Home · Secure Boot guide

Ventoy Secure Boot guide

Secure Boot is a firmware policy, not a Ventoy feature you should enable on every stick. Turn it on when the PCs you support refuse unsigned bootloaders. Leave it off for lab machines that already run in setup mode, or when you are still proving that the USB enumerates at all.

This is independent documentation on ventoy.io. Follow the Secure Boot notes bundled with your Ventoy release if they differ from this checklist.

When to enable it

Setup workflow

  1. Install or update Ventoy with the Secure Boot option enabled in Ventoy2Disk (Windows) or the matching flag in Ventoy2Disk.sh.
  2. Boot the USB. The first start often opens a key-enrollment screen (firmware prompt or MokManager, depending on the machine).
  3. Enroll the Ventoy key once. Do not enroll, reboot, and enroll again in a loop.
  4. Reboot from the USB and confirm the image list appears without a signature warning.
  5. Start one Linux live ISO you already trust. If that works, test the Windows installer ISO you actually need.

Common failures

What not to do

Do not disable Secure Boot on a work PC just to “make USB boot work” if policy forbids it. Do not mix random bootloader files onto the EFI partition. Update Ventoy from a verified package if a new firmware revision starts rejecting an older stick.