How to install Windows server with UEFI?

0

To install SW_DVD9_Windows_Svr_Std_and_DataCtr_2012_R2_64Bit_English_-4_MLF_X19-82891 on to an RD230 server in UEFI mode secure boot must be enabled, correct?

The ISO was written to USB with Rufus with UEFI mode selected.

While I didn't capture the note, Rufus seemed to, as I recall, indicate that secure boot should be disabled. Surely secure boot should be enabled for UEFI.

--

reference:

https://en.wikipedia.org/wiki/Unified_Extensible_Firmware_Interface

Thufir

Posted 2019-03-05T20:51:14.143

Reputation: 876

This subject seems to be well covered: install windows server uefi. There's no sense in rehashing the steps that are all across the web. You should probably state a problem you are having so someone can field an answer.

– jww – 2019-03-05T20:52:24.937

1Windows Server 2012 R2 is based on Windows 8.1 not Windows 10 – Ramhound – 2019-03-05T21:04:13.647

@Ramhound, why is it significant that Windows Server 2012 R2 is based on Windows 8.1 and not Windows 10? – Thufir – 2019-03-05T21:14:38.660

Because you provided a link about Windows 10/Server 2016. There are some significant differences between Windows 8.1 and Windows 10. – Ramhound – 2019-03-05T21:16:03.983

I see, okay. My fault then. – Thufir – 2019-03-05T21:17:35.993

How about you just try it. I may be wrong but i think if you get it wrong then you just get an error and it won't install? – barlop – 2019-03-05T21:17:44.190

Fair enough. Another person tried many times in UEFI mode. Right now it's installed in Legacy mode, so we might just leave it there. However, with legacy mode, MBR has a hard drive size limitation. So, yes, will likely try with UEFI. – Thufir – 2019-03-05T21:19:23.687

You can’t use MBR and UEFI with any version of Windows. – Ramhound – 2019-03-05T21:33:53.880

Answers

2

Surely secure boot should be enabled for UEFI

Rufus only asks you to temporarily disable Secure Boot, and the reason it needs to do that is because, if your ISO contains a file that is larger than 4GB, then you cannot use FAT32 to write it but have to use NTFS (as FAT32 cannot accommodate files that are larger than 4GB, a technical limitation of that file system). But this means that you also need an NTFS UEFI driver & bootloader to boot that drive in UEFI mode.

Rufus can and does install those files for you. However, because of Microsoft's arbitrary decisions (point 4 here) with regards to what can and cannot be signed for Secure Boot, the files that Rufus uses, which are licensed under the GPLv3, cannot be signed for Secure Boot, which means that Secure Boot must be TEMPORARILY disabled for the first boot where the NTFS bootloader has to be used. But of course you can reenable it afterwards, and you should understand that, because Rufus is itself digitally signed and if you have validated the SHA-1 of the Windows ISO you used, temporarily disabling Secure Boot is not as great a security risk as people tend to believe (in other words it's not because it's called "Secured Something" that it should never be disabled, ever).

For more information on this, you can read this entry from the Rufus FAQ.

But again, the message you have gotten for Rufus did mention very explicitly (I know, because I'm the one who wrote that message) that the disabling of Secure Boot was only to be temporary. Oh, and I also made sure that, besides that message, there was a direct link to the FAQ entry I pointed above, that user can consult if they need more info about why Rufus asks them to temporarily disable Secure Boot. So please try to also pay attention to what the application tells you, as it might answer your questions...

Akeo

Posted 2019-03-05T20:51:14.143

Reputation: 3 236

I haven't tried it yet, but are there issues with getting a large RAID disk recognized by the install media? – Thufir – 2019-03-07T16:51:10.237

1Shouldn't be, if you have the relevant Windows drivers injected in your media (provided that Windows doesn't have them by default) or can provide them during the installation process. – Akeo – 2019-03-08T12:26:57.203