Chapter 4: BIOS
123
Secure Boot
Use this feature to enable secure boot. The options are Disabled and Enabled.
Secure Boot Mode
Use this item to congure Secure Boot variables without authentication. The options are
Standard and Custom.
CSM Support
This feature is for manufacturing debugging purposes.
Enter Audit Mode
This submenu can only be used if current System Mode is set to User (refer to Exit Deployed
Mode). The PK variable will be erased on transition to Audit Mode.
Key Management
This submenu allows you to congure the following Key Management settings.
Restore Factory Keys
Force System to User Mode. Install factory default Secure Boot key databases.
Reset to Setup Mode
This feature deletes all Secure Boot key databases from NVRAM.
Export Secure Boot variables
This feature allows you to copy NVRAM content of Secure boot variables to les in a
root folder on a le system device.
Enroll EFI Image
This feature allows the image to run in Secure Boot Mode. Enroll SHA256 Hash Certi-
cate of the image into the Authorized Signature Database.
Device Guard Ready
Remove 'UEFI CA' from DB
This feature allows you to decide if all secure boot variables should be saved.