4-24
X9SPU-F Motherboard User’s Manual
Secure Boot Policy
Use this feature to congure the extended options for Secure Boot mode.
Internal FV
Use this item to determine whether or not to load an image from the above device
path in the event of a security violation. The current available option is Always
Execute.
Option ROM, Removable Media, Fixed Media
Use this item to determine whether or not to load an image from the above device
paths in the event of a security violation. The options are Always Execute, Always
Deny, Allow Execute, Defer Execute, Deny Execute, and Query User.
Key Management
Use this feature to congure key management options for the following items:
Platform Key (PK)
Set PK from File: This item launches the Filebrowser to set the Platform Key from
le.
Get PK to File: This item stores the existing Platform key to le name PK in se-
lected lesystem's root.
Delete the PK: Deletes the Platform Key
Key Exchange Key Database (KEK)
Set KEK from File: This item launches the Filebrowser to set the Key Exchange
Key Signature Database from le.
Get KEK to File: This item stores the existing Key Exchange Key Signature Data-
base to le name KEK in selected lesystem's root.
Delete the KEK: Deletes the Key Exchange Key Signature Database.
Append an entry to KEK: This item launches the Filebrowser to append the Key
Exchange Key Signature Database entry from le.
Authorized Signature Database (DB)
Set DB from File: This item launches the Filebrowser to set the Authorized Sig-
nature Database from le.
Get DB to File: This item stores the existing Authorized Signature Database to le
name DB in selected lesystem's root.