Chapter 4: BIOS
119
Key Exchange Keys (KEK)
The Key Exchange Key (KEK), which is held by the operating system vendor, can be
updated by the holder of the PK and be used by secure boot to protect access to signa-
tures databases. The options are
Save to File
, Set New, Append, and Erase.
Authorized Signatures
Authorized Signature Database (DB) contains authorized signing certificates and digital
signatures. The options are
Save to File
, Set New, Append, and Erase.
Forbidden Signatures
Forbidden Signature Database (DBX), which is the inverse of DB, contains forbidden
certificates and digital signatures. The options are
Save to File
, Set New, Append, and
Erase
Authorized TimeStamps
Authorized Timestamp Database (DBT) is used to issue and check signed time stamp
certificates. The options are Save to File, Set New, Append, and Erase
OsRecovery Signatures
OsRecovery Signatures Database (DBR) contains secure boot authorized recovery vari-
ables. The options are
Save to File
, Set New, Append, and Erase
Содержание X11DSC+
Страница 1: ...USER S MANUAL Revision 1 0a X11DSC...