37
Reset to Setup Mode
Key Management
Press [Enter] to make settings for the following sub-items:
Vendor Keys
Factory Key Provision
This item install factory default Secure Boot keys after the platform reset and
while the system is in setup mode.
The optional settings are: [Disabled]; [Enabled].
Restore Factory Keys
This item force system to user mode. Install factory default secure boot key
databases.
Reset To Setup Mode
Export Secure Boot Variables
Enroll Efi Image
This item allows the image to run in Secure Boot mode.
Enroll SHA256 Hash certificate of a PE image into Authorized Signature
Database (db).
Device Guard Ready Remove ‘UEFI CA’ from DB
Restore DB default
This item restore DB variable to factory defaults.
Secure Boot variable/Size/Keys/Key Source
Platform Key(PK)/Key Exchange Keys/Authorized Signatures/Forbidden
Signatures/ Authorized TimeStamps/OsRecovery Signatures
Use this item to enroll Factory Defaults or load certificates from a file:
1. Public Key Certificate:
a) EFI_SIGNATURE_LIST
b) EFI_ CERT_X509 (DER)
c) EFI_ CERT_RSA2048 (bin)
d) EFI_ CERT_SHAXXX
2. Authenticated UEFI Variable
3. EFI PE/COFF Image (SHA256)
Key Source: Factory, External, Mixed.
3-10 Boot Menu