Chapter 5: UEFI BIOS
103
Secure Boot
Use this feature to enable secure boot. The options are
Disabled
and Enabled.
Secure Boot Mode
Use this feature to configure Secure Boot variables without authentication. The options are
Standard and
Custom
.
CSM Support
Select Enabled to support the EFI Compatibility Support Module (CSM), which provides
compatibility support for traditional legacy BIOS for system boot. The options are
Enabled
and Disabled.
Key Management
This submenu allows the user to configure the following Key Management settings.
Provision Factory Default Keys
Select Enabled to install the default Secure Boot keys set by the manufacturer. The op-
tions are
Disabled
and Enabled.
Restore Factory Keys
Select Yes to force system to install factory default keys. The options are
Yes
and No.
Reset to Setup Mode
Select Yes to delete all erase all Secure Boot key databases from NVRAM. The options
are
Yes
and No.
Export All Secure Boot Variables
This feature allows the user to copy all variables onto a file on a separate device.
Enroll EFI Image
This feature allows the image to run in Secure Boot Mode. Enroll SHA256 Hash Certifi
-
cate of the image into the Authorized Signature Database.
Device Guard Ready
Remove 'UEFI CA' from DB