1. System BIOS
Express5800/E120g-M Maintenance Guide
86
Chapter 2 Useful Features
(a) Key Management submenu
Option Paramete
Description
Provision Factory Default
keys
Disabled
[Enabled]
Enable/Disable the function to automatically register the
default key if you do not have Platform Key (PK).
Delete All Secure Boot
Variables
-
Set “System Mode” to [Setup]. Secure Boot will be
disabled. All keys and signature databases (PK, KEK,
DB, DBX and DBT) will be deleted. You can execute this
section only when you set “Provision Factory Default
keys” to [Disabled].
Enroll All Factory Default Keys
-
Set “System Mode” to [User]. Register the default key
and signature databases (PK, KEK, DB, DBX and DBT).
You can execute this section only when you set
“Provision Factory Default keys” to [Enabled].
Save All Secure Boot
Variables
-
Save all keys and signature databases (PK, KEK, DB,
DBX and DBT) in an external media. You can execute
this section only when you have registered PK, KEK, db,
dbx and dbt keys.
Secure Boot variable | Size|
Key#| Key source
(Display only)
Display the status of keys and signature databases (PK,
KEK, DB, DBX and DBT).
Platform Key(PK)
-
Display the status of Platform Key (PK). Also
register/delete PK.
Key Exchange Keys
-
Display the status of Key Exchange Keys (KEK). Also
register/delete KEK.
Authorized Signatures
-
Display the status of Authorized Signatures (DB). Also
register/delete DB.
Forbidden Signatures
-
Display the status of Forbidden Signatures (DBX). Also
register/delete DBX.
Authorized Timestamps
-
Display the status of Authorized Timestamps (DBT). Also
register/delete DBT.