E3C246D4I-2T
56
57
English
3.5.1 Key Management
In this section, expert users can modify Secure Boot Policy variables without full authenti-
cation.
Factory Key Provision
Install factory default Secure Boot keys after the platform reset and while the System
is in Setup mode.
Clear Secure Boot keys
Force System to Setup Mode - clear all Secure Boot Variables. Change takes effect
after reboot.
Export Secure Boot variables
Copy NVRAM content of Secure Boot variables to files in a root folder on a file
system device.
Enroll Efi Image
Allow the image to run in Secure Boot mode. Enroll SHA256 Hash certificate of a
PE image into Authorized Signature Database (db).
Remove 'UEFI CA' from DB
Device Guard ready system must not list ‘Microsoft UEFI CA’ Certificate in Autho