Chapter 4: BIOS
91
*If Secure Boot Mode is set to Customized, Key Management features will be available
for conguration:
Reset to Setup Mode
Select Yes to delete all Secure Boot key databases and force the system to Setup Mode.
The options are Yes and No.
Restore Factory Keys
Select Yes to restore all factory keys to the default settings. The options are Yes and No.
Key Management
This submenu allows the user to congure the following Key Management settings.
Provision Factory Default Keys
Select Enabled to install the default Secure Boot keys set by the manufacturer. The options
are Disabled and Enabled.
Install Factory Default Keys
Select Yes to install the default settings for all keys. The options are Yes and No.
Enroll E Image
This feature allows the image to run in Secure Boot mode.
Save All Secure Boot Variables
This feature allows the user to decide if all secure boot variables should be saved.
Platform Key (PK)
This feature allows the user to congure the settings of the platform keys.
Set New Key
Select Yes to load the new platform keys (PK) from the manufacturer's defaults. Select No
to load the platform keys from a le. The options are Yes and No.
Key Exchange Key (KEK)
Set New Key
Select Yes to load the KEK from the manufacturer's defaults. Select No to load the KEK
from a le. The options are Yes and No.
Append Key
Select Yes to add the KEK from the manufacturer's defaults list to the existing KEK. Select
No to load the KEK from a le. The options are Yes and No.