path: root/src/Boot/EFI
diff options
authorMounir IDRASSI <>2016-08-17 16:51:17 +0200
committerMounir IDRASSI <>2016-08-17 17:06:21 +0200
commit0dc3cb7cd192e333365d1e4c4c0442c1306b0929 (patch)
tree3f0dbd61b955a176ee071d057c9c32cc8202427e /src/Boot/EFI
parentd4192bf863fdd4bb67b794d5834fbaa9efba658d (diff)
Add reference to VeraCrypt-DCS EFI Boot loader in Readme. Update copyrights.
Diffstat (limited to 'src/Boot/EFI')
1 files changed, 23 insertions, 1 deletions
diff --git a/src/Boot/EFI/Readme.txt b/src/Boot/EFI/Readme.txt
index 882c247a..f396b324 100644
--- a/src/Boot/EFI/Readme.txt
+++ b/src/Boot/EFI/Readme.txt
@@ -1,4 +1,26 @@
-To update secure boot configuration
+The source code for VeraCrypt EFI bootloader files is available at:
+Use tag "VeraCrypt_1.18" to extract the sources that were used when building VeraCrypt 1.18.
+VeraCrypt-DCS uses EDK II as its UEFI development environement.
+VeraCrypt-DCS is licensed under LGPL:
+Here the steps to build VeraCrypt-DCS (Visual Studio 2010 SP1 should be installed)
+ * Clone EDK: git clone edk2
+ * Switch to UDK2015 branche: git checkout UDK2015
+ * Clone VeraCrypt-DCS as DcsPkg inside edk2 folder: git clone DcsPkg
+ * Switch to VeraCrypt_1.18 branche: git checkout VeraCrypt_1.18
+ * Setup EDK by typing edksetup.bat at the root of folder edk2
+ * change directoty to DcsPkg and then type setenv.bat.
+ * change directory to DcsPkg\Library\VeraCryptLib and then type mklinks_src.bat: you will be asked to provide the path to VeraCrypt src folder.
+ * change directory to DcsPkg and then type dcs_bld.bat X64Rel
+ * After the build is finished, EFI bootloader files will be present at edk2\Build\DcsPkg\RELEASE_VS2010x86\X64
+Secure Boot:
+In order to allow VeraCrypt EFI bootloader to run when EFI Secure Boot is enabled, VeraCrypt EFI bootloader files are signed
+using a custom key whose public part can be loader into Secure Boot to allow the verification of VeraCrypt EFI files.
+below are instruction to update Secure Boot configuration:
1. Enter BIOS configuration
2. Switch Secure boot to setup mode (or custom mode). It deletes PK (platform certificate) and allows to load DCS platform key.
3. Boot Windows