Skip to content

Secure Boot in KVM Configuration

You can enable or disable the Secure Boot option when running the command to create a new virtual machine or after the virtual machine has been created.

In order to create a KVM virtual machine with Secure Boot enabled by default, use the following --boot parameters on the virt-install command when setting up your VM:

--boot loader=/usr/share/OVMF/OVMF_CODE.secboot.fd,\
loader.readonly=yes,loader.secure=yes,loader.type=pflash,\
nvram.template=/usr/share/OVMF/OVMF_VARS.secboot.fd \

In order to create a KVM virtual machine with Secure Boot disabled by default, use the following --boot parameters on the virt-install command when setting up your VM:

--boot loader=/usr/share/OVMF/OVMF_CODE.secboot.fd,\
loader.readonly=yes,loader.secure=yes,loader.type=pflash,\
nvram.template=/usr/share/OVMF/OVMF_VARS.fd \

You can enable Secure Boot on an existing virtual machine by editing its XML configuration. To disable Secure Boot, follow the instructions in the Secure Boot in UEFI section.

  1. Run the following command to use the nano editor:

    sudo EDITOR=/usr/bin/nano virsh edit vm-name

  2. Edit the os element as follows, specifying the name of your VM:

    <os>
        <type arch="x86_64" machine="q35">hvm</type>
        <firmware>
            <feature enabled='yes' name='enrolled-keys'/>
            <feature enabled='yes' name='secure-boot'/>
        </firmware>
        <loader readonly='yes' secure='yes' type='pflash' format='raw'>
            /usr/share/OVMF/OVMF_CODE.secboot.fd</loader>
        <nvram template='/usr/share/OVMF/OVMF_VARS.secboot.fd' 
        templateFormat='raw' format='raw'>
            /var/lib/libvirt/qemu/nvram/vm-name_VARS.fd</nvram>
        .
        .
        .
    </os>

    Make sure that the enrolled-keys and secure-boot features are enabled as shown above.

  3. Reset the NVRAM configuration by running the command below.

    Caution

    Resetting NVRAM will remove all VM-specific UEFI settings, including boot options and any certificates or keys enrolled after NVRAM was created.

    sudo virsh start vm-name --reset-nvram

After you have configured the Secure Boot option, you can enable/disable it in the UEFI menu.

Secure Boot in UEFI

Follow the steps below to enable or disable Secure Boot in UEFI.

  1. Start your KVM virtual machine and enter EXIT at the BOOTMGR> prompt.

  2. Press Esc. The UEFI screen will appear.

  3. Select Device Manager and then Secure Boot Configuration.

  4. Select the Attempt Secure Boot option and press Space to toggle the enabled/disabled state. The "X" symbol enables the Secure Boot option; empty square brackets ("[ ]") disable the Secure Boot option.

  5. Press Esc to exit the UEFI menu.