Secure boot on Dell Optiplex 7020 not working

Hi Balena Team,

we are trying to install the secure boot image of balena os to an Dell Optiplex 7020. The non secure boot image is working without any problem.

So if we try to install we clear tpm, clear keys and put the secure boot to audit mode (we think this is the setup mode on Dell bios).

If we boot now from the secure boot image at first all looks good. We don´t see anything on the screen, but after a minute or two the device shut down. Than we put out the stick and reboot the device but now we got the error that no signed os is installed.

If we go to bios we can see that the tpm2 don´t have new keys so we can´t delete it in bios because it is empty.

Also if we try to upload the keys (.auth) of the usb stick to secure boot we got no other result.

Do you have any info here how we can setup this?

Thanks

Rainer

Hello, have you checked the requirements and followed the steps in this guide: Setup secure boot and full disk encryption for Generic x86_64 (GPT) | balena docs

Hi, yes, I did all the steps but the result is allways the same…

Even after a full UEFI factory reset and following the exact official setup steps (Setup docs), including using the latest balenaOS version (7.7.0, well above the recommended 6.5.24+ for the PCR7 stability fix), the device still enters the same boot loop. This suggests the issue is not the previously-documented PCR1 instability, but a separate, currently undocumented incompatibility with this specific Dell OptiPlex 7020 (2024) BIOS/TPM implementation.