- 78 -
BIOS Setup
Parameter
Description
Key Management
Press[Enter]tocongureadvanceditems.
Please note that this item is congurable when Secure Boot Mode is set
to Custom.
Factory Key Provision
– Allows to provision factory default Secure Boot keys when system is in
Setup Mode.
– Options available: Enabled, Disabled. Default setting is Disabled.
Restore Factory Keys
– Installs all factory default keys. It will force the system in User Mode.
– Options available: Yes, No.
EnrollEImage
– Press [Enter] to enroll SHA256 hash of the binary into Authorized
Signature Database (db).
Secure Boot variable
– Displays the current status of the variables used for secure boot.
Platform Key (PK)
– Displays the current status of the Platform Key (PK).
– Press[Enter]tocongureanewPK.
– Options available: Update.
Key Exchange Keys (KEK)
– Displays the current status of the Key Exchange Key Database (KEK).
– Press[Enter]tocongureanewKEKorloadadditionalKEKfrom
storage devices.
– Options available: Update, Append.
Authorized Signatures (DB)
– Displays the current status of the Authorized Signature Database.
– Press[Enter]tocongureanewDBorloadadditionalDBfromstorage
devices.
– Options available: Update, Append.
Forbidden Signatures (DBX)
– Displays the current status of the Forbidden Signature Database.
– Press[Enter]tocongureanewdbxorloadadditionaldbxfrom
storage devices.
– Options available: Update, Append.
Authorized TimeStamps (DBT)
– Displays the current status of the Authorized TimeStamps Database.
– Press[Enter]tocongureanewDBTorloadadditionalDBTfrom
storage devices.
– Options available: Update, Append.
OsRecovery Signatures
– Displays the current status of the OsRecovery Signature Database.
– Press[Enter]tocongureanewOsRecoverySignatureorload
additional OsRecovery Signature from storage devices.
– Options available: Update, Append.