
1. System Utilities
Express5800/R120h-1M, R120h-2M Maintenance Guide
108
Chapter 2 Useful Features
ii-1.
Enroll KEK Entry Menu
When you select
System Configuration
>
BIOS/Platform Configuration (RBSU)
>
Server Security
>
Secure
Boot Settings
>
Advance Secure Boot Options
>
KEK - Key Exchange Key
>
Enroll KEK Entry
from the
System Utilities, the
Enroll KEK Entry
menu appears.
For details about the options, see the table below.
Option
Parameter
Description
Enroll KEK using File
-
Use this option to read the KEK certificate from a file on
an attached media device. Supported formats
include .der, .cer, and .crt.
Signature Owner GUID
(optional)
[Other]
Hewlett Packard Enterprise
Company
Hewlett-Packard Company
Microsoft Corporation
SUSE Linux Products HmbH
Select the Signature Owner to use their Signature
GUID in the Certificate.
Signature GUID (optional)
String of 32 digits (“0” to “9”) and
alphabetic characters “A” to “F”
Enter the optional security certificate Signature GUID.
You must enter the data in the following GUID format:
11111111-2222-3333-4444-1234567890ab.
For
Hewlett Packard Enterprise certificates, enter
1E910BE1-4BEB-6337-19F1-8A8AC107D512.
For
Hewlett-Packard certificates, enter
F5A96B31-DBA0-4faa-A42A-7A0C9832768E.
For
Microsoft certificates, enter
77fa9abd-0359-4d32-bd60-28f4e78f784b.
For SUSE
certificates, enter
2879c886-57ee-45cc-b126-f92f24f906b9.
Commit changes and exit
-
Commit changes and exit.
Discard changes and exit
-
Discard changes and exit.
[ ]: Default setting
iii. DB - Allowed Signatures Database
When you select
System Configuration
>
BIOS/Platform Configuration (RBSU)
>
Server Security
>
Secure
Boot Settings
>
Advance Secure Boot Options
>
DB - Allowed Signatures Database
from the System Utilities,
the
DB - Allowed Signatures Database
menu appears.
For details about the options, see the table below.
Option
Parameter
Description
View Signatures
-
Shows the signature.
The expiration date of the certificate is shown in
Coordinated Universal Time (UTC).
Enroll Signatures
-
Enrolls the signature.
Delete Signature
-
Deletes the enrolled signature.
Export Signature
-
Use this option to export the signature to a file on an
attached media device. Supported formats
include .der, .cer, and .crt.
Reset to platform defaults
-
Restores the DB setting to the default.