62
IB822 Series
User’s Manual
4.6.1.1.
Factory Key Provision
BIOS Setting
Description
Restore Factory
Keys
Provision factory default keys on next re-boot
only when the system is in Setup mode.
Restore Factory
Keys
Force system to user mode. Configure NVRAM
to contain OEM-defined factory default secure
boot keys.
Enroll Efi Image
Allows the image to run in Secure Boot mode.
Enroll SHA256 Hash certificate of a PE image
into Authorized signature database (db).
Restore DB defaults
Restore DB variable to factory defaults.
Platform Key (PK) /
Key Exchange Keys
/ Authorized
Signatures /
Forbidden
Signatures /
Authorized
TimeStamps /
OsRecovery
Signatures
Enrolls factory defaults or load certificates from
a file:
1.) Public Key Certificate in:
EFI_SIGNATURE_LIST /
EFI_CERT_XS09 (DER encoded) / EFI-
CERT_RSA2048 (bin) /
EFI_CERT_SHA256,384,512
2.) Authenticated UEFI Variable
3.) EFI PE/COFF Image (SHA256)
Key source: factory, external, mixed