
Chapter 6: UEFI BIOS
149
Secure Boot Mode
Use this feature to configure Secure Boot variables without authentication. The options are
Standard and
Custom
.
CSM Support
Select Enabled to support the EFI Compatibility Support Module (CSM), which provides
compatibility support for traditional legacy BIOS for system boot. The options are
Enabled
and Disabled.
Key Management
This submenu allows the user to configure the following Key Management settings.
Provision Factory Default Keys
Select Enabled to install the default Secure Boot keys set by the manufacturer. The op-
tions are
Disabled
and Enabled.
Restore Factory Keys
Select Yes to install factory default Secure Boot keys set by the manufacturer. The op-
tions are
Yes
and No.
Reset to Setup Mode
Select Yes to delete all variables and reset the System to Setup Mode. The options are
Yes
and No.
Export Secure Boot variables
This feature allows the user to export Secure Boot variables to a folder in the system.
Enroll Efi Image
This feature allows the image to run in Secure Boot Mode. Enroll SHA256 Hash Certifi
-
cate of the image into the Authorized Signature Database.
Device Guard Ready
Remove 'UEFI CA' from DB
This feature allows the user to remove 'UEFI CA' certificate from an authorized signature
database. The options are
Yes
and No.