- 69 -
BIOS Setup
Parameter
Description
Key Management
Press [Enter] to configure advanced items.
Please note that this item is configurable when Secure Boot Mode is set
to Custom.
Factory Key Provision
– Allows to provision factory default Secure Boot keys when system is in
Setup Mode.
– Options available: Enabled/Disabled. Default setting is Disabled.
Restore Factory Keys
– Installs all factory default keys. It will force the system in User Mode.
– Options available: Yes/No.
Enroll Efi Image
– Press [Enter] to enroll SHA256 hash of the binary into Authorized
Signature Database (db).
Restore DB defaults
– Restore DB variable to factory defaults.
Secure Boot variable
– Displays the current status of the variables used for secure boot.
Platform Key (PK)
– Displays the current status of the Platform Key (PK).
–
Press [Enter] to configure a new PK.
– Options available: Set New.
Key Exchange Keys (KEK)
– Displays the current status of the Key Exchange Key Database (KEK).
–
Press [Enter] to configure a new KEK or load additional KEK from
storage devices.
– Options available: Set New/Append.
Authorized Signatures (DB)
– Displays the current status of the Authorized Signature Database.
–
Press [Enter] to configure a new DB or load additional DB from storage
devices.
– Options available: Set New/Append.
Forbidden Signatures (DBX)
– Displays the current status of the Forbidden Signature Database.
–
Press [Enter] to configure a new dbx or load additional dbx from
storage devices.
– Options available: Set New/Append.
Authorized TimeStamps (DBT)
– Displays the current status of the Authorized TimeStamps Database.
–
Press [Enter] to configure a new DBT or load additional DBT from
storage devices.
– Options available: Set New/Append.
OsRecovery Signatures
– Displays the current status of the OsRecovery Signature Database.
–
Press [Enter] to configure a new OsRecovery Signature or load
additional OsRecovery Signature from storage devices.
– Options available: Set New/Append.