BOLT
UDOO BOLT User Manual - Rev. First Edition: 1.0 - Last Edition: 1.0 - Author: S.B. - Reviewed by L.V. Copyright © 2019 SECO S.p.A.
65
4.5.1.1
Key Management submenu
Menu Item
Options
Description
Factory Key Provision
Disabled / Enabled
Install factory default Secure Boot Keys after the platform reset and while the System is in Setup Mode
Restore Factory Keys
Force System to User Mode. Install factory Default Secure Boot key databases
Reset to Setup Mode
Delete all Secure Boot key databases from NVRAM
Export Secure Boot variables
Copy NVRAM content of Secure Boot variables to files in a root folder on a file system device
Enrol Efi Image
File System Image
Allow the selected image to run in Secure Boot mode. Enrol SHA256 Hash Certificates of a PE Image into
Authorized Signature Database (db)
Remove
‘
UEFI CA
’
from DB
Device Guard ready system must not list
‘
Microsoft UEFI CA
’
Certificate in Authorized Signature Database
(db)
Restore DB defaults
Restore DB variable to factory defaults
Platform key
Key Exchange Keys
Authorized Signatures
Forbidden Signatures
Authorized Timestamps
OS Recovery Signatures
Details
Export
Update
Append
Delete
Enrol factory Defaults or load certificates from a file:
1. Public Key Certificate in:
a) EFI_SIGNATURE_LIST
b) EFI_CERT_X509 (DER encoded)
c) EFI_CERT_RSA2048 (bin)
d) EFI_CERT_SHAXX
2. Authenticated UEFI variables
3. EFI PE/COFF Image (SHA256)
Key Source:
Factory, External, Mixed