Option Description
UEFI Capsule
Firmware
Updates
This option controls whether the system allows BIOS updates through UEFI capsule update packages.
NOTE: Disabling this option will block the BIOS updates from services such as Microsoft Windows
Update and Linux Vendor Firmware Service (LVFS).
This option is enabled by default.
TPM 2.0 Security Allows you to enable the Trusted Platform Module (TPM) during POST. This option is enabled by default.
The options are:
● TPM On
● Clear
● PPI Bypass for Enabled Commands
● PPI Bypass for Disabled Commands
● Attestation Enable
● Key Storage Enable
● SHA - 256
NOTE: Activation, deactivation, and clear options are not affected if you load the setup program's
default values. Changes to this option take effect immediately.
Computrace (R) Allows you to activate or disable the optional Computrace software The options are:
● Deactivate
● Disable
● Activate
NOTE: The Activate and Disable options will permanently activate or disable the feature and no
further changes will be allowed
Default setting: Deactivate
CPU XD Support Allows you to enable or disable the Execute Disable mode of the processor.
Enable CPU XD Support (default)
Admin Setup
Lockout
Allows you to enable or disable the option to enter setup when an admin password is set.
● Enable Admin Setup Lockout - This option is disabled by default.
Secure boot screen options
Option
Description
Secure Boot
Enable
This option enables or disables the Secure Boot feature.
● Disabled
● Enabled
Default setting: Enabled.
Expert Key
Management
Allows you to manipulate the security key databases only if the system is in Custom Mode. The Enable
Custom Mode option is disabled by default. The options are:
● PK
● KEK
● db
● dbx
If you enable the Custom Mode, the relevant options for PK, KEK, db, and dbx appear. The options are:
● Save to File—Saves the key to a user-selected file
● Replace from File—Replaces the current key with a key from a user-selected file
● Append from File—Adds a key to the current database from a user-selected file
●
Delete—Deletes the selected key
● Reset All Keys—Resets to default setting
● Delete All Keys—Deletes all the keys
48 System Setup Options