
Appendix C: Secure Boot Settings
139
Key Exchange Key
The Key Exchange Key (KEK), which is held by the operating system vendor, can be
updated by the holder of the PK and be used by secure boot to protect access to sig-
natures databases. The options are
Save to File
, Set New, Append, and Erase. Select
Save to File to save the current KEKs to a FAT formatted USB flash drive. Select Set
New to load the manufacturer's defaults or load it from the external media. Select Erase
to clear the current KEKs.
Append: Use the arrow keys to select Append.