How Ventoy Handles Secure Boot Validation Across Different UEFI Firmware Signatures

Ventoy validates Secure Boot by querying the UEFI SecureBoot variable, selectively presenting signed EFI binaries when enabled, and stripping all executable payloads when disabled to prevent firmware signature verification failures.

The ventoy/Ventoy repository implements a multi-layered Secure Boot handling mechanism that adapts to diverse UEFI firmware implementations from Intel, AMD, ARM, and various OEM vendors. According to the source code, Ventoy does not perform signature validation itself; instead, it controls whether signed EFI binaries are exposed to the firmware or removed entirely based on the detected Secure Boot state and user preferences.

UEFI Firmware Detection and Variable Parsing

Ventoy detects the Secure Boot state by querying the UEFI SecureBoot variable using the globally unique identifier gEfiGlobalVariableGuid. In EDK2/edk2_mod/edk2-edk2-stable201911/MdeModulePkg/Application/Ventoy/Ventoy.c, the function ventoy_get_variable_wrapper intercepts calls to gRT->GetVariable to read this firmware state.

When the user elects to bypass Secure Boot, this wrapper forces the return value to 0 (disabled) even if the firmware reports it as active. This manipulation occurs after ExitBootServices has been invoked, ensuring that cached Secure Boot states in different UEFI implementations are overridden consistently.

The GRUB2 module in GRUB2/MOD_SRC/grub-2.04/grub-core/ventoy/ventoy_cmd.c independently reads the same variable via grub_efi_get_variable("SecureBoot", ...) to expose the flag to GRUB scripts, maintaining state consistency across the boot chain.

/* ventoy_get_variable_wrapper – forces SecureBoot = 0 when bypassed */
EFI_STATUS EFIAPI ventoy_get_variable_wrapper(
    IN CHAR16 *VariableName,
    IN EFI_GUID *VendorGuid,
    OUT UINT32 *Attributes OPTIONAL,
    IN OUT UINTN *DataSize,
    OUT VOID *Data OPTIONAL)
{
    EFI_STATUS Status = g_org_get_variable(VariableName, VendorGuid,
                                            Attributes, DataSize, Data);
    if (StrCmp(VariableName, L"SecureBoot") == 0 && *DataSize == 1 && Data) {
        *(UINT8 *)Data = 0;               // fake “SecureBoot disabled”
    }
    return Status;
}

Cross-Platform UEFI Firmware Compatibility

UEFI firmware from different manufacturers (e.g., AMI, Phoenix, Insyde, or ARM vendors) validates EFI binary signatures using platform-specific keys enrolled in the firmware database. Ventoy handles these different UEFI firmware signatures through a binary presence strategy rather than signature manipulation.

Secure Boot Enabled: Ventoy preserves its signed EFI binaries—including grubx64_real.efi, MokManager.efi, and BOOTX64.EFI—within the EFI System Partition. These binaries carry valid signatures from the Ventoy project or Microsoft, allowing standard UEFI Secure Boot validation to succeed across all compliant firmware implementations.

Secure Boot Disabled: Ventoy guarantees that no EFI executable is presented to the firmware, preventing signature verification failures on strict implementations. The VentoyProcSecureBoot function in LinuxGUI/Ventoy2Disk/Web/ventoy_http.c completely removes all EFI payloads from the in-memory FAT image before the USB device is exposed to the system.

static int VentoyProcSecureBoot(int SecureBoot)
{
    if (SecureBoot) {
        vlog("Secure boot is enabled ...\n");
        return 0;                         // keep EFI files
    }

    /* Secure boot disabled → delete all EFI payloads from FAT image */
    fl_remove("/EFI/BOOT/BOOTX64.EFI");
    fl_remove("/EFI/BOOT/grubx64.efi");
    fl_remove("/EFI/BOOT/grubx64_real.efi");
    fl_remove("/EFI/BOOT/MokManager.efi");
    fl_remove("/EFI/BOOT/mmx64.efi");
    return 0;
}

Windows-Side Secure Boot Bypass Implementation

For Windows installations, Ventoy provides an operating-system-level bypass that complements the firmware handling. In vtoyjump/vtoyjump/vtoyjump.c, the code writes the registry DWORD BypassSecureBootCheck with value 1 to HKLM\System\Setup\LabConfig\ during the boot preparation phase.

This registry modification instructs the Windows boot manager to ignore Secure Boot validation failures, allowing installation on systems where the Ventoy certificate chain might not be recognized by the specific UEFI firmware signature database.

/* vtoyjump.c – write the BypassSecureBootCheck key */
RegSetValueExA(hSubKey, "BypassSecureBootCheck", 0,
               REG_DWORD, (LPBYTE)&dwValue, sizeof(DWORD));

UI Feedback and Persistent Configuration Storage

Ventoy propagates the Secure Boot detection state through its user interface components using the global boolean g_SecureBoot in Ventoy2Disk/WinDialog.c. When CurDrive->SecureBootSupport is true, the UI displays a lock icon next to the selected target drive and activates the "Secure Boot Support" menu indicator.

The Secure Boot status persists across reboots through the GPT header extension field SecureBootSupport. The function GetVentoyVerInPhyDrive() in Ventoy2Disk/PhyDrive.c reads this field from the Ventoy-installed USB drive, ensuring the UI reflects the correct state even after the device is reinserted or the system restarts.

// In WinDialog.c – when the user selects a drive:
if (CurDrive->SecureBootSupport) {
    g_SecureBoot = CurDrive->SecureBootSupport;
    ShowWindow(g_DiskIconSecureHwnd, SW_NORMAL);
    ShowWindow(g_LocalIconSecureHwnd, SW_NORMAL);
} else {
    ShowWindow(g_DiskIconSecureHwnd, SW_HIDE);
    ShowWindow(g_LocalIconSecureHwnd, SW_HIDE);
}

Summary

  • Ventoy queries the UEFI SecureBoot variable via gEfiGlobalVariableGuid to detect firmware state, with a wrapper function that can force-disable the flag when users select bypass mode.
  • Different UEFI firmware signatures are handled by conditional binary presentation: signed EFI files remain when Secure Boot is enabled, and all EFI executables are stripped when disabled to prevent validation errors.
  • Windows installations use a registry bypass (HKLM\System\Setup\LabConfig\BypassSecureBootCheck) to skip OS-level Secure Boot checks regardless of firmware state.
  • The UI reflects real-time Secure Boot status through global flags and persistent storage in the GPT header extension, displaying lock icons when the feature is active.

Frequently Asked Questions

How does Ventoy detect Secure Boot status on different firmware implementations?

Ventoy detects Secure Boot by calling gRT->GetVariable with the SecureBoot variable name and gEfiGlobalVariableGuid GUID, which is standardized across all UEFI 2.3+ implementations. The ventoy_get_variable_wrapper function in Ventoy.c intercepts this call to provide consistent results even on firmware that caches Secure Boot states before ExitBootServices.

What happens when Secure Boot is disabled in Ventoy?

When Secure Boot is disabled or bypassed, the VentoyProcSecureBoot function deletes all EFI executables—including BOOTX64.EFI, grubx64.efi, and MokManager.efi—from the Ventoy FAT image before exposing the USB device to the firmware. This ensures the UEFI firmware encounters no binaries requiring signature validation.

Does Ventoy work with ARM-based UEFI firmware?

Yes, Ventoy's Secure Boot detection mechanism relies on the standard UEFI variable interface defined in the UEFI specification, which is architecture-agnostic and implemented uniformly across x64, ARM32, and ARM64 UEFI firmware. The ventoy_get_variable_wrapper functions identically regardless of the underlying processor architecture.

How does Ventoy bypass Secure Boot checks during Windows installation?

Ventoy writes the BypassSecureBootCheck registry DWORD (value 1) to HKLM\System\Setup\LabConfig\ via the vtoyjump.c module before Windows Setup begins. This registry key instructs the Windows boot manager to skip Secure Boot validation, allowing installation to proceed even when the Ventoy EFI certificate is not enrolled in the firmware database.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →