56
57
English
3.5.1 Key Management
In this section, expert users can modify Secure Boot Policy variables without full authenti-
cation.
Provision Factory Defaults
Allow to provision factory default Secure Boot keys when System is in Setup Mode.
Install Default Secure Boot Keys
Please install default secure boot keys if it’s the first time you use secure boot.
Enroll Efi Image
Allow the image to run in Secure Boot mode. Enroll SHA256 hash of the binary into
Authorized Signature Database (db).
Platform Key(PK)
Enroll Factory Defaults or load certificates from a file:
1. Public Key Certificate in:
a) EFI_SIGNATURE_LIST
b) EFI_CERT_X509 (DER encoded)
c) EFI_CERT_RSA2048 (bin)