3-22
H110T-CM-A R2.0
KEK Management
The Key Exchange Keys (KEK) manages the Signature database (db) and
Forbidden Signature database (dbx).
Key Exchange Keys (KEK) refers to Microsoft
®
Secure Boot Key-Enrollment
Key (KEK).
Save To File
This item allows you to save the KEK to a USB storage device.
Set New Key
This item allows you to load the downloaded KEK from a USB
storage device.
Append Key
This item allows you to load the additional KEK from a storage
device for an additional db and dbx loaded management.
Delete key
This item allows you to delete the KEK from your system.
Configuration options: [Yes] [No]
The KEK file must be formatted as a UEFI variable structure with time-based
authenticated variable.
DB Management
The Authorized Signatures (db) lists the signers or images of UEFI
applications, operating system loaders, and UEFI drivers that you can load
on the single computer.
Save To File
This item allows you to save the db to a USB storage device.
Set New Key
This item allows you to load the downloaded db from a USB
storage device.
Append Key
This item allows you to load the additional db from a storage
device for an additional db and dbx loaded management.
Delete key
This item allows you to delete the db file from your system.
Configuration options: [Yes] [No]
The db file must be formatted as a UEFI variable structure with time-based
authenticated variable.
DBX Management
The Forbidden Signature database (dbx) lists the forbidden images of db
items that are no longer trusted and cannot be loaded.