Hi!
How should I enable Secure Boot? Custom or standard?
Standard should be used unless signing the boot uefi files with a custom key.
Thinking about it, I’m not sure if enabling Secure Boot is risky with the Windows CA certificate issue. Chuwi doesn’t seem likely to release a BIOS update to adapt to the new certificates.
What do you think?
Windows should be able to update the certs in the firmware database regardless of Chuwi releasing an update.
I’ve read on several sites that if they can’t be updated, it’s the manufacturer who must implement it through a BIOS update.