5 ms·
I have a Ryzen 5000-series PC that I built about 6 months ago using mostly new parts. Yesterday I was curious whether my PC was compatible out of the box, so I
by dlevine 5y ago
I have a Ryzen 5000-series PC that I built about 6 months ago using mostly new parts. Yesterday I was curious whether my PC was compatible out of the box, so I downloaded Microsoft's compatibility checker. It told me that my PC didn't have Secure Boot enabled. I figured that I would just enabled that in my BIOS (haha).
I went into the BIOS (sorry, UEFI setup) and enabled TPM, which I had read about as being one of the major issues. That wasn't enough, and I was informed that my PC still isn't compatible. I tried enabling Secure Boot, and got an error message that there was something else I had to do first (generate a security key). I figured out how to do that, and I still couldn't enable Secure Boot because my PC was in CSM mode. CSM mode is my B450 motherboard's default mode.
I tried disabling CSM mode, and then I was able to turn on Secure Boot. However, when I rebooted, my computer couldn't find my SSD, and kicked me back to the BIOS, with no message other than a beep. I turned everything off and gave up for the evening.
Then this morning I Googled some of the messages I got and realized that the problem might be that my SSD doesn't use GPT but MBR for the partition table (it was pulled from my previous PC). After thinking I was going to have to back up and recreate my hard drive, I realized that there is a command-line tool I could use, helpfully named mbr2gpt. I ran that with the appropriate options, ignoring some warnings. It ran successfully, although I got an error about my recovery image, which was spurious so far as I can tell.
Once I did all of this, I was able to switch on Secure Boot, and the compatibility checker informed me that my computer is compatible.
The point is that I'm pretty computer-savvy and have a pretty new PC. It still took me quite a while to figure this out, and a lot of people would have given up around the time they had to go mucking around in the BIOS. Unless you are have a recent store-bought PC that has Secure Boot and TPM enabled out of the box, you probably aren't going to be able to upgrade, even if your hardware is compatible.
I'm guessing that Microsoft walks back on this decision.
- staticassertion 5y agoSo the moral of this story is that your recent computer was actually compatible with Windows 11 and that installing an OS that's currently in alpha onto a computer that you built yourself requires being computer savvy - yeah?
- wdfx 5y agoNo, the pc does contain compatible hardware but by default configured in a way which is not compatible. Even a tech savvy user then gets bored of the process to change the configuration. Most other people will simply give up and either not use the new windows version or replace the perfectly good hardware with something else that someone else has already configured. Now I'm also bored already just trying to explain what's going on here.
- staticassertion 5y agoMost other people aren't going to build their own computer and try to install an alpha preview of an OS on it. It kinda sounds like you signed up for that boring work to me.
- detaro 5y agoInstalling the non-alpha upgrade will improve this experience how? Things like this not being setup optimally on pre-built PCs is also not exactly unusual. Although I assume it'll mostly lead to people sticking with Win10 for longer.
- staticassertion 5y ago> Installing the non-alpha upgrade will improve this experience how? For one thing it'll cut the 30% of the story that involved figuring out the compatibility issue iteratively.
- edgyquant 5y agoMost people will not have an MBR scheme on an ssd. Most people who have a Windows PC they bought towards the end of Windows 7/Windows 8 era will have secure boot on already and working. This user is an outlier.
- unstatusthequo 5y agoWhile true, I think his point is more about how many computers will be scrapped because non techie people won’t know to do the above and assume that they need a new computer. Then massive e-waste pile grows. Do we even know if UEFI compatible hardware and SecureBoot is enabled by all OEMs by default? I could see a scenario where that’s not true. Microsoft should have made this a suggestion and warned about why it’s better for the end user rather than forcing the issue. I could also see “Your computer is not compatible. Get Surface Pro for XX% off at the Microsoft store!” Because antitrust and MS are a thing, historically.
- frombody 5y agoYou don't have a pretty new PC, you have parts from a new PC mixed with parts from an older PC. No manufacturer has shipped an mbr formatted drive in the last 5 years.
- rootsudo 5y agoCorrect, Dell, Lenovo, HP even enable the basic EFI(bios) menu with Secureboot enabled, granted this is a bit disabled if you get an Ubuntu/XPS model but can be enabled easily for dual booting. This is relatively a non-issue for most orgs, you should have an imaging solution in place, if not there is Windows Hello/Autopilot, not free but easy to deploy and helps you manage and orchestrate, which is what every corporation should do with owned devices. Machines 5yrs+ support TPM 2.0 unless you bought absolutely bargain basement prices like Dell Inspirion models from Walmart instead of Dell.com and such, but even lately those also include TPM and Secure Boot as Microsoft demanded it from it's vendors. Building your own PC, is something that, is kinda dead in todays times though.
- anakaine 5y ago"Building your own PC, is something that, is kinda dead in todays times though." The number of people having issues finding high end graphics cards over the past 18 months says otherwise.
- makomk 5y agoManufacturers don't generally ship internal drives with any kind of partition table at all in my experience - that gets added when you do the initial install, which generally depends on what mode you booted the installer from and in turn probably on your motherboard BIOS defaults...
- slantyyz 5y agoI have a Lenovo desktop with a Ryzen 4000 series APU, and the only way I can reliably install BIOS updates is to disable Secure Boot, as the other methods just never work. It doesn't help that the Lenovo BIOS updating software is crap too. I don't know why it asks me if I want to change the serial number every time it runs (and it doesn't default to "No").
- alamortsubite 5y agoReading this made me yearn for the days of IRQ conflicts.
- rootsudo 5y agoIRQ Conflicts and BSOD from using Windows 95/98 drivers on Windows ME days...
- ohazi 5y agoThis is a BIOS vs. UEFI thing, it has nothing to do with Windows or Secure Boot or the TPM requirement. When you do an initial OS install today, you have to boot the computer in the mode that you intend to use (Legacy BIOS / CSM mode vs. UEFI mode, with or without secure boot). This is the case with Linux too. You can't really just switch modes afterwards. For Windows, you'll definitely need a reinstall. (Edit: I didn't read your post carefully, apparently there's a tool to fix it? Neat!) For Linux, there's probably a way to re-bootstrap everything yourself (reorganize your partitions, create the EFI partition, copy your kernel and initrd, etc.), but reinstalling is preferred, and will almost certainly be easier. Several years ago I screwed up a Windows/Linux dual boot by installing one under BIOS and the other under UEFI. The only way to select the operating system was to go into the firmware settings and flip the CSM/UEFI bit each time. That was an annoying week, but the fix was to turn off CSM and reinstall everything under UEFI.
- fuzzfactor 5y ago>When you do an initial OS install today, you have to boot the computer in the mode that you intend to use (Legacy BIOS / CSM mode vs. UEFI mode That's one worthwhile technique. Not many users want to go much further since then you need at least twice as many boot files as the minimum and it's best to test each configuration thoroughly. If you're dual-booting you are already putting twice as much effort into OS installation & maintenance already, this is not really popular but I did post my latest findings just a couple days ago how I use 4 sets of boot files for W10 & Ubuntu on BIOS & UEFI: https://news.ycombinator.com/item?id=27629350 https://news.ycombinator.com/item?id=27629350 It's a little entensive background info, the basic outline is shorter than that.
- lostmsu 5y agoI don't think you need to reinstall much. As long as you have a UEFI-compatible bootloader after converting your hard drive to GPT partition scheme, your UEFI should pick it up. Windows certainly installs one.
- omegalulw 5y ago+1. I had to go through this when I switched from BIOS to UEFI. Windows 11 needs to be criticized for mandating TPM but not for this.
- qwerty456127 5y agoTo me it seems Secure Boot has always been a near-zero-value bullshit invented and pushed by Microsoft to make life of dual-booters harder.
- ohazi 5y agoThe only theoretical value I see in Secure Boot is if you're trying to build a tamper-resistant laptop. You'd have to only run Linux, you'd have to disable everything except your own signing keys (rather than using the shim, or anything else signed by Microsoft, because they'll sign (or can be coerced into signing) basically anything), you'd probably want to skip GRUB and boot an EFI executable directly without editable kernel arguments, and you'd have to manually sign every kernel update or module that you wanted to load. But even then, I see no reason to trust that a given UEFI implementation won't quietly accept some secret hard-coded key even after all of the defaults have been removed, so now I guess we're stuck with older machines that can be flashed with Coreboot? Yeesh. The number of people who can get this to work has got to be vanishingly small...
- lostmsu 5y agoEvery single cloud provider uses Secure Boot as an additional layer of security for machines.
- fomine3 5y agoSecure boot and corresponding protection is just like security protection on Mac/iPhone/Android by Secure Enclave / TrustZone. Maybe users something like using FOSS phone don't like them, but it seems to better to have it in general.
- smileybarry 5y agoOn Windows 10, turning on Secure Boot then requires every boot driver to be manually signed by Microsoft themselves, in addition to the dev's code signing cert. This is a significant security boundary, given that most malicious actors won't go through the process of EV registration with Microsoft to gain this. (I guess netfilter is an interesting exception) If they compromise someone's credentials and still get a driver signed, Microsoft have a copy of the driver and when/where it was signed. In addition, Secure Boot prevents malware from changing the bootloader (and helps stop boot-time ransomware). It's just a good sense fix to many attack vectors left alone for years.
- tyingq 5y agoThere's also some computers that would need a TPM firmware upgrade from 1.2 to 2.0. So another not mom-and-pop friendly task to add to the pile.
- fomine3 5y agoMost people just bought Windows 8/10 preinstalled PC that is installed with UEFI/GPT, probably CSM disabled by default, and hopefully TPM enabled by default. Most Windows 7 PCs are old to be supported by Windows 10. So, who still using Windows 10 on MBR/BIOS installation is mostly beginner for DIY PC.
- anakaine 5y agoThats a whole lot of generalising, and a broad assumption at the end there. Even with UEFI enabled there can still be hudles to getting secure boot and TPM2.0 enabled without messing up the current install.