Jump to content

Secure Boot Issue - Dell Latitude 3190 2-in-1 Laptop


Recommended Posts

Posted (edited)

Been using MDT 2013 / Lite Touch / WDS to deploy Windows successfully to many different models of laptops (and desktops) with Secure Boot enabled for a long time now.

 

However, been having issues specifically with Dell Latitude 3190 2-in-1 models only.

 

All other Dell models (Latitude 3190, Latitude 3380, Latitude 3310) as well as the various DfE laptops (e.g. HP 245, 255 - Toshiba & Dynabook) too, all PXE boot and build OK (with secure boot enabled) but these Latitude 3190 2-in-1 laptops simply won't!

 

We use the official Dell USB3 to Ethernet PXE adaptors, and even attempted to create a LiteTouch.iso USB pen drive to boot from (inc. checking GPT, UEFI enabled, latest BIOS Firmware and Dell Deployment CAB / drivers etc.) - but same issue.

Operating System Loader failed signature verification. WARNING: The file may have been tampered with! All bootable devices failed Secure Boot verification.

 

If Secure Boot is disabled, then the laptop PXE Boots OK and the Windows image is deployed. And not even sure if you can then re-enable Secure Boot retrospective afterwards?? I did try but BIOS initially stated there was no .PK key, and after reseting BIOS to defaults, it progressed but still ended up with the same above error message.

 

Any thoughts?

 

Thanks,

Edited by MYK-IT
Posted (edited)

This is an odd one as both the 3190 and 3190 2-in-1 use the same motherboards (only difference is that the 2-in-1 has extra components/connectors for the touchscreen) and the same system BIOS image.

 

Have you tried re-flashing the BIOS in case this restores the .PK keys?

 

EDIT: Just re-read your post that you did just that. Maybe if it'll allow you to, roll back to an earlier BIOS release?

Edited by MrEprise
  • Thanks 1
Posted (edited)

Thanks for the suggestions @MrEprise

 

I have finally found the solution!!! It was related to Expert Key Management even though I have never touched those settings and ensured I'd (re)flashed the latest BIOS etc.

 

Essentially, within the BIOS:

 

Settings > Secure Boot > Expert Key Management

 

  • Checked 'Enable Custom Mode'
  • Clicked 'Reset All Keys'
  • Unchecked 'Enable Custom Mode'
  • Click 'Apply'

 

 

Then rebooted and the laptop now PXE Boots and deploys with 'Secure Mode' enabled.

Edited by MYK-IT
  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...