Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Sign own UEFI key, prevent staff install Windows

views
     
TSAnime4000
post Mar 16 2017, 01:07 AM, updated 7y ago

Regular
******
Senior Member
1,917 posts

Joined: Jul 2009
From: /dev/null


I lending my staff a Linux Laptop, which I set auto connect OpenVPN to my office server, allowing staff to have network drive, email, etc... (cheap way to having secure connection).

how to block my staff installing windows? putting BIOS password can be remove by clear CMOS, I saw a BIOS menu that allow to add own secure boot key, how to do it?
Eventless
post Mar 17 2017, 05:39 PM

Look at all my stars!!
*******
Senior Member
2,641 posts

Joined: Jan 2003
I'm pretty sure that the secure boot key feature is to allow you to install an os signed using your own security certs, not to prevent people from installing their own os.

There's not much you can do in order to prevent a person from installing their own os on the laptop once it is in their hands.
abubin
post Mar 22 2017, 03:56 PM

10k Club
********
All Stars
10,423 posts

Joined: Jan 2003



how about telling him not to do it? If he still do it knowing that he can't, then why do you still want to keep this kind of staff? We are all adult and can follow instructions without having to be placed in a jail environment.
Netto Hikari
post Apr 14 2017, 05:15 PM

Solution Architect?
*******
Senior Member
2,394 posts

Joined: Jan 2003
From: Selangor


disable boot from usb & cdrom. bios security lock.
this prevent at all to install any OS biggrin.gif
TSAnime4000
post Apr 15 2017, 04:18 PM

Regular
******
Senior Member
1,917 posts

Joined: Jul 2009
From: /dev/null


QUOTE(Netto Hikari @ Apr 14 2017, 05:15 PM)
disable boot from usb & cdrom. bios security lock.
this prevent at all to install any OS biggrin.gif
*
set jumper to clear CMOS, most laptop have hardware reset, make contact both pin to clear NVRAM
Netto Hikari
post Apr 16 2017, 08:28 AM

Solution Architect?
*******
Senior Member
2,394 posts

Joined: Jan 2003
From: Selangor


QUOTE(Anime4000 @ Apr 15 2017, 04:18 PM)
set jumper to clear CMOS, most laptop have hardware reset, make contact both pin to clear NVRAM
*
provided they noe how to dismantle and try their luck. if a person really wan to do shit, they will just do it regardless how many security restriction u put in.


 

Change to:
| Lo-Fi Version
0.0142sec    0.23    5 queries    GZIP Disabled
Time is now: 29th March 2024 - 04:28 AM