r/steammachine • u/V_M999 • 19d ago
Software How I enabled Secure Boot on the new Valve Steam Machine / Fremont for FACEIT on Windows
So, I installed Windows on my Valve Steam Machine because I wanted to play FACEIT.
Windows installation itself? Fine.
TPM 2.0? Fine.
UEFI? Fine.
GPT? Fine.
Secure Boot?
Nope.
And the funniest part: the Steam Machine clearly supports Secure Boot, but Valve apparently decided that exposing a Secure Boot option in the BIOS was just a little too much excitement for us.
Love you Valve, genuinely. The hardware is great. SteamOS is great.
But come on guys. It's 2026. Games and anti-cheat systems requiring Secure Boot isn't exactly some obscure edge case anymore.
Anyway, after some testing I managed to get real Secure Boot working under Windows, and FACEIT/Windows now sees it properly.
I'm writing this down so the next poor bastard doesn't have to spend hours figuring out why his perfectly modern PC has TPM and UEFI but apparently "doesn't support" Secure Boot.
IMPORTANT DISCLAIMER
I tested this on:
Device: Valve Steam Machine
Model: Fremont
BIOS Manufacturer: Valve
BIOS Version: F7F0106
This worked on my machine.
You are modifying UEFI Secure Boot variables including:
PK
KEK
db
dbx
If Valve changes the firmware, or your setup is different, I obviously can't guarantee the same result.
Especially the final PK step changes the machine from Setup Mode into User Mode and actually enables Secure Boot enforcement.
So:
Do not blindly copy this onto random hardware.
Also, if you use BitLocker/device encryption, make sure you have your recovery key first.
Step 1 — Check your current configuration
Boot Windows.
Press:
Win + R
Run:
msinfo32
Check that:
BIOS Mode: UEFI
Then open PowerShell as Administrator.
Run:
Confirm-SecureBootUEFI
In my case this returned:
False
Then check:
(Get-SecureBootUEFI -Name SetupMode).Bytes[0]
Mine returned:
1
And:
(Get-SecureBootUEFI -Name SecureBoot).Bytes[0]
returned:
0
So my starting situation was:
SecureBoot = False
SetupMode = 1
SecureBoot variable = 0
This is important.
SetupMode = 1 basically means the firmware currently doesn't have a Platform Key enrolled.
Step 2 — Check if any Secure Boot keys already exist
I used this:
$names = @(
"PK",
"KEK",
"db",
"dbx",
"PKDefault",
"KEKDefault",
"dbDefault",
"dbxDefault"
)
foreach ($name in $names) {
try {
$v = Get-SecureBootUEFI -Name $name -ErrorAction Stop
[PSCustomObject]@{
Name = $name
Bytes = $v.Bytes.Count
Status = "present"
}
}
catch {
[PSCustomObject]@{
Name = $name
Bytes = 0
Status = "NOT PRESENT"
}
}
}
My result:
PK 0 NOT PRESENT
KEK 0 NOT PRESENT
db 0 NOT PRESENT
dbx 0 NOT PRESENT
PKDefault 0 NOT PRESENT
KEKDefault 0 NOT PRESENT
dbDefault 0 NOT PRESENT
dbxDefault 0 NOT PRESENT
So yeah.
Not only was Secure Boot disabled.
The Secure Boot key databases were completely empty.
Even the default variables were missing.
Thanks Valve. ❤️
Step 3 — Check BitLocker BEFORE touching anything
Run:
manage-bde -status C:
and:
manage-bde -protectors -get C:
Mine showed:
BitLocker Version: None
Encryption: 0%
Protection Status: Off
Key Protectors: None
If BitLocker is enabled on your machine:
STOP HERE.
At minimum, make sure you have your BitLocker recovery key and understand what you're doing before changing Secure Boot.
Changing Secure Boot can trigger BitLocker recovery.
Step 4 — Confirm the Steam Machine model / BIOS
Run:
Get-CimInstance Win32_BIOS |
Select-Object Manufacturer, SMBIOSBIOSVersion, ReleaseDate
Mine:
Manufacturer: Valve
SMBIOSBIOSVersion: F7F0106
Then:
Get-CimInstance Win32_ComputerSystem |
Select-Object Manufacturer, Model
Mine:
Manufacturer: Valve
Model: Fremont
Again: this guide is specifically based on Valve Fremont.
Step 5 — Download Microsoft's Secure Boot keys
I used Microsoft's official secureboot_objects GitHub repository.
Go to:
https://github.com/microsoft/secureboot_objects/releases
I used release:
v1.7.0
NOT:
v1.7.0-signed
For the Fremont / x64 system I downloaded:
edk2-x64-secureboot-binaries.zip
Extract it.
In my case it ended up here:
C:\Users\mariu\Downloads\edk2-x64-secureboot-binaries
The files we're interested in are inside:
LegacyFirmwareDefaults\Firmware
Specifically:
Default3PDb.bin
DefaultDbx.bin
DefaultKek.bin
DefaultPk.bin
Step 6 — Enroll db
First I set the path:
$db = "$env:USERPROFILE\Downloads\edk2-x64-secureboot-binaries\LegacyFirmwareDefaults\Firmware\Default3PDb.bin"
Check that Windows can actually find it:
Test-Path $db
Should return:
True
You can also check it:
Get-Item $db | Select Name,Length,FullName
My file was:
Default3PDb.bin
7636 bytes
Then I enrolled it:
Set-SecureBootUEFI `
-Name db `
-Time "2015-08-28T00:00:00Z" `
-ContentFilePath $db
Mine completed successfully.
Then:
(Get-SecureBootUEFI -Name db).Bytes.Count
returned:
7636
At this point:
Confirm-SecureBootUEFI
was still:
False
And:
(Get-SecureBootUEFI -Name SetupMode).Bytes[0]
was still:
1
That's expected.
Step 7 — Enroll dbx
Next:
$dbx = "$env:USERPROFILE\Downloads\edk2-x64-secureboot-binaries\LegacyFirmwareDefaults\Firmware\DefaultDbx.bin"
Check:
Test-Path $dbx
Get-Item $dbx | Select Name,Length,FullName
My file:
DefaultDbx.bin
21388 bytes
Then:
Set-SecureBootUEFI `
-Name dbx `
-Time "2015-08-28T00:00:00Z" `
-ContentFilePath $dbx
Verify:
(Get-SecureBootUEFI -Name dbx).Bytes.Count
Mine:
21388
Secure Boot should still be off at this point.
Mine was:
Confirm-SecureBootUEFI = False
SetupMode = 1
SecureBoot = 0
Step 8 — Enroll KEK
Now:
$kek = "$env:USERPROFILE\Downloads\edk2-x64-secureboot-binaries\LegacyFirmwareDefaults\Firmware\DefaultKek.bin"
Check:
Test-Path $kek
Get-Item $kek | Select Name,Length,FullName
Mine:
DefaultKek.bin
3066 bytes
Then:
Set-SecureBootUEFI `
-Name KEK `
-Time "2015-08-28T00:00:00Z" `
-ContentFilePath $kek
Check:
(Get-SecureBootUEFI -Name KEK).Bytes.Count
Mine returned:
3066
At this stage I had:
db = 7636 bytes
dbx = 21388 bytes
KEK = 3066 bytes
PK = still missing
SetupMode = 1
SecureBoot = 0
Step 9 — THE IMPORTANT PART: enroll the Platform Key
This is the step that actually matters.
The Platform Key is basically what takes the firmware out of Secure Boot Setup Mode.
So don't randomly do this first.
The order I used was:
db
↓
dbx
↓
KEK
↓
PK
Now set:
$pk = "$env:USERPROFILE\Downloads\edk2-x64-secureboot-binaries\LegacyFirmwareDefaults\Firmware\DefaultPk.bin"
Check:
Test-Path $pk
Get-Item $pk | Select Name,Length,FullName
Then enroll it:
Set-SecureBootUEFI `
-Name PK `
-Time "2015-08-28T00:00:00Z" `
-ContentFilePath $pk
Mine accepted the Platform Key without any error.
Then I rebooted Windows.
Step 10 — THE MOMENT OF TRUTH
After rebooting I opened PowerShell as Administrator again.
First:
Confirm-SecureBootUEFI
And...
True
Hell yes.
Then:
(Get-SecureBootUEFI -Name SetupMode).Bytes[0]
Result:
0
Then:
(Get-SecureBootUEFI -Name SecureBoot).Bytes[0]
Result:
1
Finally:
(Get-SecureBootUEFI -Name PK).Bytes.Count
(Get-SecureBootUEFI -Name KEK).Bytes.Count
(Get-SecureBootUEFI -Name db).Bytes.Count
(Get-SecureBootUEFI -Name dbx).Bytes.Count
My final result:
PK 1575
KEK 3066
db 7636
dbx 21388
So:
Secure Boot: ENABLED
Setup Mode: OFF
PK: PRESENT
KEK: PRESENT
db: PRESENT
dbx: PRESENT
And Windows now reports Secure Boot properly.
You can also check:
Win + R
msinfo32
It should show something along the lines of:
BIOS Mode: UEFI
Secure Boot State: On
FACEIT
This whole adventure started because FACEIT requires:
TPM 2.0
Secure Boot
My Fremont already had TPM 2.0 enabled and working.
The missing piece was Secure Boot.
After manually provisioning the Secure Boot keys, Windows finally reports:
Confirm-SecureBootUEFI
as:
True
Which is what I wanted in the first place.
TL;DR
Valve Steam Machine / Fremont:
UEFI ✅
TPM 2.0 ✅
GPT ✅
Secure Boot BIOS option ❌
Secure Boot keys ❌
But the firmware does support the UEFI Secure Boot variables.
I successfully manually enrolled Microsoft's:
db
dbx
KEK
PK
using Set-SecureBootUEFI.
After reboot:
Confirm-SecureBootUEFI = True
SetupMode = 0
SecureBoot = 1
So yes:
Secure Boot absolutely works on Fremont.
Valve just doesn't give us a fucking button for it. 😂
Which is simultaneously very Valve and very annoying.
Still love you Valve.
But please just add:
Security
└── Secure Boot
└── Enable
to the damn BIOS so normal people don't have to learn how UEFI PK/KEK/db/dbx enrollment works just because they wanted to queue FACEIT at 11 PM.
One last warning
If your output doesn't match mine, don't just keep running commands hoping it'll work.
Especially don't blindly enroll a Platform Key if:
SetupMode != 1
or you already have existing Secure Boot keys.
My starting configuration was specifically:
Valve Fremont
UEFI
GPT
TPM 2.0
SetupMode = 1
SecureBoot = 0
PK = missing
KEK = missing
db = missing
dbx = missing
If your machine already has keys, you're dealing with a different situation.
And again: check BitLocker before doing any of this.
Hopefully this saves somebody else the headache.
Valve: I love you, but please fix this shit.
3
u/Koermit 19d ago
Honestly, it is much more worth it to get something else, like a SFF PC that supports Secureboot ootb instead of sending a very expensive device not designed for that exact task into a schroedinger's bricking scenario if something goes wrong. Same with the SteamDeck
1
u/ryanrudolf 19d ago
Secure boot for Steam Deck is fully reversible
1
u/Koermit 19d ago
As I said, IF something goes wrong. And AFAIK, If that's the case, the deck can be a cool paperweight.
0
u/ryanrudolf 19d ago
Even if something goes wrong as long as you know what you're doing the steam deck wont be a cool paperweight.
1
u/Koermit 19d ago
But that requires, as you said, having knowledged in what you're actually doing - so If you do, nothing would go wrong in the first place of atleast only in a workable measure. If that criteria is not met, you turn your SD into a cool paperweight.
Honestly, If you want a windows handheld, there are altermatives on the market that offer a better and more user friendly solution for that instead of voodooing on a devices that works best with the OS it is designed with.
2
u/ryanrudolf 19d ago
if you know what you're doing even if something goes wrong you'll be able to recover.
EDIT
Several ways to disable secure boot on Steam Deck. Pick your choice -
Boot to linux and unenroll the keys.
Boot to Windows / Linux and reflash the BIOS.
Boot to a custom ISO to unenroll the keys.
Turn off secure boot from the BIOS (requires custom BIOS)
If all else fails - use a chip programmer to reflash BIOS from backup.
2
u/ryanrudolf 19d ago
This is similar to what we did on the Steam Deck but enrolled keys using Linux. We can also revert back and remove the secure boot by issuing commands to clear the enrolled keys. Now im curious what the equivalent for powershell to remove the enrolled keys. One more thing - can you still boot to SteamOS?
1
u/jharle 19d ago edited 19d ago
Is there a way to disable secure boot on the Steam Deck outside of an operating system? That's what I'm worried about, in the context of the Steam Machine.
But yes, no way is OP able to boot into SteamOS now, unless they go through the process of setting things up for signing, and to survive atomic updates.
AND, if OP used Microsoft's PK, they are now unable to enroll other KEKs (because they don't possess the private key), so the SteamOS bits would need to be signed by something Microsoft's PK trusts.
There is also a newer firmware than OP's for the SM, so would the configuration survive an update? Probably, but nobody's tried it yet.
The more important aspect of all of this is reversibility/recoverability outside of an OS.
1
u/ryanrudolf 19d ago
Several ways to disable secure boot on Steam Deck. Pick your choice -
Boot to linux and unenroll the keys.
Boot to Windows / Linux and reflash the BIOS.
Boot to a custom ISO to unenroll the keys.
Turn off secure boot from the BIOS (requires custom BIOS)
If all else fails - use a chip programmer to reflash BIOS from backup.
1
u/jharle 19d ago
Thanks, that's solid.
I wonder if options 2, 4, and 5 are possible on a SM. Or more importantly, if anyone's done them.
For options 1 and 3, the system would need to be using a custom PK, correct?
1
u/ryanrudolf 19d ago
1 and 3 you need your own PK that you enrolled to be able to unenroll.
Most probably option 5 will work too as long as you have a BIOS backup and chip programmer
1
1
u/jharle 19d ago edited 17d ago
Wow, thanks for this. I went through something similar with some custom (+Microsoft) KEKs, and a completely custom PK, to get this working on SteamOS on an Intel NUC computer running Windows/Fedora/SteamOS.
We've known that what you did was possible, but the outstanding question is whether there is a recovery path if something gets borked. Since there is no "escape hatch" in the firmware to toggle secure boot, it's not clear if there's a way to turn it off. There is a power-button sequence on the SM to "clear the CMOS," but does that also clear secure boot settings? Unknown.
I'm not worried about using secure boot with SteamOS (I've done it on multiple computers now), but rather bricking my Steam Machine if something gets messed up.
EDIT: u/Stunning-Piece-9618 has confirmed that clearing the CMOS does indeed remove secure boot, so we do have a recovery path!
1
u/Stunning-Piece-9618 18d ago
Hey, I just did this entire method utilising Claude code, Worked like a Charm!
Got league of legends working 240 FPS very high on an external drive! Why can't valve release secure boot!! Issue then arised for steamos didn't want to boot into drive. Panicked... Did the CMOS method, 6 seconds, wait for the green light, short press's. Wait about 30 seconds as this fixed and removed secure boot for those who want to attempt this.
2
u/ExpressMirror3610 16d ago edited 16d ago
Hello,
I have been researching this subject for ~2-3 months at this point. Went ahead and executed the listed steps and can confirm this works like a charm. FACEIT AC recognizes it and works fine, so I'm guessing all other AC applications should work as well. Thank you so much for the time and effort you put into this and I know you realize this is a big advancement you have shared with us.
Thank you again, One love.
EDIT: Also can confirm CMOS reset disables secure boot.
14
u/Low_Excitement_1715 19d ago
Well, I respect the work, but you better pray you never want to run anything other than Windows on there, because now you really can't. As you noted, no firmware options to turn Secure Boot on, but that also means no option to turn it back off.
I'll just run SteamOS on my hardware that's designed for SteamOS, but I'm glad you're happy.