34 | 5. Security Menu
Key Management
Factory Key Provision
Install factory default Keys on next re-boot only when system in setup mode.
Options: Disabled (Default) / Enabled
Restore Factory Keys
Force System to User Mode. Configure NVRAM to contain OEM-defined factory default Secure
Boot Keys.
Restore To Setup Mode
Delete NVRAM content of all UEFI Secure Boot Key databases.
Export Secure Boot variables
Copy NVRAM content of Secure Boot variables to files in a root folder on a file system device.
Enroll Efi Image
Allow the image to run in Secure Boot mode. Enroll SHA256 Hash certificate of a PE image into
Authorized Signature Database (db).
Remove ‘UEFI CA’ from DB
Device Guard ready system must not list ‘Microsoft UEFI CA’ Certificate in Authorized Signature
database (db).
Restore DB defaults
Restore DB variable to factory defaults.
Platform Key (PK)
Options: Details / Export / Update / Delete
Key Exchange Keys
Options: Details / Export / Update / Append / Delete
Authorized Signatures
Options: Details / Export / Update / Append / Delete
Forbidden Signatures
Options: Details / Export / Update / Append / Delete
Authorized Timestamps
Options: Update / Append
OsRecovery Signatures
Options: Update / Append