PK Management
ThePlatformKey(PK)locksandsecuresthermwarefromanynon-permissible
changes.ThesystemveriesthePKbeforeyoursystementerstheOS.
Set New Key
ThisitemallowsyoutoloadthedownloadedPKfromaUSBstoragedevice.
ThePKlemustbeformattedasaUEFIvariablestructurewithtime-basedauthenticated
variable.
Delete Key
ThisitemallowsyoutodeletethePKfromyoursystem.OncethePKisdeleted,all
thesystemsSecureBootkeyswillnotbeactive.
Congurationoptions:[Yes][No]
KEK Management
TheKEK(Key-exchangeKeyorKeyEnrollmentKey)managestheSignaturedatabase
(db)andRevokedSignaturedatabase(dbx).
Key-exchangeKey(KEK)referstoMicrosoft
®
SecureBootKey-EnrollmentKey(KEK).
Set New Key
AllowsyoutoloadthedownloadedKEKfromaUSBstoragedevice.
Append Key
AllowsyoutoloadtheadditionalKEKfromastoragedeviceforanadditionaldband
dbxloadedmanagement.
Delete Key
AllowsyoutodeletetheKEKfromyoursystem.Congurationoptions:[Yes][No]
TheKEKlemustbeformattedasaUEFIvariablestructurewithtime-basedauthenticated
variable.
DB Management
Thedb(AuthorizedSignaturedatabase)liststhesignersorimagesofUEFI
applications,operatingsystemloaders,andUEFIdriversthatyoucanloadonthe
singlecomputer.
Set New Key
AllowsyoutoloadthedownloadeddbfromaUSBstoragedevice.
Append Key
Allowsyoutoloadtheadditionaldbfromastoragedevicesothatmoreimagescan
beloadedsecurely.
Delete Key
Allowsyoutodeletethedblefromyoursystem.
Congurationoptions:[Yes][No]
TheDBlemustbeformattedasaUEFIvariablestructurewithtime-based
authenticatedvariable.
UEFIexecutablelesincludeUEFIbootdevices,driversandapplications.
2-44 Chapter 2: Getting started