Skip to content

Secure Boot Overview

Starting with VSI OpenVMS E9.2-4, the Secure Boot feature is supported via the First Stage Bootloader.

The OpenVMS Boot Manager is signed with an OpenVMS-specific certificate and is validated by the First Stage Bootloader before it is loaded. To establish trust between the First Stage Bootloader and OpenVMS, the OpenVMS signing certificate must be added to the First Stage Bootloader's Machine Owner Key (MOK) database as described in Adding OpenVMS Certificate to the Machine Owner Key Database.

Once the certificate is registered and the Secure Boot option is enabled, OpenVMS can boot successfully while maintaining the Secure Boot chain of trust.

Use the following command to see whether Secure Boot is enabled on your system:

$ WRITE SYS$OUTPUT F$GETSYI("SECURE_BOOT")
Output Description
0 Disabled
1 Enabled

For more information, see VSI OpenVMS Guide to System Security.