Record firmware versions, boot mode and Secure Boot state across the lab
Task
Build a firmware and driver inventory for every machine in your lab: firmware vendor and version, whether the machine boots in UEFI or legacy mode, whether Secure Boot is on, and the version of one important driver. This is the record a firmware update starts from, and the one that tells you afterwards whether the update actually applied.
Steps
- On Linux machines, save
dmidecode -t biostolab/firmware/<host>-bios.txt, and record whether/sys/firmware/efiexists and the output ofmokutil --sb-state. - On win-srv, save
Get-CimInstance Win32_BIOS | Format-Listtolab/firmware/win-srv-bios.txt, and record the output ofConfirm-SecureBootUEFIand the BIOS mode shown bymsinfo32. - For each machine, record the network adapter's driver and version:
ethtool -i <interface>on Linux,Get-NetAdapter | Format-List Name,DriverVersion,DriverProvideron Windows. - Write
lab/firmware/inventory.csvwith headerhost,firmware_vendor,firmware_version,boot_mode,secure_boot,nic_driver,nic_driver_version, with boot_mode writtenUEFIorLegacyas msinfo32 shows it. - For one machine, find the vendor's current firmware version for that model or hypervisor and record in
lab/firmware/gap.txtwhether an update is available.
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
ls lab/firmware/*-bios.txt | wc -l
grep -Eic 'Version|SMBIOSBIOSVersion' lab/firmware/*-bios.txt
awk -F, 'NR>1 && ($4=="UEFI" || $4=="Legacy") {n++} END {print n" host(s) with a boot mode"}' lab/firmware/inventory.csv
awk -F, 'NR>1 && NF>=7 {n++} END {print n" complete row(s)"}' lab/firmware/inventory.csv
grep -c . lab/firmware/gap.txt
Every host has a saved firmware record, a boot mode of UEFI or Legacy and a complete row. Hypervisor guests report the hypervisor's virtual firmware, which is itself worth noticing: in a VM, the firmware is part of the hypervisor and is updated with it.
Notes
A machine installed in UEFI mode will not boot if the firmware is switched to legacy, and the reverse. Recording the mode now is what lets you recognise that fault quickly in the boot failures lesson.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.