26 | 5. Security Menu
Secure Boot
Secure Boot can be enabled if 1. System running in user mode with enrolled Plaorm Key(PK)
2.CSM funcon is disabled.
Opons: Disabled (Default) / Enabled
Secure Boot Mode
Secure Boot mode selector. ‘Custom’ mode enables users to change Image Execuon policy and
manage Secure Boot Keys.
Opons: Custom (Default) / Standard
Key Management
Provision Factory Default Keys
Install factory default Secure Boot Keys when system is in setup mode.
Opons: Disabled (Default) / Enabled
Enroll all Factory Default Keys
Force System to User Mode - install all Factory Default Keys(PK, KEK, , dbt, dbx). Change takes
eect aer reboot.
Save all Factory Default Keys
Save NVRAM content of all Secure Boot Variables to the les (EFI_SIGNATURE_LIST data format)
in root folder on a target le system device.
Plaorm Key (PK)
Delete Key – Allows you to delete the PK le from your system.
Set new Key – Allows you set new PK le.
Key Exchange Key
Delete Key – Allows you to delete the KEK le from your system.
Set new Key – Allows you set new KEK le.
Append Key – Allows you append Var to KEK.
Authorized Signature
Delete Key – Allows you to delete the DB le from your system.
Set new Key – Allows you set new DB le.
Append Key – Allows you append Var to DB.