Key-exchangeKey(KEK)referstoMicrosoft
®
SecureBootKey-EnrollmentKey(KEK).
Set New Key
AllowsyoutoloadthedownloadedKEKfromaUSBstoragedevice.
Append Key
AllowsyoutoloadtheadditionalKEKfromastoragedeviceforanadditionaldband
dbxloadedmanagement.
TheKEKlemustbeformattedasapublickeycerticateorUEFIvariablestructurewith
time-basedauthenticatedvariable.
Delete key
AllowsyoutodeletetheKeyfromyoursystem.Congurationoptions:[Yes][No]
DB Management
Thedb(AuthorizedSignaturedatabase)liststhesignersorimagesofUEFI
applications,operatingsystemloaders,andUEFIdriversthatyoucanloadonthe
singlecomputer.
Set New Key
AllowsyoutoloadthedownloadeddbfromaUSBstoragedevice.
Append Key
AllowsyoutoloadtheadditionalKEKfromastoragedeviceforanadditionaldband
dbxloadedmanagement.
TheDBlemustbeformattedasapublickeycerticateorUEFIvariablestructurewith
time-basedauthenticatedvariable.
Delete key
AllowsyoutodeletetheKeyfromyoursystem.Congurationoptions:[Yes][No]
DBX Management
TheDBX(RevokedSignaturedatabase)liststheforbiddenimagesofdbitemsthatare
nolongertrustedandcannotbeloaded.
Set New Key
AllowsyoutoloadthedownloadeddbxfromaUSBstoragedevice.
Append Key
AllowsyoutoloadtheadditionalKEKfromastoragedeviceforanadditionaldband
dbxloadedmanagement.
TheDBXlemustbeformattedasapublickeycerticateorUEFIvariablestructurewith
time-basedauthenticatedvariable.
Delete key
AllowsyoutodeletetheKeyfromyoursystem.Congurationoptions:[Yes][No]
2-42
Chapter 2: Getting started