12044128 Rev. 00
33
D ATA M O D U L AG | w w w .data-m odul.com
Key Management
N ote: D efault Secure B oot Keys PK and KEK should be updated by O EM PK and KEK Keys.
Param eter
V alue
Com m ent
Factory Key Provision
D isabled
Enabled
Install factory default Secure B oot keys w hen System is
in Setup M ode.
Restore Factory Keys
Function Key
Force System to U ser M ode.
Install factory default Secure B oot key databases.
Reset to Setup M ode
Function Key
D elete all Secure B oot key databases from N VRAM .
Export Secure B oot variables
Function Key
Copy N VRAM content of Secure B oot variables to files
in a root folder on a file system device.
Enroll Efi Im age
Function Key
Allow the im age to run in Secure B oot m ode.
Enroll SH A256 H ash certificate of a PE im age into
Authorized Signature D atabase (db).
Rem ove ‘U EFI CA’ from D B
Function Key
D evice G uard ready system m ust not list ‘M icrosoft U EFI
CA’ Certificate in Authorized Signature databes (db).
Restore D B defaults
Function Key
Restore D B variable to factory defaults.
Platform Key (PK)
Function Key
Enroll Factory D efaults or load certificates from a
file:
1. Public Key Certificate in:
a)EFI_S IG N A TU RE_LIS T
b)EFI_CERT_X509 (D ER encod ed)
c)EFI_CERT_RS A 2048 (bin)
d)EFI_CERT_S H A 256 (bin)
2. A uthenticated U EFI V ariable
3. EFI PE/CO FF Im age (S H A 25 6)
Key source: D efault, External, M ixed, Test
Key Exchange Keys
Function Key
Authorized Signatures
Function Key
Forbidden Signatures
Function Key
Authorized Tim eStam ps
Function Key
O sRecovery Signatures
Function Key