Secure boot
Table 8. Secure Boot
Option Description
Secure Boot Enable
Allows you to enable or disable the Secure Boot Feature.
Click one of the following options:
• Disabled
• Enabled—Default
Expert Key Management
Allows you to enable or disable Expert Key Management.
• Enable Custom Mode
This option is not set by default.
The Custom Mode Key Management options are:
• PK—Default
• KEK
• db
• dbx
Intel Software Guard Extensions
Table 9. Performance
Option Description
Intel SGX Enable
This elds species you to provide a secured environment for
running code/storing sensitive information in the context of the
main OS. The options are:
• Disabled
• Enabled
• Software Controlled—Default
Enclave Memory Size
This option sets SGX Enclave Reserve Memory Size. The option
are:
• 32 MB
• 64 MB
• 128 MB
This option is set by default.
System Setup 69