In this Hackintosh HowTo I will show you how to enable SecureBoot to get Full Security in macOS and Windows11.
AGENDA
00:00 Intro
00:45 What is SecureBoot?
01:40 Relevant Settings
02:49 Overview of the steps
03:35 Step 1: Create Backup stick with disabled SecureBoot
04:25 Step 2: Prepare config.plist for SecureBoot
05:34 Step 3: Enable SecureBoot in BIOS
06:40 Step 4: Enroll .efi files in BIOS
08:21 Step 5: Bless Macintosh Partition in macOS Recovery
10:28 Step 6: Boot into macOS
11:26 Step 7: Calculate ApECID
12:15 Step 8: Add ApECID in config.plist
13:06 Step 9: Check Full Security in macOS
14:35 Step 10: Check SecureBoot State in Windows
DORTHANIA GUIDE
➡️ Dorthania Guide: https://dortania.github.io/OpenCore-P...
SCRIPT
➡️ What is Secure Boot?
„Secure Boot“ is a feature of the UEFI-BIOS. SecureBoot makes sure, that important firmware elements like the (Windows or OpenCore) Bootloader will only start if they haven’t been manipulated.
macOS Security Levels: No Security, Medium Security, Full Security
➡️ Why enable Secure Boot?
Windows 11 requires SecureBoot and TPM 2.0. Also games e.g. Valorant require it.
Mix of macOS/Windows 11 with OpenCore without working SecureBoot is not working well.
➡️ HowTo Enable SecureBoot?
Within my video I assume you have preinstalled Windows/macOS, use OpenCore and have Secure Boot disabled
Relevant Settings:
config.plist:
Misc->Security
SecureBootModel=Disabled
ApecID=0
NVRAM->7C436110-AB2A-4BBB-A880-FE41995C9F82
csr-active-config=00000000
BIOS:
Security Chip/TPM 2.0 enabled
Intel Platform Trust Technology=Enabled
Secure Boot=Enabled
Secure Boot Mode = Custom
Step 1: Create a Backup Stick with SecureBoot Disabled in config.plist:
Misc->Security
SecureBootModel=Disabled
ApecID=0
Step 2: Prepare Config.plist for SecureBoot
Config.plist:
SecureBootModel: j137 (for iMacPro1,1. See Dorthania Guide for the SecureBootModel that fits your SMBIOS)
ApECID: 0
csr-active-config: 00000000
Step 3: Enable Secure Boot in BIOS
Security Chip/TPM 2.0:enabled
Intel Platform Trust Technology: Enabled
Secure Boot: Enabled
Secure Boot Mode: Custom
Step 4: Enroll all penCore EFIs in BIOS (otherwise OpenCore won’t boot with SecureBoot enabled)
Key Management
Enroll all EFIs from OpenCore: Bootx64.efi, OpenCore.efi and all driver .efi’s
Step 5: Bless Macintosh Partition in macOS Recovery
Terminal command:
bless --folder "/Volumes/Macintosh HD/System/Library/CoreServices" --bootefi --personalize
Step 6: Calculate ApECID
Terminal command (requires Python installed):
python3 -c ‘import secrets; print(secrets.randbits(64))’
Step 7: Add ApecID in config.plist
Misc->Security
ApECID=<your ApECID>
Step 8: Check Security Status within macOS
Terminal command:
nvram 94b73556-2197-4702-82a8-3e1337dafbfb:AppleSecureBootPolicy
Attention: You might have to repeat steps if you upgrade OpenCore (except to calculate a new ApECID, it shouldn't change with OpenCore Updates)
PC SPECS
-------------------------------------------------------
➡️ Case | NCASE M1.
➡️ CPU | i9-11900k.
➡️ MB | Gigabyte Z590i Vision D.
➡️ GPU1 (for Windows) | Zotac Trinity 3090
➡️ GPU2 (for macOS) | AMD Pro W5500
➡️ RAM | 32GB G.Skill Trident-Z 3600Mhz CL18.
➡️ WiFi/BT | BCM94360NG. Replaces the onboard Wifi 6. Plug & Play. The onboard Wifi sits in a m.2 Slot. The original antennas fit on the BCM94360NG. https://de.aliexpress.com/i/400063236...
➡️CPU-cooler: Kraken X53.
➡️ Bottom Fans | 2x Noctua NF-A12x25 PWM.120mm. Exhaust for GPU. Controlled by the GPU.
➡️ Side Panel Fans | 2x Noctua NF-F12 Chromax.120mm. Exhaust for CPU. Replacing the AiO Arctic P12 Fans.
➡️ Back Fans | 1x Noctua AF-9 PWM Chromax.92mm. Intake.
➡️ PSU | Corsair SF750.
CAMERA GEAR
-------------------------------------------------------
►Sony A7SIII
►Sony A7RIV
►Sony 24mm f1.4 GM
►Sony 24-105mm f4
►Sony 16-35mm f2.8 GM
►Tamron 70-300mm f4.5-6.3
Retro Lenses via Yashica Contax Adapter
►Carl Zeiss 50mm f1.4
►Carl Zeiss 35mm f2.8
►Carl Zeiss 28mm f2.8
LIGHT GEAR
----------------------------------------------------
►Aputure 120D
►Godox SL60W
SOUND GEAR
----------------------------------------------------
►SHURE SM7B
►RODE NTG3
►RODE VideoMicro
►Zoom H5