Chapter 6: BIOS
95
Secure Boot Mode
Use this feature to configure Secure Boot variables without authentication. The options are
Standard and
Custom
.
CSM Support
Select Enabled to support the EFI Compatibility Support Module (CSM), which provides
compatibility support for traditional legacy BIOS for system boot. The options are Disabled
and
Enabled
.
Key Management
This submenu allows the user to configure the following Key Management settings.
Restore Factory Keys
Select Yes to restore all factory keys to the default settings. The options are
Yes
and No.
Reset to Setup Mode
Select Yes to delete all Secure Boot key databases and force the system to Setup
Mode. The options are
Yes
and No.
Export Secure Boot variables
Use this feature to copy the NVRAM contents of the secure boot variables to a file.
Enroll EFI Image
This feature allows the image to run in Secure Boot Mode. Enroll SHA256 Hash Cer-
ticate of the image into the Authorized Signature Database.
Device Guard Ready
Remove 'UEFI CA' from DB
Use this feature to remove the Microsoft UEFI CA certificate from the database. The
options are
Yes
and No.
Restore DB Defaults
Select Yes to restore the DB defaults.The options are
Yes
and No.
Secure Boot Variable
Platform Key (PK)
This feature allows the user to update the settings of the platform keys.
Update
Select Yes to load a factory default PK or No to load from a file on an external media.
The options are
Yes
and No.