Table 10. Security (continued)
Option
Description
●
One-Time Enable — User may enter OROM configuration
screens via the hotkeys on next boot only. After next boot,
the setting will revert to disabled.
●
Disable — User may not enter OROM configuration
screens via the hotkey.
Admin Setup Lockout
Allows you to enable or disable the option to enter Setup
when an Administrative password is set. This option is not set
by default.
Table 11. Secure Boot
Option
Description
Secure Boot Enable
Allows you to enable or disable Secure Boot feature
●
Disable (selected by default)
●
Enable
Expert key Management
Allows you to manipulate the security key databases only if
the system is in Custom Mode. The
Enable Custom Mode
option is disabled by default. The options are:
●
PK (default)
●
KEK
●
db
●
dbx
If you enable the
Custom Mode
, the relevant options for
PK,
KEK, db, and dbx
appear. The options are:
●
Save to File
- Saves the key to a user-selected file
●
Replace from File
- Replaces the current key with a key
from a user-selected file
●
Append from File
- Adds a key to the current database
from a user-selected file
●
Delete
- Deletes the selected key
●
Reset All Keys
- Resets to default setting
●
Delete All Key
s- Deletes all the keys
NOTE:
If you disable the Custom Mode, all the changes
made will be erased and the keys will restore to default
settings.
Table 12. Intel Software Guard Extensions
Option
Description
Intel SGX Enable
Allows you to enable or disable the Intel Software Guard
Extensions to provide a secured environment for running
code/storing sensitive information in the context of the main
operating system.
●
Disabled (default)
●
Enabled
Enclave Memory Size
Allows you to set the Intel SGX Enclave Reserve Memory
Size.
●
32 MB
●
64 MB (Disabled by default)
●
128 MB (Disabled by default)
BIOS setup
41