This is a read-only archive. No new posts or registrations. Privacy Page
Software

UEFI

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am trying to reconcile UEFI and imaging.

 

With Macrium I have to learn about UEFI.

Although I thought I read that Win PE 5.0 would run Macrium boot without setting the boot order with UEFI - I do not now if that is true.

 

Does the same apply to the native image program with Win 8.1 on the lower corner of the file history page regarding boot order?

 

Or does it boil down to having to disable secure boot and enable CSM?

 

If you have legacy, can you select it and when you restart it will allow you to select the boot choice?

After selecting legacy, and rebooting, do you have to tap F12 anyway?

 

Although I thought I read that Win PE 5.0 would run Macrium boot without setting the boot order with UEFI - I do not now if that is true.

no it is not.

 

let me see if i can explain things in a way that is easy to understand of how things work without going into anything technical.

 

when you power on a pc a program has to run which enables all the different hardware in it to communicate with each other before any os is started/installed, on older pc's this was called the bios on newer pc's this is called uefi.

 

now when everything knows how to talk to each other it then has to know where to find the os to install and this is where the boot order comes in, so usually it is set to look for the os on a cd/dvd and then on any hard drives followed by any removable/usb media and finally a network connection.

 

secure boot is a feature implemented in uefi which means when enabled before any os or software can run uefi checks to see if it is signed with a digital security signature, if it doesn't have one then it will not run the software.

in legacy mode or if secure boot is turned off this check is not done and any os or software is allowed to run/install.

 

now having cleared that up (i hope.  :D )

 

when your create an image it is making a 1 to 1 copy of your hard drive or partition, so the bios or uefi doesn't enter into the equation at all.

 

the only time uefi or secure boot matters is in what type of media your creating to start the image restore process, if you've created a cd/dvd that isn't digitally signed with the security code needed to run when a pc's uefi is set to secure boot then it will not work UNLESS you then go into the uefi and turn it off or set it to legacy boot.

 

i believe winpe 5.0 has this digital signature so the question of uefi/legacy or secure boot doesn't matter because it will always run regardless if it is set to legacy boot or has secure boot enabled.

of course the cd/dvd drive has to be first in the uefi's boot order other wise it will look in other locations first and if it finds an os to install/run then it will not open the cd/dvd to start the recovery process because it will run/install the first os found.

 

a recovery/restore disk/usb stick has a small os that is run in memory only exactly the same as when you've run linux live cd's.

 

does that explain things and make sense? :rofl:

 

:popcorn:  

Yes, Terry and thank you for the very clearly written explanation.

2 Questions if I may;

 

 

You wrote>>I believe WinPE 5.0 has this digital signature so the question of uefi/legacy or secure boot doesn't matter because it will always run regardless if it is set to legacy boot or has secure boot enabled.

 

And I stated >>it was possible to run Win PE 5. regardless of UEFI. There seems to be a contradiction or I am not reading it correctly.

 

Lastly, Does it make sense to look for Legacy if it exists and enable it so you can then use the Macrium cd?

If there is no legacy, one would then disable secure boot under boot then enable csm under privacy or is enabling csm not necessary after disabling Secure boot.

 

In any case do you still have to set the boot order so that cd/dvd is first?

 

And I stated >>it was possible to run Win PE 5. regardless of UEFI. There seems to be a contradiction or I am not reading it correctly.

you stated it was possible to run winpe 5.0 regardless without setting boot order. but the way uefi works is it will always boot the first os it finds, so if the boot order isn't set to boot your restore media first, either with the quick F12 1 time boot option or actually going into uefi and permanently changing the boot order there then there is no guarantee it will run.

 

ie. you have a working but malware infected os running on your hard drive and have previously created a clean image along with a bootable usb winpe 5.0 stick to start the recovery process.

 

so you insert the stick, start your pc up, expecting the recovery process to start but instead it boots to the infected os your wanting to replace, this is because the boot order is cd/dvd then hard drives then usb sticks, so the uefi first checked for any cd/dvd's and found nothing then checked hard drives and found an os to install so never checked anything else and just installed the infected os.

 

 

In any case do you still have to set the boot order so that cd/dvd is first?

so yes you always have to check/set the first boot device so your sure it will boot the correct media your wanting to boot and not any thing else that's bootable it may find first.

 

like i said earlier manufacturers usually set the boot order so uefi checks cd/dvd, then hard drives, then removable media, then network connection. so unless you've changed things (some people make the hard drives first boot just to get to the desktop slightly quicker.) and always use a cd/dvd recovery medium then you never have to worry or change anything.

 

 

Lastly, Does it make sense to look for Legacy if it exists and enable it so you can then use the Macrium cd?

 

this macrium cd, is it the winpe 5.0 recovery cd/dvd you made? if so then no you never have to worry about secure boot or legacy boot options, in fact for better security it should always be set to uefi and have secure boot enabled.

 

now you've confused me with the next part,

 

If there is no legacy, one would then disable secure boot under boot then enable csm under privacy or is enabling csm not necessary after disabling Secure boot.

each uefi bios is slightly different depending on manufacturer so a setting in one type may not be in another type or named differently.

for example in some uefi's just disabling secure boot is enough to boot any program, digitally signed or not yet in others you also have to make sure to enable legacy boot. so in some 1 change will make things boot but in others 2 changes are needed to the settings before it will boot correctly.

 

so don't really know if for you just disabling secure boot is enough or if you also have to enable csm too.

what exactly does csm stand for anyway? never seen such a setting myself in uefi. :rofl:

 

anyway the software your trying to boot whatever it is always needs to be digitally signed before it will boot with secure boot enabled.

most reputable software will have this digital signature now or in the near future with their latest program versions but there is always some older software that is very useful but will never be digitally signed for one reason or another.

 

this secure boot thing is a pet peeve of mine because the hardware is yours and you should always be able to install whatever you want to it, but with microsofts licensing agreements especially now with win 10 as far as i know, the secure boot always has to be enabled but also you may now not have the option any more to actually turn it off and boot legacy software which is not signed.

 

hope that answers your questions or most anyway, keep asking away with anything your still not sure about and we'll see if we can clear things up for you.

 

:popcorn:

 

ok found it. csm = Compatibility Support Module. or a posh way of saying legacy mode. :rofl:

 

should also add, even tho it is a completely different topic but related slightly to this one about uefi and legacy boot options, the partition table of the hard drive makes a big difference on which you need to use.

there are 2 types mbr or gpt, with the hard drive formatted using gpt you need to use uefi because legacy or csm mode will not boot a windows os installed on a gpt partition..

It is good to know most manufacturers have boot order set as it should be. I always thought the hard drive should be first but now I get it.

 

I made two discs with Macrium; one is Linux which works for my system and the other is Win PE 5 for Win 8.1, just in case.

 

I could not agree with you more about Windows taking over like Google did with KitKat 4.4  then relented to a degree with Lollipop 5. and eased permissions or restrictions so you could write to the SD card.

 

My friend has the pc with UEFI and b/c I do not want to be responsible for any trouble I will explain Macrium as I use it and my limitation with UEFI. If he chooses to go ahead so be it.

I will tell him that he has to undo what he changes after wards and although I depend upon imaging greatly,  would encourage creating an image or 2 and making discs, then let him study up on the uefi in case he needs it. I would not tinker.

 

I watch tutorials on YouTube and learn a little each time. You are right that each manufacturer has a different way of doing things. I guess the companies who help people who are stuck with all of these new SECURITY changes are making a lot of money.

It was the word security that got Google to restrict permissions until 1/2 of the World balked. Maybe Windows users should do the same.

 

As usual, thank you very much for your patience and assistance.

As a rhetorical PS, I wonder what Windows thinks the average user is supposed to do when a severe problem occurs or a problematic  bug infects the machine and imaging is not possible.

imaging will always be possible, it's just that you will have to use software that is digitally signed (of course they have to pay to get their software digitally signed.), what it does mean tho is you will have less choice on what you can and can not install on your own pc.

 

personally i don't believe secure boot makes a pc any more secure than a pc running without such a check or with an older bios in reality even tho in theory it should, all it does is make things more difficult for the owner of the hardware.

 

like i said earlier it is a pet peeve of mine, even though it only really effects oem machines(store bought.) and doesn't make any difference to people like me who build their own pc's. :angry:

 

:popcorn:

I echo your sentiments exactly.

 

W/o getting into it again, would you say that Macrium's Win PE I have is digitally signed? I know it sounds like I did not understand but I was only  a bit vague on that poin

yes all winpe versions from 4.0 and up are digitally signed from my understanding so you have nothing to worry about there, if you had an older macrium restore disk created with a lower version number then you'd need to create a new one for it to boot with secure boot enabled.

 

:popcorn:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI