Chapter
4:
UEFI
BIOS
SMCI
Security
Erase
Configuration
Secure
Boot
This
section
contains
options
and
menus
for
securing
your
boot
mode
and
for
key
management.
Secure
Boot
This
option
allows
you
specify
when
the
Platform
Key
(PK)
is
enrolled.
When
enabled,
the
System
Mode
is
user
deployed,
and
the
CSM
function
is
disabled.
Options
include
Disabled
and
Enabled.
Secure
Boot
Mode
Use
this
item
to
select
the
secure
boot
mode.
The
options
are
Standard
and
Custom
.
CSM
Support
Select
Enabled
to
support
the
EFI
Compatibility
Support
Module
(CSM),
which
provides
compatibility
support
for
traditional
legacy
BIOS
for
system
boot.
The
options
are
Disabled
and
Enabled
.
Key
Management
This
submenu
allows
the
user
to
configure
the
following
Key
Management
settings.
Vendor
Keys
Provision
Factory
Defaults
This
feature
is
to
provision
the
default
secure
boot
keys
set
by
the
manufacturer
when
system
is
in
the
Setup
mode.
The
options
are
Disabled
and
Enabled.
Restore
Factory
Keys
Select
and
press
Yes
to
restore
factory
default
secure
boot
keys
and
key
variables.
Also,
it
will
reset
the
system
to
the
User
mode.
Select
Yes
to
install
all
default
secure
keys
set
by
the
manufacturer.
The
options
are
Yes
and
No.
Reset
To
Setup
Mode
Select
and
press
Yes
to
clear
all
secure
boot
variables
and
reset
the
system
to
the
Setup
mode.
This
option
allows
you
to
delete
all
Secure
Boot
key
databases
from
NVRAM.
The
options
are
Yes
and
No.
Export
Secure
Boot
variables
Use
this
feature
to
export
NVRAM
content
of
secure
boot
variables
to
files
in
a
root
folder
on
a
file
system
device.
Enroll
Efi
Image
This
feature
is
to
enroll
SHA256
hash
of
the
binary
into
the
Authorized
Signature
Database
(DB)
and
to
allow
the
image
to
run
in
the
secure
boot
mode.
85