Figure 3: UEFI Custom Secure Boot Options menu
The custom Secure Boot key options are:
PK Options
Platform key options.
Only one platform key may be enrolled. To enroll a different platform key, any existing platform key must first be
deleted.
You can enroll a platform key using a certificate file (X.509 DER format). The file must be available on a UEFI file
system.
KEK Options
Key Exchange Keys options.
You can enroll additional signature keys to establish a trusted relationship between an operating system and the
system firmware.
DB Options
Database of allowed signatures (whitelist).
DBX Options
Database of disallowed signatures (blacklist).
DBT Options
Not currently supported.
Troubleshooting OS Secure Boot issues
Cannot enable the Attempt Secure Boot option
Symptom
The
Attempt Secure Boot option in the Secure Boot Configuration menu cannot be selected.
Secure Boot
54