Chapter 4: UEFI BIOS
111
Reset To Setup Mode (Available when any secure keys have been
installed)
This feature resets the system to the Setup Mode. The options are Yes and No.
Enroll E Image
This feature allows the image to run in the secure boot mode. Enroll SHA256 Hash cer-
ticate of a PE image into the Authorized Signature Database (DB).
Export Secure Boot Variables (Available when any secure keys have
been installed)
This feature exports the NVRAM contents of secure boot variables to a storage device.
The options are Yes and No.
Secure Boot variable / Size / Keys / Key Source
Platform Key (PK)
Use this feature to enter and congure a set of values to be used as platform rmware
keys for the system. These values also indicate the sizes, keys numbers, and the sources
of the authorized signatures. Select Update to update your "Platform Key." The default
option is Update.
Key Exchange Key (KEK)
Use this feature to enter and congure a set of values to be used as Key-Exchange-Keys
for the system. These values also indicate the sizes, keys numbers, and the sources of
the authorized signatures. Select Update to update your "Key Exchange Keys." Select
Append to append your "Key Exchange Keys." The options are Update and Append.
Authorized Signatures (db)
Use this feature to enter and congure a set of values to be used as Authorized Signatures
for the system. These values also indicate the sizes, keys numbers, and the sources of
the authorized signatures. Select Update to update your "Authorized Signatures." Select
Delete to delete the authorized signatures. The options are Update and Append.