Bonjour Christine et Abdelhafid,
Pour info :
J'ai pris contact avec le concepteur de Rufus pour évoquer avec lui la solution d'une clé usb universelle ( cle MBR à 2 partitions créées par Diskpart ) ne nécessitant pas de désactiver le Secure Boot.
Il connaissait le principe et m'a rapidement répondu en indiquant ses arguments pour conserver le mode actuel de Rufus dans la réponse ( en anglais ) ci-après :
>>> Mon message initial :
On 2018.12.10 13:36, HDUBAIL wrote:
> Hello,
>
> I found on the Net how to build an usb key which contains _install.wim
> or .esd file greater than 4 Gb_ and can boot on an Uefi system *without
> desactiving the Secure Boot.*
>
> The method consists on creating two partitions ( one small FAT32
> partition and a big NTFS one ) :
>
> * The FAT32 partition contains files bootmgr and bootmgr.efi , folders
> \boot and \efi, and file \sources\boot.wim copied from the iso file
> * The NTFS partition contains all the files and folders from the iso file
>
> When the usb key has a MBR structure and the FAT32 is active, such a key
> can be used *both* on bios/mbr or bios/uefi sytem with Secure Boot active.
>
> The method can be used whatever size has the install file and for all
> systems.
>
> Do you know such a way, which could be easily implemented in Rufus ?
>
> Henri DUBAIL
>
>>> La réponse :
Hi Henri,
Yes, I am well aware of the method you describe.
However I don't see the point of implementing it when:
- It adds unwarranted complexity and is not as future-proof as UEFI:NTFS
when Microsoft may suddenly decide, for Windows 11 or later, that they
need more than \boot, \efi and boot.wim on the first partition. With
UEFI:NTFS you are certain to always have all the files needed on the
same partition
- If you believe that *temporarily* disabling Secure Boot, as is needed
with UEFI:NTFS, is going to reduce the security of your system, then I'm
afraid you have been brainwashed into believing that because something
says "Secure", you should not disable it ever. I therefore encourage you
to read
- UEFI:NTFS can also be used to create systems that can be used on
*both* UEFI and BIOS. The logic that disables dual BIOS+UEFI in Rufus
has nothing to do with the 4 GB limitation. It is a design choice to
avoid inexperienced people installing Windows in BIOS mode when they
wanted UEFI (again, this is explained in the FAQ:
But if you use the Alt-E cheat mode, you will see that Rufus has no
issue creating dual BIOS + UEFI bootable installation drives, even with
a >4GB install.wim.
- Considering that Microsoft is most definitely using Secure Boot as a
means to extinguish the licenses they don't like, such as GPLv3, and are
therefore happy to let misinformation about disabling Secure Boot being
a big NO_NO spread, I feel it is my duty to provide a counter point and
spread the message that, no, temporarily disabling Secure Boot will not
get you malware, especially if you use official OS images and validate
their SHA (as you should *always* do before you install an OS). Instead
you should be very weary when a single entity (Microsoft) effectively
acts as the gatekeeper of what *YOU* can and cannot run on the computer
that *YOU* own.
- You seem to imply that it would be "easily" implemented in Rufus. I
beg to differ, especially as only later versions of Windows 10 can mount
multiple partitions at once from removable media, which means Windows 7
and Windows 8 users (as well as Windows 10 users who haven't upgraded to
the latest releases) would be left stranded. Also this would require
computing the size needed for the additional partition as well as other
supposedly small matters that eventually ad up to make it less easy to
implement that people imagine.
To conclude, I will just say that Rufus has solved the issue of >4GB
install.wim a long time ago.
If you are paranoid to the point that you think that temporarily
disabling Secure Boot is not an option, then I will kindly ask you to
use a different utility, or manually create the media with the
partitions described, which should be fairly easy if you are using a
recent version of Windows 10.
Regards,
/Pete