Mit Rufus erstellte USB-Sticks booten nicht wegen UEFI/Secure Boot

Antwort erstellen


Diese Frage dient dazu, das automatisierte Versenden von Formularen durch Spam-Bots zu verhindern.
Smileys
:) ;) :smile: :lol: :hihi: :D :rofl: :muahah: :( :pff: :kopfstreichel: :ohno: :betruebt: :heulen: :kopfkratz: :duckundweg: :o :? :oops: :psst: :sauer: :-P :daumenrunter: :daumen: :dankeschoen: :thx: :dafür: :gähn:
Mehr Smileys anzeigen

BBCode ist eingeschaltet
[img] ist eingeschaltet
[flash] ist ausgeschaltet
[url] ist eingeschaltet
Smileys sind eingeschaltet

Die letzten Beiträge des Themas

Ich habe die Datenschutzerklärung gelesen und bin damit einverstanden.

   

Ansicht erweitern Die letzten Beiträge des Themas: Mit Rufus erstellte USB-Sticks booten nicht wegen UEFI/Secure Boot

Re: Mit Rufus erstellte USB-Sticks booten nicht wegen UEFI/Secure Boot

von DK2000 » 08.09.2026, 12:18

Debian ab Version 10 geht mit Secureboot ohne Probleme, da die sich mit Microsoft geeinigt haben und die Secureboot Zertifikate von Windows verwenden dürfen. Hier muss man eigentlich nichts machen. Aber das ist von Distribution zu Distribution verschieden. Ein paar verwenden eigene Zertifikate, andere verwenden gar keine Zertifikate. Mit letzteren hat man dann Probleme in Verbindung mit Secureboot. Und GRML fällt da auch darunter. Da ist überhaupt nichts passend signiert.

Ventoy unterstützt Secureboot. Hier müssen die Vorrausetzungen passen:

https://www.ventoy.net/en/doc_secure.html

Allerdings, Ventoy für eine "Persistence Live Linux" unbrauchbar, da hier nicht in die ISO geschrieben werden kann. Das geht nur, wenn man einen passenden USB-Stick erstellt und das Live Linux das auch unterstützt. Ist leider auch nicht immer der Fall.

Bei Rufus weiß ich es jetzt nicht, ob dessen Dateien entsprechend für Secureboot signiert sind.

Das Problem mit Secureboot sind ja die Zertifikate. Alles was mit dem Booten zu tun hat, muss entsprechend signiert sein und im UEFI muss das passende Zertifikat in der DB hinterlegt sein. Ohne Signatur geht gar nichts und, falls nicht das Microsoft Zertifikat im UEFI verwendet werden darf, muss hier dann vorher ein entsprechendes gültiges Zertifikat in die UEFI DB eingespielt werden. Ansonsten geht hier auch nichts.

[ERLEDIGT] Re: Mit Rufus erstellte USB-Sticks booten nicht wegen UEFI/Secure Boot

von GwenDragon » 08.09.2026, 11:37

Irgendwo hat das BIOS F15 des Gigabyte einen weg. Ich musste es nun komplett neu flashen, damit Secure Boot deaktiviert bleibt, und USB-Sticks korrekt booten. Ich muss das mal längerfristig beobachten, ob nicht der Flashspeicher für das BIOS defekt ist.

Re: Mit Rufus erstellte USB-Sticks booten nicht wegen UEFI/Secure Boot

von Blondi_2021 » 07.09.2026, 19:57

Ja 2 .0 3.0 hab es wie @ Qwenn mit Rufus UEfi formatiert . Was mich wundert ist halt das weder Stick , Maus und Keybord erkannt werden beim einstecken . Will ja nicht den Thread entführen ;) . Secur Boot beim Brennen deinstalliert . Jetz ist auch noch abgetürtzt ich mach einen neuen Thread auf weil hat dann nichts mehr mit Qwenns Thread zu tun hat.

Re: Mit Rufus erstellte USB-Sticks booten nicht wegen UEFI/Secure Boot

von Linund11 » 07.09.2026, 19:37

Am besten ein Win-ISO bauen mit allen Treibern (und ohne Defender und Windows-Suche), sonst extrem lahm, könnte ja später nach dem Setup nach installiert werden.
-oder: Beim Lenovo S100 -IYB 11 eine USB-Tastatur nutzen für das Setup, die interne funkt gar nicht ohne Treiber.
ISO auf Stick -oder: micro.SD mit Win-Iso in den freien micro.SD-Slot stecken und von dort booten sollte auch gehen.

Re: Mit Rufus erstellte USB-Sticks booten nicht wegen UEFI/Secure Boot

von Holgi » 07.09.2026, 19:20

Blondi_2021 hat geschrieben: 07.09.2026, 18:06 an den Usb Ports nicht erkannt wird auch Maus und Tastatur nicht.
das klingt ja nach USB Port Problem.
Wenn du mehrere davon hast: schon mal an einem anderen versucht?
Unterschiedliche USB Sticks versucht?
Im BIOS/UEFI wegen USB Einstellungen geschaut? Alles ok dort?

Re: Mit Rufus erstellte USB-Sticks booten nicht wegen UEFI/Secure Boot

von Blondi_2021 » 07.09.2026, 18:06

habe da ein ähnliches Problem mit dem Lenovo S100 -IYB 11 und Usb Stick der nicht bootet mit Win 10. bzw an den Usb Ports nicht erkannt wird auch Maus und Tastatur nicht .Ja aktutuelles win 10 Home nach einigen Schwierigkeiten rödelt zwar immer noch da ja nur 2 GB Arbeitsspeicher . Hat da jemand einen Tip. Habe 10 Gb freigeschaufelt damit man es überhaupt installieren kann . Sorry @Qwenn wenn ich ich da mal mit reinhänge .

Re: Mit Rufus erstellte USB-Sticks booten nicht wegen UEFI/Secure Boot

von GwenDragon » 07.09.2026, 17:55

Mit zurück gesetzten Keys und Secure Boot off started SystemRescue von USB, kann dann über nicht das Root-System laden.
GRML probiere ich gleich noch. Na, wenigstens das klappt.

Re: Mit Rufus erstellte USB-Sticks booten nicht wegen UEFI/Secure Boot

von Linund11 » 07.09.2026, 17:01

DK2000 hat geschrieben: 07.09.2026, 15:36 Mit oder ohne Secureboot? Das geht aus Deinen Screenshots nicht hervor.
Hier funktioniert beides, hängt aber stark von der Hardware ab.
Kannst du auch in einem alten Screenshots lesen, wird dann virtuell vom UEFI erzeugt.

https://ibb.co/yBXYR3km
https://ibb.co/PG87dFXM
https://ibb.co/prx29H9t
https://ibb.co/mVCC2xPV

Re: Mit Rufus erstellte USB-Sticks booten nicht wegen UEFI/Secure Boot

von DK2000 » 07.09.2026, 15:36

Mit oder ohne Secureboot? Das geht aus Deinen Screenshots nicht hervor.

Re: Mit Rufus erstellte USB-Sticks booten nicht wegen UEFI/Secure Boot

von Linund11 » 07.09.2026, 14:35

GwenDragon hat geschrieben: 07.09.2026, 14:22 @DK2000 Danke für den Hinweis. Also nicht einfach nutzbar, ohne am BIOS der PCs rum zu basteln.

Also werde ich weiterhin Debian 12 Live nutzen.
Unter Linux-Mint (Live) einfach mit USB-Abbilderstellung auf einen USB-Stick schreiben und gut ist es, siehe hier mal kurz gemacht und UEFI-Boot durchgeführt, läuft eins a-

https://ibb.co/3m6Pxdz4
https://ibb.co/0RLz6QGZ
https://ibb.co/VW3bR8T4

Re: Mit Rufus erstellte USB-Sticks booten nicht wegen UEFI/Secure Boot

von GwenDragon » 07.09.2026, 14:22

@DK2000 Danke für den Hinweis. Also nicht einfach nutzbar, ohne am BIOS der PCs rum zu basteln.

Also werde ich weiterhin Debian 12 Live nutzen.

Re: Mit Rufus erstellte USB-Sticks booten nicht wegen UEFI/Secure Boot

von DK2000 » 07.09.2026, 13:22

Secureboot muss aus sein. Ansonsten bootet GRML nicht. Keine der Bootdateien ist in irgendeiner Form signiert, weswegen das UEFI mit dieser Meldung kommt.

Ich habe nur das gefunden;

https://github.com/grml/grml/issues/191 ... 3267866864

Letzter Eintrag war März 2026 und die sind wohl immer noch am Diskutieren, wie man da verfahren soll und das wohl schon seit 2022. Ich finde da auch nichts weiter, ob es da eine öffentliche ISO gibt, welche Secureboot unterstützt. Die aktuelle ISO 2026.09 unterstützt das jedenfalls nicht.

Re: Mit Rufus erstellte USB-Sticks booten nicht wegen UEFI/Secure Boot

von GwenDragon » 07.09.2026, 12:53

Ich bin nun wirklich nicht unerfahren mit bootable USB-Sticks, aber GRML raubt mir die Nerven …

@Linund11 Die Boot-Parameter, wo soll ich die denn setzen, wenn der Bootloader von USB nicht wegen Secure Boot lädt?

Bild

Wenn ich im BIOS auf Anderes Betriebssystem + CSM + UEFI schalte, klappt es nicht.

Re: Mit Rufus erstellte USB-Sticks booten nicht wegen UEFI/Secure Boot

von Holgi » 07.09.2026, 11:51

danke @Linund11
hab´sie mir gleich mal heruntergeladen und beiseite gelegt.

Re: Mit Rufus erstellte USB-Sticks booten nicht wegen UEFI/Secure Boot

von Linund11 » 07.09.2026, 11:25

@Gwen: Lesen in deinem Link steht doch alles.

Code: Alles auswählen

Booting related options:
------------------------
toram                            Copy the whole CD/medium to RAM and run from there
toram=filename.squashfs          Copy the specified file to RAM and run from there
                                 Usage example: grml toram=grml-medium.squashfs
                                 Notice: grml2ram is an alias for this option which
                                 corresponds with the grml flavour settings by default
bootfrom=/dev/sda1               Use the squashfs file from directory 'live' of the specified device
                                 Setup can be done by executing:
                                   rsync -a --progress /run/live/medium/live /media/sda1/
                                 NOTE: you can can also use bootfrom=/dev/disk/by-label/yourlabel
                                 (adjust yourlabel as needed), which should prevent choosing the
                                 wrong block device (e.g. if more than one disk is present).
bootfrom=removable               Restrict search for the live media to removable type only.
bootfrom=removable-usb           Restrict search for the live media to usb mass storage only.
isofrom=[fs:][/device]/grml.iso  Use specified ISO image for booting.
                                 Useful when booting as a rescue system from a different device.
                                 If you want to load the image from a device different from the root device
                                 specified through the bootloader, prefix its device path to the path, like
                                 in "/dev/sda1/grml.iso".
                                 Internally, the initrd will mount the given device, automatically detecting
                                 the file system.
                                 If needed, prefix the file system separated with a colon character to
                                 override the automatic detection, like in "ext4:/dev/sda1/grml.iso".
                                 As an example, boot the according grml kernel and initrd using the
                                 bootoptions "boot=live isofrom=btrfs:/dev/vda40/path/to/grml.iso"
                                 NOTE: "fromiso" does the same as "isofrom", it's just there
                                 to prevent any typing errors
                                 NOTE: you can can also use isofrom=/dev/disk/by-label/yourlabel
                                 (adjust yourlabel as needed), which should prevent choosing the
                                 wrong block device (e.g. if more than one disk is present).
findiso=/grml-....iso            Look for the specified ISO file on all disks where it usually
                                 looks for the .squashfs file (so you don't have to know the device name
                                 as in isofrom=....).
fetch=$IP/filename.squashfs      Download a squashfs image from a given url, copying to ram and booting it.
live-media-path=/live/grml...    Sets the path to the live filesystem on the medium
                                 By default, it is set to /live/$GRML_FLAVOUR/ (where $GRML_FLAVOUR
                                 is corresponding to grml64-full, grml32-full, grml64-small,...
                                 [Note: this parameter is mandatory]
module=grml                      Instead of using the default "$name.module" another file can
                                 be specified without the extension ".module"; it should be placed
                                 on "/live" directory of the live medium
                                 Useful for Multiboot USB pen, see
                                 https://wiki.grml.org/doku.php?id=tips#multiboot_usb_pen
bootid=mybootid                  Use specified argument as identifier for the ISO.
                                 mybootid is specified in /conf/bootid.txt on the ISO.
ignore_bootid                    Disable bootid verification.
@Holgi: Die 2.18 ist am besten für Linux und DD, da als einzige kompatibel mit fast allen ISO.
Viele neue Rufus Versionen funken nicht mit alten DD Linux ISO

Nach oben