3.5.1 Key Management
In this section, expert users can modify Secure Boot Policy variables without full authenti-
Factory Key Provision
Install factory default Secure Boot keys after the platform reset and while the System
is in Setup mode.
Install Default Secure Boot Keys
Please install default secure boot keys if it’s the first time you use secure boot.
Clear Secure Boot keys
Force System to Setup Mode - clear all Secure Boot Variables. Change takes effect
after reboot.
Export Secure Boot variables
Copy NVRAM content of Secure Boot variables to files in a root folder on a file
system device.
Enroll Efi Image
Allow the image to run in Secure Boot mode. Enroll SHA256 Hash certificate of a
PE image into Authorized Signature Database (db).