User Manual

Table Of Contents
4-41
Install Default Secure Boot Keys
This option will load the default secure boot keys, including the PK (Platform key), KEK
(key-exchange key), db (signature database), and dbx (revoked signature database). All the
secure boot keys states will change from unloaded to loaded. Save changes and reset the
system for the changes to take effect.
Clear Secure Boot Keys
This option will delete all previously applied secure boot keys, including the PK (Platform
key), KEK (key-exchange key), db (signature database), and dbx (revoked signature
database). All the secure boot keys states will change from unloaded to loaded. Save
changes and reset the system for the changes to take effect.
Key Management
This item only appears when the item Secure Boot Mode is set to [Custom]. The Key
Management item allows you to modify Secure Boot variables and set Key Management
page.
Factory Key Provision [Enabled]
Allows you to provision factory default Secure Boot keys when the system is in Setup
Mode.
Configuration options: [Disabled] [Enabled]
Install Default Secure Boot Keys
This option will load the default secure boot keys, including the PK (Platform key), KEK
(key-exchange key), db (signature database), and dbx (revoked signature database).
All the secure boot keys states will change from unloaded to loaded. Save changes
and reset the system for the changes to take effect.
Clear Secure Boot Keys
This option will delete all previously applied secure boot keys, including the PK
(Platform key), KEK (key-exchange key), db (signature database), and dbx (revoked
signature database). All the secure boot keys states will change from unloaded to
loaded. Save changes and reset the system for the changes to take effect.
PK Management
Configuration options: [Details] [Save To File] [Set New Key] [Delete key]
KEK Management / DB Management / DBX Management\
Configuration options: [Details] [Save To File] [Set New Key] [Append Key] [Delete key]
DB Management / DB Management / DBX Management
Configuration options: [Details] [Save To File] [Set New Key] [Append Key] [Delete key]
DBX Management / DB Management / DBX Management
Configuration options: [Details] [Save To File] [Set New Key] [Append Key] [Delete key]
Authorized TimeStamps / OsRecovery Signatures
Configuration options: [Set New Key] [Append Key]
Save all Secure Boot Variables
This option will save NVRAM content of Secure Boot policy variables to the file (EFI_
SIGNATURE_LIST data format) in root foler on a target file system device.