78 79
English
3.4.1 Key Management
In this section, expert user can modify Secure Boot Policy variables without full authenti-
cation.
Factory Key Provision
Install factory default Secure Boot keys aer the platform reset and while the System is in
Setup mode.
Install Default Secure Boot Keys
Please install default secure boot keys if it’s the rst time to use the secure boot.
Enroll E Image
Allow the image to run in Secure Boot mode. Enroll SHA256 hash of the binary into Au-
thorized Signature Database (db).
Platform Key(PK)
Enroll Factory Defaults or load certicates from a le:
1. Public Key Certicate in:
a) EFI_SIGNATURE_LIST
b) EFI_CERT_X509 (DER)