Menu

some shit about chinese motherboards, eg msi

BABUT
2017-08-15
2017-08-15
  • BABUT

    BABUT - 2017-08-15

    sorry for my english, i am from mars.
    ugly manual for install veracrypt on chinese shit, eg msi:

    1. in rufus(https://rufus.akeo.ie/?locale) create windows 10(on torrents, eg http://nnm-club.name/forum/viewtopic.php?t=1042266) installation usb flash drive with uefi support.
    2. boot into the bios. switch bios into uefi support mode with enabled "windows 10 support", and enable "secure boot" into "standart mode"(its using default keys, stored in bios).
    3. boot from usb flash drive and install windows 10.
    if bios does not see uefi flash drive(eg motherboards from msi, older z270 chipset)- reset the bios with jumper and reboot- should help.
    4. mount efi partition- mountvol <any unused disk char here, eg P>: /s
    copy into p:\ all five certs from https://github.com/veracrypt/VeraCrypt-DCS/tree/master/SecureBoot/certs
    initiate veracrypt system partition encrypt test and reboot.
    5a. you see black screen or something similar(eg "i cant load this shit, because i dont have valid keys for secure boot!"), but not asking password- it means veracrypt loader installed, enabled and set as first for load. but check in any case: both "windows boot manager" and "veracrypt" must be enabled, and "veracrypt" first for load.
    go to the bios, in "secure boot" section switch mode from "standart" to "custom"("user")- this will clear the default keys in nvram, if not then do clean manually. 
    install(dont use mouse for navigation. just trust me, dont use) veracrypt's keys(from usb flash drive): 
     pk- DCS_platform
     kek- DCS_key_exchange
     db- DCS_sign, MicWinProPCA2011_2011-10-19, MicCorUEFCA2011_2011-06-27 -install first, then add(not "install" or "new", because its replasing first key) other.
     dbx- nothing, just delete all here.
     if exist something else- clean.
    reboot and goto step 8
    5b. test failed(no black screen, does not asked password, booting into win10).
    in win10: 
    mount efi partition- mountvol <any unused disk char here, eg P>: /s
    /* open for edit p:\efi\veracrypt\dcsprop, add to "<configuration>" section string "<config key="ActionSuccess">postexec file(EFI\Microsoft\Boot\bootmgfw.efi)</config>". ACHTUNG! used "bootmgfw.efi" not "bootmgfw_ms.efi". */ not needed.
    copy into p:\ all five certs from https://github.com/veracrypt/VeraCrypt-DCS/tree/master/SecureBoot/certs
    rename p:\efi\boot\bootx64.efi in something for backup.
    copy "uefi shell"(https://svn.code.sf.net/p/edk2/code/trunk/edk2/ShellBinPkg/UefiShell/X64/Shell.efi) into p:\efi\boot\ and rename to bootx64.efi
    reboot
    6. boot from usb flash drive(now booting into "uefi shell", because we replased bootx64.efi with "uefi shell"). if you cant boot from usb flash drive with "uefi shell" loader then you should temporarily disable "secure boot".
    in uefi shell do:
    map fs* -its show drives, find hdd with you win10, eg fs1, then
    fs1: -its change directory to fs1 drive
    bcfg boot dump -its show all boot entries, find last entry number, eg 5, then
    bcfg boot add 6 \efi\veracrypt\dcsboot.efi "VeraCrypt" -its added new entry with number 6 and label "VeraCrypt"(it will be shown in bios boot menu), pointed on veracrypt loader dcsboot.efi, then do again "bcfg boot dump" and make sure that the entry is added.
    reboot
    7. go to the bios, in "secure boot" section switch mode from "standart" to "custom"("user")- this will clear the default keys in nvram, if not then do clean manually. 
    install(dont use mouse for navigation. just trust me, dont use) veracrypt's keys(from usb flash drive): 
     pk- DCS_platform
     kek- DCS_key_exchange
     db- DCS_sign, MicWinProPCA2011_2011-10-19, MicCorUEFCA2011_2011-06-27 -install first, then add(not "install" or "new", because its replasing first key) other.
     dbx- nothing, just delete all here.
     if exist something else- clean.
    reboot 
    8. the end. if now not asking password for booting and then not booting to the win10, then kill yourself.. or me ^^
    
     

    Last edit: BABUT 2017-10-03
  • BABUT

    BABUT - 2017-08-15

    some ugly automatic formation from this shitty site. i dont know what to do with it :(

    up: oh! need use "code" worms

     

    Last edit: BABUT 2017-08-15

Log in to post a comment.

MongoDB Logo MongoDB