© Copyright Lenovo 2017
70
AdministratorPassword
SetAdministratorPassword
UserPassword
SetUserPassword
One Blank Line
SecureBootmenu
#In Secure Boot menu Table
CustomizableSecureBoot
settings
SecureBootmenuTable(Subof
SecurityMenu)
SecureBootmenu CustomizableSecureBootsettings
SystemMode Setup
SecureBoot NotActive
VendorKeys NotActive
AttemptSecureBoot Disabled/Enabled SecureBoo tactivatedwhenPlatformKey(PK)is
enrolled,SystemmodeisUser/Deployed,andCSM
functionisdisabled
SecureBootMode Standard/Custom SecureBootmodeselector:Standard/Custom.In
CustommodeSecureBootVariablescan
beconfiguredwithoutauthentication
KeyManagement EnablesexperienceduserstomodifySecureBoot
variables
ForMLKBIOSonly.
ProvisionFactoryDefault
keys
Disabled/Enabled
InstallfactorydefaultSecureBootkeyswhen
SystemisinSetupMode
ForMLKBIOSonly.
Oneblankline
EnrollallFactoryDefault
keys
Yes/No
ForceSystemtoUserMode‐installFactoryDefault
keys(PK,KEK,db,dbx).Changetakeseffectafter
reboot.
ForMLKBIOSonly.
Sav eallSecureBoot
variables
Sav eNVRAMcontentofallSecureBootvariablesto
thefiles(EFI_SIGNATURE_LISTdataformat)inroot
folderonatargetfilesystemdevice
ForMLKBIOSonly.
Oneblankline
SecureBootvariable|
Size|Key#|Keysource
PlatformKey(PK)| SetNewKey/Delete EnrollFactoryDefaultsorloadthekeysfromafile