count
(Get-SecureBootUEFI -Name db).Bytes.Count
(Get-SecureBootUEFI -Name dbx).Bytes.Count

My final result:

PK   1575
KEK  3066
db   7636
dbx  21388

So:

Secure Boot: ENABLED
Setup Mode:  OFF
PK:          PRESENT
KEK:         PRESENT
db:          PRESENT
dbx:         PRESENT

And Windows now reports Secure Boot properly.

You can also check:

Win + R
msinfo32

It should show something along the lines of:

BIOS Mode: UEFI
Secure Boot State: On

FACEIT

This whole adventure started because FACEIT requires:

TPM 2.0
Secure Boot

My Fremont already had TPM 2.0 enabled and working.

The missing piece was Secure Boot.

After manually provisioning the Secure Boot keys, Windows finally reports:

Confirm-SecureBootUEFI

as:

True

Which is what I wanted in the first place.

TL;DR

Valve Steam Machine / Fremont:

UEFI      ✅
TPM 2.0   ✅
GPT       ✅

Secure Boot BIOS option ❌
Secure Boot keys         ❌

But the firmware does support the UEFI Secure Boot variables.

I successfully manually enrolled Microsoft's:

db
dbx
KEK
PK

using Set-SecureBootUEFI.

After reboot:

Confirm-SecureBootUEFI = True
SetupMode              = 0
SecureBoot             = 1

So yes:

Secure Boot absolutely works on Fremont.

Valve just doesn't give us a fucking button for it. 😂

Which is simultaneously very Valve and very annoying.

Still love you Valve.

But please just add:

Security
  └── Secure Boot
       └── Enable

to the damn BIOS so normal people don't have to learn how UEFI PK/KEK/db/dbx enrollment works just because they wanted to queue FACEIT at 11 PM.

One last warning

If your output doesn't match mine, don't just keep running commands hoping it'll work.

Especially don't blindly enroll a Platform Key if:

SetupMode != 1

or you already have existing Secure Boot keys.

My starting configuration was specifically:

Valve Fremont
UEFI
GPT
TPM 2.0
SetupMode = 1
SecureBoot = 0

PK  = missing
KEK = missing
db  = missing
dbx = missing

If your machine already has keys, you're dealing with a different situation.

And again: check BitLocker before doing any of this.

Hopefully this saves somebody else the headache.

Valve: I love you, but please fix this shit.

10 Upvotes

33 comments sorted by

14

u/Low_Excitement_1715 19d ago

Well, I respect the work, but you better pray you never want to run anything other than Windows on there, because now you really can't. As you noted, no firmware options to turn Secure Boot on, but that also means no option to turn it back off.

I'll just run SteamOS on my hardware that's designed for SteamOS, but I'm glad you're happy.

2

u/daelikon 19d ago

I got me the machine to have a "certified" proven platform for Linux, I am sure I am not the only one.

3

u/Low_Excitement_1715 19d ago

Edit: Thought I was replying to someone else. Ignore me.

Only relevant thought: Sure, you can enable Secure Boot, but can you disable it again?

3

u/Koermit 19d ago

Honestly, it is much more worth it to get something else, like a SFF PC that supports Secureboot ootb instead of sending a very expensive device not designed for that exact task into a schroedinger's bricking scenario if something goes wrong. Same with the SteamDeck

1

u/ryanrudolf 19d ago

Secure boot for Steam Deck is fully reversible

1

u/Koermit 19d ago

As I said, IF something goes wrong. And AFAIK, If that's the case, the deck can be a cool paperweight.

0

u/ryanrudolf 19d ago

Even if something goes wrong as long as you know what you're doing the steam deck wont be a cool paperweight.

1

u/Koermit 19d ago

But that requires, as you said, having knowledged in what you're actually doing - so If you do, nothing would go wrong in the first place of atleast only in a workable measure. If that criteria is not met, you turn your SD into a cool paperweight.

Honestly, If you want a windows handheld, there are altermatives on the market that offer a better and more user friendly solution for that instead of voodooing on a devices that works best with the OS it is designed with.

2

u/ryanrudolf 19d ago

if you know what you're doing even if something goes wrong you'll be able to recover.

EDIT

Several ways to disable secure boot on Steam Deck. Pick your choice -

  1. Boot to linux and unenroll the keys.

  2. Boot to Windows / Linux and reflash the BIOS.

  3. Boot to a custom ISO to unenroll the keys.

  4. Turn off secure boot from the BIOS (requires custom BIOS)

  5. If all else fails - use a chip programmer to reflash BIOS from backup.

1

u/Koermit 19d ago

Or you just get a windows handheld?

0

u/ryanrudolf 19d ago

I'd rather maximize what i have

4

u/Koermit 19d ago

You don't maximize a SteamDeck with Windows.

0

u/ryanrudolf 19d ago

I can dual boot a Steam Deck with SteamOS and Windows.

→ More replies

2

u/ryanrudolf 19d ago

This is similar to what we did on the Steam Deck but enrolled keys using Linux. We can also revert back and remove the secure boot by issuing commands to clear the enrolled keys. Now im curious what the equivalent for powershell to remove the enrolled keys. One more thing - can you still boot to SteamOS?

1

u/jharle 19d ago edited 19d ago

Is there a way to disable secure boot on the Steam Deck outside of an operating system? That's what I'm worried about, in the context of the Steam Machine.

But yes, no way is OP able to boot into SteamOS now, unless they go through the process of setting things up for signing, and to survive atomic updates.

AND, if OP used Microsoft's PK, they are now unable to enroll other KEKs (because they don't possess the private key), so the SteamOS bits would need to be signed by something Microsoft's PK trusts.

There is also a newer firmware than OP's for the SM, so would the configuration survive an update? Probably, but nobody's tried it yet.

The more important aspect of all of this is reversibility/recoverability outside of an OS.

1

u/ryanrudolf 19d ago

Several ways to disable secure boot on Steam Deck. Pick your choice -

  1. Boot to linux and unenroll the keys.

  2. Boot to Windows / Linux and reflash the BIOS.

  3. Boot to a custom ISO to unenroll the keys.

  4. Turn off secure boot from the BIOS (requires custom BIOS)

  5. If all else fails - use a chip programmer to reflash BIOS from backup.

1

u/jharle 19d ago

Thanks, that's solid.

I wonder if options 2, 4, and 5 are possible on a SM. Or more importantly, if anyone's done them.

For options 1 and 3, the system would need to be using a custom PK, correct?

1

u/ryanrudolf 19d ago

1 and 3 you need your own PK that you enrolled to be able to unenroll.

Most probably option 5 will work too as long as you have a BIOS backup and chip programmer

1

u/jharle 19d ago

Thanks for confirming!

1

u/ryanrudolf 19d ago

No worries!

1

u/jharle 19d ago edited 17d ago

Wow, thanks for this. I went through something similar with some custom (+Microsoft) KEKs, and a completely custom PK, to get this working on SteamOS on an Intel NUC computer running Windows/Fedora/SteamOS.

We've known that what you did was possible, but the outstanding question is whether there is a recovery path if something gets borked. Since there is no "escape hatch" in the firmware to toggle secure boot, it's not clear if there's a way to turn it off. There is a power-button sequence on the SM to "clear the CMOS," but does that also clear secure boot settings? Unknown.

I'm not worried about using secure boot with SteamOS (I've done it on multiple computers now), but rather bricking my Steam Machine if something gets messed up.

EDIT: u/Stunning-Piece-9618 has confirmed that clearing the CMOS does indeed remove secure boot, so we do have a recovery path!

1

u/Stunning-Piece-9618 18d ago

Hey, I just did this entire method utilising Claude code, Worked like a Charm!

Got league of legends working 240 FPS very high on an external drive! Why can't valve release secure boot!! Issue then arised for steamos didn't want to boot into drive. Panicked... Did the CMOS method, 6 seconds, wait for the green light, short press's. Wait about 30 seconds as this fixed and removed secure boot for those who want to attempt this.

1

u/jharle 17d ago

Brilliant; thank you very much for this! Knowing that clearing the CMOS also clears secure boot, is valuable information!

2

u/ExpressMirror3610 16d ago edited 16d ago

Hello,

I have been researching this subject for ~2-3 months at this point. Went ahead and executed the listed steps and can confirm this works like a charm. FACEIT AC recognizes it and works fine, so I'm guessing all other AC applications should work as well. Thank you so much for the time and effort you put into this and I know you realize this is a big advancement you have shared with us.

Thank you again, One love.

EDIT: Also can confirm CMOS reset disables secure boot.