Outline ·
[ Standard ] ·
Linear+
Sign own UEFI key, prevent staff install Windows
TSAnime4000
|
Mar 16 2017, 01:07 AM, updated 7y ago
|
|
I lending my staff a Linux Laptop, which I set auto connect OpenVPN to my office server, allowing staff to have network drive, email, etc... (cheap way to having secure connection).
how to block my staff installing windows? putting BIOS password can be remove by clear CMOS, I saw a BIOS menu that allow to add own secure boot key, how to do it?
|
|
|
|
Eventless
|
Mar 17 2017, 05:39 PM
|
|
I'm pretty sure that the secure boot key feature is to allow you to install an os signed using your own security certs, not to prevent people from installing their own os.
There's not much you can do in order to prevent a person from installing their own os on the laptop once it is in their hands.
|
|
|
|
abubin
|
Mar 22 2017, 03:56 PM
|
|
how about telling him not to do it? If he still do it knowing that he can't, then why do you still want to keep this kind of staff? We are all adult and can follow instructions without having to be placed in a jail environment.
|
|
|
|
Netto Hikari
|
Apr 14 2017, 05:15 PM
|
|
disable boot from usb & cdrom. bios security lock. this prevent at all to install any OS
|
|
|
|
TSAnime4000
|
Apr 15 2017, 04:18 PM
|
|
QUOTE(Netto Hikari @ Apr 14 2017, 05:15 PM) disable boot from usb & cdrom. bios security lock. this prevent at all to install any OS set jumper to clear CMOS, most laptop have hardware reset, make contact both pin to clear NVRAM
|
|
|
|
Netto Hikari
|
Apr 16 2017, 08:28 AM
|
|
QUOTE(Anime4000 @ Apr 15 2017, 04:18 PM) set jumper to clear CMOS, most laptop have hardware reset, make contact both pin to clear NVRAM provided they noe how to dismantle and try their luck. if a person really wan to do shit, they will just do it regardless how many security restriction u put in.
|
|
|
|