Chapter 4: BIOS
83
Append Key
Select Yes to add the KEK from the manufacturer's defaults list to the existing KEK. Select No to
load the KEK from a file. The options are Yes and No.
Authorized Signatures
Set New Key
Select Yes to load the database from the manufacturer's defaults. Select No to load the DB from
a file. The options are Yes and No.
Append Key
Select Yes to add the database from the manufacturer's defaults to the existing DB. Select No to
load the DB from a file. The options are Yes and No.
Forbidden Signatures
Set New Key
Select Yes to load the DBX from the manufacturer's defaults. Select No to load the DBX from a
file. The options are Yes and No.
Append Key
Select Yes to add the DBX from the manufacturer's defaults to the existing DBX. Select No to
load the DBX from a file. The options are Yes and No.
Authorized TimeStamps
Set New Key
Select Yes to load the DBT from the manufacturer's defaults. Select No to load the DBT from a
file. The options are Yes and No.
Append Key
Select Yes to add the DBT from the manufacturer's defaults list to the existing DBT. Select No to
load the DBT from a file. The options are Yes and No.
OsRecovery Signature
This item uploads and installs an OSRecovery Signature. You may select options for Set New for
a factory default key, or select Append to get it from a file. The file formats accepted are:
1) Public Key Certificate
a. EFI Signature List
b. EFI CERT X509 (DER Encoded)
c. EFI CERT RSA2048 (bin)
d. EFI SERT SHA256 (bin)
2) EFI Time Based Authenticated Variable
When prompted, select "Yes" to load Factory Defaults or "No' to load from a file.