
Chapter 6: BIOS
79
Enroll EFI Image
This feature allows the image to run in Secure Boot Mode. Enroll SHA256 Hash Cer-
ticate of the image into the Authorized Signature Database.
Device Guard Ready
Remove 'UEFI CA' from DB
Use this feature to remove the Microsoft UEFI CA certificate from the database. The
options are
Yes
and No.
Restore DB Defaults
Select Yes to restore the DB defaults.The options are
Yes
and No.
Secure Boot Variable
Platform Key (PK)
This feature allows the user to update the settings of the platform keys.
Update
Select Yes to load a factory default PK or No to load from a file on an external media.
The options are
Yes
and No.
Key Exchange Keys
Update
Select Yes to load the KEK from the manufacturer's defaults. Select No to load the
KEK from a file. The options are
Yes
and No.
Append
Select Yes to add the KEK from the manufacturer's defaults list to the existing KEK.
Select No to load the KEK from a file. The options are
Yes
and No.
Authorized Signatures
Update
Select Yes to load the database from the manufacturer's defaults. Select No to load
the DB from a file. The options are
Yes
and No.
Append
Select Yes to add the database from the manufacturer's defaults to the existing DB.
Select No to load the DB from a file. The options are
Yes
and No.