47
Secure Boot
Secure Boot feature is active if secure boot is enabled, Platform Key(PK) is
enrolled and the system is in user mode. The mode change requires platform
reset.
The optional settings are: [Disabled]; [Enabled].
Secure Boot Mode
Use this item to Secure Boot mode to Standard mode or Custom mode. This
change is effective after save. After reset, this mode will return to Standard mode.
In Custom mode, Secure Boot Policy variables can be configured by a physically
present user without full authentication.
The optional settings: [Standard]; [Custom].
When set as [
Custom
], user can make further settings in the following items that
show up:
Restore Factory Keys
This item force system to user mode. Install factory default secure boot key
databases.
Reset to Setup Mode
Key Management
Press [Enter] to make settings for the following sub-items:
Vendor Keys
Factory Key Provision
This item install factory default Secure Boot keys after the platform reset and
while the system is in setup mode.
The optional settings are: [Disabled]; [Enabled].
Restore Factory Keys
This item force system to user mode. Install factory default secure boot key
databases.
Enroll Efi Image
This item allows the image to run in Secure Boot mode.
Enroll SHA256 Hash certificate of a PE image into Authorized Signature
Database (db).