Chapter 6: BIOS
83
Append Key
Select Yes to add the KEK from the manufacturer's defaults list to the existing KEK. Select No to
Authorized Signatures
Set New Key
Select Yes to load the database from the manufacturer's defaults. Select No to load the DB from
Append Key
Select Yes to add the database from the manufacturer's defaults to the existing DB. Select No to
Forbidden Signatures
Set New Key
Select Yes to load the DBX from the manufacturer's defaults. Select No to load the DBX from a
Append Key
Select Yes to add the DBX from the manufacturer's defaults to the existing DBX. Select No to
Authorized TimeStamps
Set New Key
Select Yes to load the DBT from the manufacturer's defaults. Select No to load the DBT from a
Append Key
Select Yes to add the DBT from the manufacturer's defaults list to the existing DBT. Select No to
OsRecovery Signature
This item uploads and installs an OSRecovery Signature. You may select options for Set New for
a. EFI Signature List
b. EFI CERT X509 (DER Encoded)
c. EFI CERT RSA2048 (bin)
d. EFI SERT SHA256 (bin)
2) EFI Time Based Authenticated Variable