**This is an old revision of the document!**

dreamflasher

  • hostname: dma-dreamflasher
  • os: nixos

Entering Secure Boot Setup Mode

  1. Enter BIOS setup by spamming Esc then Device Manager
  2. Go into Secure Boot Configuration
  3. Switch Secure Boot mode to Custom mode
  4. Go to the list of Secure Boot keys, then PK, then Delete PK. Confirm yes.
  5. Go out, then Boot Manager, then boot into NixOS as usual.
  6. Validate setup mode using sbctl status and bootctl status.
  7. Use sbctl enroll-keys --microsoft.
  8. Validate that you're no longer in setup mode via the above commands.
  9. Reboot again. Validate that the system boots fine.
  10. Re-enroll TPM2-backed decryption via Arch wiki guide.