EP2C622D16-2T
74
75
English
Remove 'UEFI CA' from DB
Device Guard ready system must not list ‘Microsoft UEFI CA’ Certificate in Autho-
rized Signature database (db).
Restore DB Defaults
Restore DB variable to factory defaults.
Platform Key(PK)
Enroll Factory Defaults or load certificates from a file:
1. Public Key Certificate in:
a) EFI_SIGNATURE_LIST
b) EFI_CERT_X509 (DER encoded)
c) EFI_CERT_RSA2048 (bin)
d) EFI_CERT_SHA256, 384, 512
2. Authenticated UEFI Variable
3. EFI PE/COFF Image(SHA256)
Key Source: Default, External, Mixed, Test
Key Exchange Keys
Enroll Factory Defaults or load certificates from a file:
1. Public Key Certificate in:
a) EFI_SIGNATURE_LIST
b) EFI_CERT_X509 (DER encoded)
c) EFI_CERT_RSA2048 (bin)
d) EFI_CERT_SHA256, 384, 512
2. Authenticated UEFI Variable
3. EFI PE/COFF Image(SHA256)
Key Source: Default, External, Mixed, Test
Authorized Signatures
Enroll Factory Defaults or load certificates from a file: