
50
This item enables expert users to modify Secure Boot Policy variables without full
authentication. Press [Enter] to make settings for the following sub-items:
Factory Key Provision
This item is for user to install factory default secure boot keys after the platform
reset and while the system is in Setup mode.
The optional settings are: [Disabled]; [Enabled].
Restore Factory Keys
Use this item to force system into User Mode. Install factory default Secure Boot
Key databases.
Reset to Setup Mode
Use this item to delete all Secure Boot key databases from NVRAM.
Enroll Efi Image
Use this item to allow efi image to run in secure boot mode. Enroll SHA256 Hash
certificate of a PE image into authorized signature database (db)
The optional settings are: [<EFI>]; [<System Volume Information>]; [date.txt];
[Time.txt]; [Counter.txt]
Export Secure Boot variables
Use this item to copy NVRAM content of Secure Boot variables to files in a root
folder on a file system device.
Secure Boot Variable/Size/Keys/Key Source
Platform Key (PK)/Key Exchange Keys/Authorized Signature/Forbidden
Signature/ Authorized TimeStamps/OS Recovery Signatures
Use this item to enroll Factory Defaults or load the keys from a file with:
1. Public Key Certificate in:
a) EFI_SIGNATURE_LIST
b) EFI_ CERT_X509 (DER)
c) EFI_ CERT_RSA2048 (bin)
d) EFI_ CERT_SHAXXX
2. Authenticated UEFI Variable
3. EFI PE/COFF Image (SHA256)