Skip to content

Adding OpenVMS Certificate to the Machine Owner Key Database

In order to boot VSI OpenVMS with Secure Boot enabled, you must register the OpenVMS key in the Machine Owner Key (MOK) database.

There are two methods to do so: manual and automatic. For automatic registration, ensure that OpenVMS has been booted at least once before enabling Secure Boot.

  1. Enable Secure Boot as described in the Secure Boot Option section and start your virtual machine.

  2. The UEFI key management utility will load. You will see a countdown at the bottom of the screen. Press Enter before it runs out and the system starts booting.

  3. Use the arrow keys to select Enroll key from disk and press Enter.

  4. Locate the VMS_CERTIF.DER file at the following path: your-disk/EFI/VMS/VMS_CERTIF.DER.

  5. Select Continue.

  6. At the Enroll the key(s)? prompt, select Yes.

  7. Select Reboot.

  8. Now you will be able to boot to the OpenVMS Boot Manager with Secure Boot.

The OpenVMS Boot Manager automatically registers the certificate when the First Stage Bootloader is present.

  1. Boot OpenVMS with Secure Boot disabled so that the certificate is registered automatically.

  2. Shut down OpenVMS.

  3. Enable Secure Boot in the UEFI as described in the Secure Boot Option section.

  4. You will now be able to boot to the VSI Boot Manager with Secure Boot enabled.