
Chapter 6: BIOS
97
CSM Support
Select Enabled to support the EFI Compatibility Support Module (CSM), which provides
compatibility support for traditional legacy BIOS for system boot. The options are Disabled
and
Enabled
.
Key Management
This submenu allows the user to configure the following Key Management settings.
Install Factory Default Keys
Select Yes to install all default secure keys set by the manufacturer. The options are
Yes
and No.
Enroll EFI Image
This allows the image to run in Secure Boot Mode, and enroll SHA256 hash of the binary
into an Authorized Signature Database (db).
Save All Secure Boot Variables
This feature allows the user to decide if all secure boot variables should be saved.
Platform Key (PK)
This feature allows the user to configure the settings of the platform keys.
Set New Key
Select Yes to load the new platform keys (PK) from the manufacturer's defaults. Select
No to load the platform keys from a file. The options are
Yes
and No.
Provision Factory Default Keys
Select Enabled to install the default Secure-Boot keys set by the manufacturer. The op-
tions are
Disabled
and Enabled.
Key Exchange Keys
Set New Key
Select Yes to load the KEK from the manufacturer's defaults. Select No to load the KEK
from a file. The options are Yes and No.
Append Key
Select Yes to add the KEK from the manufacturer's defaults list to the existing KEK.
Select No to load the KEK from a file. The options are Yes and No.