H12DSU-iN User's Manual
84
Secure Boot
This option allows you specify when the Platform Key (PK) is enrolled. When enabled, the
System Mode is user deployed, and the CSM function is disabled. Options include
Disabled
and Enabled.
Secure Boot Mode
Use this item to select the secure boot mode. The options are
Standard and
Custom
.
CSM Support
Select Enabled to support the EFI Compatibility Support Module (CSM), which provides
compatibility support for traditional legacy BIOS for system boot. The options are Disabled
and
Enabled
.
Key Management
This submenu allows the user to configure the following Key Management settings.
Vendor Keys
Provision Factory Defaults
Install factory default Secure Boot keys after the patform reset and while the System is in Setup mode. The defaut set-
ting is
Disabled
.
Restore Factory Defaults
Select Yes to restore all factory keys to default settings. The options are Yes and No.
Reset To Setup Mode
Select Yes to delete all Secure Boot key databases and force the system to Setup Mode.The options are Yes and No.
Export Secure Boot variables
Use this feature to copy the NVRAM contents of the secure boot variables to a file.
Export Efi Image
This feature allows the image to run in Secure Boot mode. Enroll SHA256 Hash Certificate of a PE image into Authroized
Signature Database (db).
Device Guard Ready
Remove 'UEFI CA' from DB
Use this feature to remove the Microsoft UEFI CA certificate from the database. The options are Yes and No.