Chapter 4: BIOS
79
Forbidden Signatures (dbx)
This feature allows the user to enter and configure a set of values to be used as Forbid
-
den Signatures for the system. These values also indicate sizes, keys numbers, and key
sources of the forbidden signatures. Select Update to update your "Forbidden. Signa-
tures". Select Append to append your "Forbidden Signatures". The settings are
Update
,
and Append.
Authorized TimeStamps (dbt)
This feature allows the user to set and save the timestamps for the authorized signa-
tures which will indicate the time when these signatures are entered into the system.
Select Update to update your "Authorized TimeStamps". Select Append to append your
"Authorized TimeStamps". The settings are
Update
, and Append.
OsRecovery Signature (dbr)
This item uploads and installs an OSRecovery Signature. Use this feature to export
NVRAM content of secure boot variables to files in a root folder on a file system device.
The settings are
Update
, and Append.
The file formats accepted are:
1) Public Key Certificate
a. EFI Signature List
b. EFI CERT X509 (DER)
c. EFI CERT RSA2048 (bin)
d. EFI SERT SHAXXX
2) Authenticated UEFI Variable
3) EFI PE/COFF Image (SHA256)