EVGA

Secure Boot: Question about "vendor keys"

Author
Anewbis
New Member
  • Total Posts : 33
  • Reward points : 0
  • Joined: 2010/11/01 16:33:19
  • Status: offline
  • Ribbons : 1
2017/05/22 02:31:02 (permalink)
What are vendor keys, and why can't i get them back without re-flashing the BIOS?

I don't mean default keys, to clarify. There are ephemeral mystery-keys that are wiped when you revert to setup mode.
#1

5 Replies Related Threads

    KenMcC
    CLASSIFIED Member
    • Total Posts : 3329
    • Reward points : 0
    • Joined: 2010/07/02 07:02:23
    • Location: Garland, TX
    • Status: offline
    • Ribbons : 21
    Re: Secure Boot: Question about "vendor keys" 2017/05/22 06:56:01 (permalink)
    Vendor BIOS Key for my z170 Classy K  is the "DELETE KEY"
    You can google or yahoo for Motherboard Vendor Key and there are several post with lists of keys by vendor per motherboard they make

    KenMcC
    Z170 Classy K; i7-6700 CPU,
    Corsair CMK16GX4M2A2400C14
    Seasonic SSR-360GP 360W;
    Samsung 950 Pro M.2 256 GB 
    Samsung 850 Evo 500 GB SATA
    Samsung 850 Evo 256 GB SATA
    Samsung SSD 840 Series 250 GB SATA
     
    Samsung 860 EVO 1 TB SATA
    Windows 10 x64 Prof.  
    #2
    Anewbis
    New Member
    • Total Posts : 33
    • Reward points : 0
    • Joined: 2010/11/01 16:33:19
    • Status: offline
    • Ribbons : 1
    Re: Secure Boot: Question about "vendor keys" 2017/05/23 06:36:14 (permalink)
    I think you misunderstood. I don't need the key to enter the BIOS. You work for Technet?

    Joking aside; under secure boot options, there are two types of keys. One is set by manually activating the default factory provisioned keys, and sets a PK, KEK, DB, and DBx. Setting these keys changes secure boot from "setup mode" to "user mode."

    The other, "vendor keys," is active automatically after a firmware flash. Returning secure boot to "setup mode" sets "vendor keys" to "not active." The vendor keys are not listed as a PK, KEK, DB, or DBx, and on their own to not allow secure boot to run.

    What are these "vendor keys," and why are they only able to be "active" after a fresh BIOS flash?
    #3
    KenMcC
    CLASSIFIED Member
    • Total Posts : 3329
    • Reward points : 0
    • Joined: 2010/07/02 07:02:23
    • Location: Garland, TX
    • Status: offline
    • Ribbons : 21
    Re: Secure Boot: Question about "vendor keys" 2017/05/23 10:06:52 (permalink)
    Yep, you are correct, I have never heard of anything like you said above.  Perhaps an email to tech support at evga.com would help

    KenMcC
    Z170 Classy K; i7-6700 CPU,
    Corsair CMK16GX4M2A2400C14
    Seasonic SSR-360GP 360W;
    Samsung 950 Pro M.2 256 GB 
    Samsung 850 Evo 500 GB SATA
    Samsung 850 Evo 256 GB SATA
    Samsung SSD 840 Series 250 GB SATA
     
    Samsung 860 EVO 1 TB SATA
    Windows 10 x64 Prof.  
    #4
    Cordorb
    SSC Member
    • Total Posts : 635
    • Reward points : 0
    • Joined: 2007/03/18 22:27:50
    • Status: offline
    • Ribbons : 2
    Re: Secure Boot: Question about "vendor keys" 2017/05/24 19:39:30 (permalink)
    here is a little more information to people reading his question.
     
    http://www.linuxjournal.com/content/take-control-your-pc-uefi-secure-boot
     
    Most of us on the Mac side do set a hardware firmware password since it is easy to boot a full Mac system with an external disk.
    Very few of my PC friends do but I too will be interested in the answer to the OP question.
     
    I though on my first read of the question you were asking about the special keyboard keys  use at boot to get into the old  RAID BIOS .
     

     
     
    #5
    quadlatte
    CLASSIFIED ULTRA Member
    • Total Posts : 7191
    • Reward points : 0
    • Joined: 2006/09/14 16:52:58
    • Location: Greensboro, NC
    • Status: offline
    • Ribbons : 56
    Re: Secure Boot: Question about "vendor keys" 2017/05/25 10:46:18 (permalink)
    Cordorb
    here is a little more information to people reading his question.
     
    http://www.linuxjournal.com/content/take-control-your-pc-uefi-secure-boot
     
    Most of us on the Mac side do set a hardware firmware password since it is easy to boot a full Mac system with an external disk.
    Very few of my PC friends do but I too will be interested in the answer to the OP question.
     
    I though on my first read of the question you were asking about the special keyboard keys  use at boot to get into the old  RAID BIOS .
     


    i was thinking the same thing at first. good read on the link though, really explained a lot

                                   
                                                 Heatware: http://heatware.com/eval.php?id=72498
    #6
    Jump to:
  • Back to Mobile