SBC-C41-pITX
SBC-C41-pITX User Manual - Rev. First Edition: 1.0 - Last Edition: 1.1 - Author: A.R./S.B. - Reviewed by M.B. Copyright © 2021 SECO S.p.A.
63
4.5
Security menu
4.5.1
Secure Boot submenu
4.5.1.1
Key Management submenu
Menu Item
Options
Description
Setup Administrator Password
Set Setup Administrator Password
User Password
Set User Password
Secure Boot
See Submenu
Customizable Secure Boot Settings
Menu Item
Options
Attempt Secure Boot
Enabled / Disabled
Secure Boot is activated when the Platform Key (PK) is enrolled, System Mode is User/Deployed and CSM
function is disabled.
Secure Boot Mode
Standard / Customized
Set UEFI Secure Boot Mode to STANDARD Mode or CUSTOM mode. This change will be effective after
save. And after reset, the mode will return to Standard
Key management
See submenu
Enable expert users to modify Secure Boot Policy variables without full authentication
Menu Item
Options
Provision Factory Default keys
Enabled / Disabled
Provision factory default keys on next re-boot only when System in Setup Mode
Install Factory Default Keys
Force System to User Mode. Configure NVRAM to contain OEM- defined factory default Secure Boot keys
Enroll Efi Image
File System Image
Allow the selected image to run in Secure Boot mode. Enrol SHA256 Hash Certificates of the Image into
Authorized Signature Database (db)
Restore DB defaults
Restore DB variable to factory defaults
Platform key
Key Exchange Keys
Authorized Signatures
Forbidden Signatures
Authorized Timestamps
OS Recovery Signatures
Set New Var
Append Key
Enrol factory Defaults or load certificates from a file:
1. Public Key Certificate in:
a) EFI_SIGNATURE_LIST
b) EFI_CERT_X509 (DER encoded)
c) EFI_CERT_RSA2048 (bin)
d) EFI_CERT_SHA256,384,512
2. Authenticated UEFI variables
3. EFI PE/COFF Image (SHA256), Key Source: Factory, External, Mixed