Chapter 4: BIOS
99
Enroll Efi Image
This feature allows the image to run in Secure Boot Mode. Enroll SHA256 Hash Certifi
-
cate of the image into the Authorized Signature Database.
Device Guard Ready
Remove 'UEFI CA' from DB
This feature allows you to decide if all secure boot variables should be saved.
Restore DB defaults
Select Yes to restore the DB defaults.
Secure Boot variable
Platform Key (PK)
Update
Select Yes to load a factory default PK or No to load from a file on an external media.
Key Exchange Key
Update
Select Yes to load a factory default KEK or No to load from a file on an external media.
Append
Select Yes to add the KEK from the manufacturer's defaults list to the existing KEK.
Select No to load the KEK from a file. The options are Yes and No.
Authorized Signatures
Update
Select Yes to load a factory default DB or No to load from a file on an external media.
Append
Select Yes to add the DB from the manufacturer's defaults list to the existing DB. Select
No to load the DB from a file. The options are Yes and No.