Option Description
Internal HDD-2 Password Allows you to set, change or delete the password on the system's internal hard-disk drive.
NOTE: Successful password changes take eect immediately.
Default Setting: Not set
Password Change Allows you to enable the disable permission to the System and Hard Drive passwords when the admin
password is set.
Default Setting: Allow Non-Admin Password Changes is selected.
UEFI Capsule Firmware Updates Allows you to controls whether the system allows BIOS update via UEFI capsule update packages.
Default setting: Enable
PTT Security Allows you to control the Platform Trust Technology feature (PTT) is visible to the operating system.
The options are:
• PTT On
NOTE: Disabling this option dose not change any setting you have made to the PTT nor
dose it delete or change any information or keys you may have stored in the PTT. Changes
to this settings take eect immediately
Master Password Lockout The option is disabled by default
HDD Protection Support The option is disabled by default
SMM Security Mitigation The option is disabled by default
CPU XD Support Allows you to enable or disable the Execute Disable mode of the processor. This option is enabled by
default.
Table 21. Secure Boot
Option Description
Secure Boot Enable Allows you to enable or disable Secure Boot feature. The option is disabled by default.
Secure Boot Mode
• Deployed Mode (default)
• Audit Mode
Expert key Management Allows you to manipulate the security key databases only if the system is in Custom Mode. The
Enable Custom Mode option is disabled by default. The options are:
• PK (default)
• KEK
• db
• dbx
If you enable the Custom Mode, the relevant options for PK, KEK, db, and dbx appear. The
options are:
• Save to File- Saves the key to a user-selected le
• Replace from File- Replaces the current key with a key from a user-selected le
• Append from File- Adds a key to the current database from a user-selected le
• Delete- Deletes the selected key
• Reset All Keys- Resets to default setting
• Delete All Keys- Deletes all the keys
NOTE: If you disable the Custom Mode, all the changes made will be erased and the
keys will restore to default settings.
System setup 19