KEK Management
TheKEK(Key-exchangeKeyorKeyEnrollmentKey)managestheSignaturedatabase
(db)andRevokedSignaturedatabase(dbx).
Key-exchangeKey(KEK)referstoMicrosoft
®
SecureBootKey-EnrollmentKey(KEK).
Delete KEK
AllowsyoutodeletetheKEKfromyoursystem.OncetheKEKisdeleted,thedb
andthedbxcannotbeupdatedintheoperatingsystem.
Load Default KEK
SelectYestoloadthesystemdefaultKEKorselectNotoloadadownloadedKEK
fromaUSBstoragedevice.
Append Default KEK
SelectYestoappendthesystemdefaultKEKorselectNotoappendadownloaded
additionalKEKfromaUSBstoragedeviceforthedbanddbxmanagement.
TheKEKlemustbeformattedasaUEFIvariablestructurewithtime-basedauthenticated
variable.
DB Management
Thedb(AuthorizedSignaturedatabase)liststhesignersorimagesofUEFI
applications,operatingsystemloaders,andUEFIdriversthatyoucanloadonthe
singlecomputer.
Delete the db
Allowsyoutodeletethedblefromyoursystem.Doingsomaycausebootfailures.
Load Default db
SelectYestoloadthesystemdefaultdborselectNotoloadadownloadeddbfrom
aUSBstoragedevice.
Append Default db
SelectYestoappendthesystemdefaultdborselectNotoappendadownloaded
additionaldbfromaUSBstoragedevicetoloadcertaincustomizedUEFI
executableles.
TheDBlemustbeformattedasaUEFIvariablestructurewithtime-based
authenticatedvariable.
UEFIexecutablelesincludeUEFIbootdevices,driversandapplications.
dbx Management
Thedbx(RevokedSignaturedatabase)liststheforbiddenimagesofdbitemsthatare
nolongertrustedandcannotbeloaded.
Delete the dbx
AllowsyoutodeletetheDBXlefromyoursystem.Doingsomayexposethe
systemtosecuritythreats.
Load Default dbx
SelectYestoloadthesystemdefaultdbxorselectNotoloadadownloadeddbx
fromaUSBstoragedevice.
ASUS H97I-PLUS 2-45