Chapter 4: BIOS
115
Reset to Setup Mode
This feature deletes all Secure Boot key databases from NVRAM.
Export Secure Boot variables
This feature allows you to copy NVRAM content of Secure boot variables to les in a
root folder on a le system device.
Enroll EFI Image
This feature allows the image to run in Secure Boot Mode. Enroll SHA256 Hash Certi-
cate of the image into the Authorized Signature Database.
Device Guard Ready
Remove 'UEFI CA' from DB
This feature allows you to decide if all secure boot variables should be saved.
Restore DB defaults
Select Yes to restore the DB defaults.
Secure Boot Variable
Platform Key (PK)
Update
Select Yes to load the new Platform Keys (PK) from the manufacturer's defaults. Select
No to load the Platform Keys from a le.
Key Exchange Key
Update
Select Yes to load the KEK from the manufacturer's defaults. Select No to load the Key
Exchange Keys from a le.
Append
Select Yes to add the KEK from the manufacturer's defaults list to the existing KEK.
Select No to load the KEK from a le.