# How Ventoy Handles Secure Boot Validation Across Different UEFI Firmware Signatures

> Discover how Ventoy handles Secure Boot validation using UEFI firmware signatures. Ventoy ensures compatibility by intelligently managing signed EFI binaries and executable payloads.

- Repository: [longpanda/Ventoy](https://github.com/ventoy/Ventoy)
- Tags: internals
- Published: 2026-03-01

---

**Ventoy validates Secure Boot by querying the UEFI `SecureBoot` variable, selectively presenting signed EFI binaries when enabled, and stripping all executable payloads when disabled to prevent firmware signature verification failures.**

The `ventoy/Ventoy` repository implements a multi-layered Secure Boot handling mechanism that adapts to diverse UEFI firmware implementations from Intel, AMD, ARM, and various OEM vendors. According to the source code, Ventoy does not perform signature validation itself; instead, it controls whether signed EFI binaries are exposed to the firmware or removed entirely based on the detected Secure Boot state and user preferences.

## UEFI Firmware Detection and Variable Parsing

Ventoy detects the Secure Boot state by querying the UEFI `SecureBoot` variable using the globally unique identifier `gEfiGlobalVariableGuid`. In [`EDK2/edk2_mod/edk2-edk2-stable201911/MdeModulePkg/Application/Ventoy/Ventoy.c`](https://github.com/ventoy/Ventoy/blob/main/EDK2/edk2_mod/edk2-edk2-stable201911/MdeModulePkg/Application/Ventoy/Ventoy.c), the function `ventoy_get_variable_wrapper` intercepts calls to `gRT->GetVariable` to read this firmware state.

When the user elects to bypass Secure Boot, this wrapper forces the return value to `0` (disabled) even if the firmware reports it as active. This manipulation occurs after `ExitBootServices` has been invoked, ensuring that cached Secure Boot states in different UEFI implementations are overridden consistently.

The GRUB2 module in [`GRUB2/MOD_SRC/grub-2.04/grub-core/ventoy/ventoy_cmd.c`](https://github.com/ventoy/Ventoy/blob/main/GRUB2/MOD_SRC/grub-2.04/grub-core/ventoy/ventoy_cmd.c) independently reads the same variable via `grub_efi_get_variable("SecureBoot", ...)` to expose the flag to GRUB scripts, maintaining state consistency across the boot chain.

```c
/* ventoy_get_variable_wrapper – forces SecureBoot = 0 when bypassed */
EFI_STATUS EFIAPI ventoy_get_variable_wrapper(
    IN CHAR16 *VariableName,
    IN EFI_GUID *VendorGuid,
    OUT UINT32 *Attributes OPTIONAL,
    IN OUT UINTN *DataSize,
    OUT VOID *Data OPTIONAL)
{
    EFI_STATUS Status = g_org_get_variable(VariableName, VendorGuid,
                                            Attributes, DataSize, Data);
    if (StrCmp(VariableName, L"SecureBoot") == 0 && *DataSize == 1 && Data) {
        *(UINT8 *)Data = 0;               // fake “SecureBoot disabled”
    }
    return Status;
}

```

## Cross-Platform UEFI Firmware Compatibility

UEFI firmware from different manufacturers (e.g., AMI, Phoenix, Insyde, or ARM vendors) validates EFI binary signatures using platform-specific keys enrolled in the firmware database. Ventoy handles these different **UEFI firmware signatures** through a binary presence strategy rather than signature manipulation.

**Secure Boot Enabled**: Ventoy preserves its signed EFI binaries—including `grubx64_real.efi`, `MokManager.efi`, and `BOOTX64.EFI`—within the EFI System Partition. These binaries carry valid signatures from the Ventoy project or Microsoft, allowing standard UEFI Secure Boot validation to succeed across all compliant firmware implementations.

**Secure Boot Disabled**: Ventoy guarantees that no EFI executable is presented to the firmware, preventing signature verification failures on strict implementations. The `VentoyProcSecureBoot` function in [`LinuxGUI/Ventoy2Disk/Web/ventoy_http.c`](https://github.com/ventoy/Ventoy/blob/main/LinuxGUI/Ventoy2Disk/Web/ventoy_http.c) completely removes all EFI payloads from the in-memory FAT image before the USB device is exposed to the system.

```c
static int VentoyProcSecureBoot(int SecureBoot)
{
    if (SecureBoot) {
        vlog("Secure boot is enabled ...\n");
        return 0;                         // keep EFI files
    }

    /* Secure boot disabled → delete all EFI payloads from FAT image */
    fl_remove("/EFI/BOOT/BOOTX64.EFI");
    fl_remove("/EFI/BOOT/grubx64.efi");
    fl_remove("/EFI/BOOT/grubx64_real.efi");
    fl_remove("/EFI/BOOT/MokManager.efi");
    fl_remove("/EFI/BOOT/mmx64.efi");
    return 0;
}

```

## Windows-Side Secure Boot Bypass Implementation

For Windows installations, Ventoy provides an operating-system-level bypass that complements the firmware handling. In [`vtoyjump/vtoyjump/vtoyjump.c`](https://github.com/ventoy/Ventoy/blob/main/vtoyjump/vtoyjump/vtoyjump.c), the code writes the registry DWORD `BypassSecureBootCheck` with value `1` to `HKLM\System\Setup\LabConfig\` during the boot preparation phase.

This registry modification instructs the Windows boot manager to ignore Secure Boot validation failures, allowing installation on systems where the Ventoy certificate chain might not be recognized by the specific UEFI firmware signature database.

```c
/* vtoyjump.c – write the BypassSecureBootCheck key */
RegSetValueExA(hSubKey, "BypassSecureBootCheck", 0,
               REG_DWORD, (LPBYTE)&dwValue, sizeof(DWORD));

```

## UI Feedback and Persistent Configuration Storage

Ventoy propagates the Secure Boot detection state through its user interface components using the global boolean `g_SecureBoot` in [`Ventoy2Disk/WinDialog.c`](https://github.com/ventoy/Ventoy/blob/main/Ventoy2Disk/WinDialog.c). When `CurDrive->SecureBootSupport` is true, the UI displays a lock icon next to the selected target drive and activates the "Secure Boot Support" menu indicator.

The Secure Boot status persists across reboots through the GPT header extension field `SecureBootSupport`. The function `GetVentoyVerInPhyDrive()` in [`Ventoy2Disk/PhyDrive.c`](https://github.com/ventoy/Ventoy/blob/main/Ventoy2Disk/PhyDrive.c) reads this field from the Ventoy-installed USB drive, ensuring the UI reflects the correct state even after the device is reinserted or the system restarts.

```c
// In WinDialog.c – when the user selects a drive:
if (CurDrive->SecureBootSupport) {
    g_SecureBoot = CurDrive->SecureBootSupport;
    ShowWindow(g_DiskIconSecureHwnd, SW_NORMAL);
    ShowWindow(g_LocalIconSecureHwnd, SW_NORMAL);
} else {
    ShowWindow(g_DiskIconSecureHwnd, SW_HIDE);
    ShowWindow(g_LocalIconSecureHwnd, SW_HIDE);
}

```

## Summary

- **Ventoy queries the UEFI `SecureBoot` variable** via `gEfiGlobalVariableGuid` to detect firmware state, with a wrapper function that can force-disable the flag when users select bypass mode.
- **Different UEFI firmware signatures are handled by conditional binary presentation**: signed EFI files remain when Secure Boot is enabled, and all EFI executables are stripped when disabled to prevent validation errors.
- **Windows installations use a registry bypass** (`HKLM\System\Setup\LabConfig\BypassSecureBootCheck`) to skip OS-level Secure Boot checks regardless of firmware state.
- **The UI reflects real-time Secure Boot status** through global flags and persistent storage in the GPT header extension, displaying lock icons when the feature is active.

## Frequently Asked Questions

### How does Ventoy detect Secure Boot status on different firmware implementations?

Ventoy detects Secure Boot by calling `gRT->GetVariable` with the `SecureBoot` variable name and `gEfiGlobalVariableGuid` GUID, which is standardized across all UEFI 2.3+ implementations. The `ventoy_get_variable_wrapper` function in [`Ventoy.c`](https://github.com/ventoy/Ventoy/blob/main/Ventoy.c) intercepts this call to provide consistent results even on firmware that caches Secure Boot states before `ExitBootServices`.

### What happens when Secure Boot is disabled in Ventoy?

When Secure Boot is disabled or bypassed, the `VentoyProcSecureBoot` function deletes all EFI executables—including `BOOTX64.EFI`, `grubx64.efi`, and `MokManager.efi`—from the Ventoy FAT image before exposing the USB device to the firmware. This ensures the UEFI firmware encounters no binaries requiring signature validation.

### Does Ventoy work with ARM-based UEFI firmware?

Yes, Ventoy's Secure Boot detection mechanism relies on the standard UEFI variable interface defined in the UEFI specification, which is architecture-agnostic and implemented uniformly across x64, ARM32, and ARM64 UEFI firmware. The `ventoy_get_variable_wrapper` functions identically regardless of the underlying processor architecture.

### How does Ventoy bypass Secure Boot checks during Windows installation?

Ventoy writes the `BypassSecureBootCheck` registry DWORD (value `1`) to `HKLM\System\Setup\LabConfig\` via the [`vtoyjump.c`](https://github.com/ventoy/Ventoy/blob/main/vtoyjump.c) module before Windows Setup begins. This registry key instructs the Windows boot manager to skip Secure Boot validation, allowing installation to proceed even when the Ventoy EFI certificate is not enrolled in the firmware database.