Chapter 6: UEFI BIOS
99
Secure Boot
Select Enable for secure boot support to ensure system security at boot up. The options
are
Disabled
and Enabled.
Secure Boot Mode
This feature allows the user to select the desired secure boot mode for the system. The
options are Standard and
Custom
.
*If Secure Boot Mode is set to Customized, Key Management features are available
for configuration:
CSM Support
This feature is for manufacturing debugging purposes.The options are Disabled and
Enabled
.
Vendor Keys
Provision Factory Defaults
Select Enabled to install the default Secure Boot keys set by the manufacturer. The options
are
Disabled
and Enabled.
Restore Factory Keys
Select Yes to restore all factory keys to the default settings. The options are Yes and No.
Reset to Setup Mode
Select Yes to delete all Secure Boot key databases and force the system to Setup Mode.
The options are Yes and No.
Export Secure Boot Variables
This feature allows the user to copy all variables onto a file on a separate device.
Enroll EFI Image
This feature allows the image to run in Secure Boot Mode. Enroll SHA256 Hash Certificate
of the image into the Authorized Signature Database.
Device Guard Ready
Remove 'UEFI CA' from DB
Use this feature to remove the Microsoft UEFI CA certificate from the database. The options
are Yes and No.
Restore DB defaults
Select Yes to restore the DB defaults.