Express-SL/SLE
79
7.5.3
Security > Secure Boot menu > Key Management
Feature
Options
Description
Provision Factory Default Keys
Disabled
Enabled
Install factory default Secure Boot Keys when system is in Setup
Mode
Enroll all Factory Default Keys
Force System to User Mode:
Install all Factory Default Keys (PK,KEK,db,dbt).
Change takes effect after reboot.
Save all Secure Boot variables
Save NVRAM content of all Secure Boot variables to the files
(EFI_SIGNATURE_LIST data format) in root folder on a target file
system device
Platform Key (PK)
Set New Key
Enroll Factory Defaults or load the keys from a file with:
1. Public Key Certificate in:
a) EFI_SIGNATURE_LIST
b) EFI_CERT_X509 (DER encoded)
c) EFI_CERT_RSA2048 (bin)
d) EFI_CERT_SHA256 (bin)
2. Authenticated UEFI Variable
Key Source: Default , Custom, Mixed
Key Exchange Keys
Set New Key
Append Key
Enroll Factory Defaults or load the keys from a file with:
1. Public Key Certificate in:
a) EFI_SIGNATURE_LIST
b) EFI_CERT_X509 (DER encoded)
c) EFI_CERT_RSA2048 (bin)
d) EFI_CERT_SHA256 (bin)
2. Authenticated UEFI Variable
Key Source: Default , Custom, Mixed
Authorized Signatures
Set New Key
Append Key
Enroll Factory Defaults or load the keys from a file with:
1. Public Key Certificate in:
a) EFI_SIGNATURE_LIST
b) EFI_CERT_X509 (DER encoded)
c) EFI_CERT_RSA2048 (bin)
d) EFI_CERT_SHA256 (bin)
2. Authenticated UEFI Variable
Key Source: Default , Custom, Mixed
Forbidden Signatures
Set New Key
Append Key
Enroll Factory Defaults or load the keys from a file with:
1. Public Key Certificate in:
a) EFI_SIGNATURE_LIST
b) EFI_CERT_X509 (DER encoded)
c) EFI_CERT_RSA2048 (bin)
d) EFI_CERT_SHA256 (bin)
2. Authenticated UEFI Variable
Key Source: Default , Custom, Mixed
Authorized TimeStamps
Set New Key
Append Key
Enroll Factory Defaults or load the keys from a file with:
1. Public Key Certificate in:
a) EFI_SIGNATURE_LIST
b) EFI_CERT_X509 (DER encoded)
c) EFI_CERT_RSA2048 (bin)
d) EFI_CERT_SHA256 (bin)
2. Authenticated UEFI Variable
Key Source: Default , Custom, Mixed