74
3.6.1 Secure Boot
Allow users to configure boot mode and key management.
Secure Boot: Allow users to enable/disable secure boot feature. The default value is ‘Disabled’. Secure Boot feature is active
if Secure Boot is Enabled, Platform Key (PK) is enrolled and the system is in User Mode. The mode change requires a
platform reset.
Secure Boot Customization: Secure Boot mode options: ‘Standard’ or ‘Custom’. In Custom mode, Secure Boot Policy
variables can be configured by a physically present user without full authentication.
Restore Factory Keys: Force system to User Mode and install factory default Secure Boot key databases.
Reset to Setup Mode: Delete NVRAM content of all UEFI Secure Boot key database.
Key Management: Allows the user to configure the following key Management settings: