![Kontron MITX-CFL0 Series User Manual Download Page 99](http://html1.mh-extra.com/html/kontron/mitx-cfl0-series/mitx-cfl0-series_user-manual_1996300099.webp)
MITX-CFL0 Series - User Guide, Rev. 1.1
// 99
Figure 69: BIOS Security Setup Menu -- Secure Boot -- Key Management
BIOS SETUP UTILITY
Main
Advanced
Power
Boot
Security
Save & Exit
Vendor Keys
Modified
Factory Key Provision
[Disabled]
> Restore Factory Keys
> Reset To Setup Mode
> Export Secure Boot variables
> Enroll Efi Image
Device Guard Ready
> Remove ‘UEFI CA’ from DB
> Restore DB defaults
→
←
: Select Screen
↑
↓
: Select Item
Secure Boot variable
∣
Size
∣
Keys
∣
Key Source
Enter: Select
> Platform Key (PK)
∣
862
∣
1
∣
Test (AMI)
+/-: Change Opt.
> Key Exchange Keys
∣
1560
∣
1
∣
Factory
F1: General Help
> Authorized Signatures
∣
3143
∣
2
∣
Factory
F2: Previous Values
> Forbidden Signatures
∣
3724
∣
77
∣
Factory
F3: Optimized Defaults
> Authorized TimeStamps
∣
0
∣
0
∣
No Keys
F4: Save & Exit
> OsRecovery Signatures
∣
0
∣
0
∣
No Keys
ESC: Exit
Version 2.20.1275. Copyright (C) 2021, American Megatrends, Inc.
Feature
Option
Description
Factory Key Provision [Disabled],
[Enabled]
Install factory default Secure Boot keys after the platform
reset and while the System is in Setup mode.
Reset Factory Keys
[Yes],
[No]
Force System to User Mode.
Install factory default Secure Boot key databases.
Reset to Setup Mode
[Yes],
[No]
Delete all Secure Boot key databases from NVRAM.
Export Secure Boot
variables
Select a File system
Copy NVRAM content of Secure Boot variables to files in a root
folder on a file system device.
Enroll Efi Image
Select a File system
Allow the image to run in Secure Boot mode.
Enroll SHA256 Hash certificate of a PE image into Authorized
Signature Database (db).
Remove ‘UEFI CA’
from DB
[Yes],
[No]
Device Guard ready system must not list 'Microsoft UEFI CA'
Certificate in Authorized Signature database (db).
Restore DB defaults
[Yes],
[No]
Restore DB variable to factory defaults.
Platform Key (PK)
[Details],
[Export],
[Update],
[Delete]
Enroll Factory Defaults or load certificates from a file:
1. Public Key Certificate:
(a) EFI_SIGNATURE_LIST
(b) EFI_CERT_X509 (DER)