User's Manual

4-24
X9SPU-F Motherboard User’s Manual
Secure Boot Policy
Use this feature to congure the extended options for Secure Boot mode.
Internal FV
Use this item to determine whether or not to load an image from the above device
path in the event of a security violation. The current available option is Always
Execute.
Option ROM, Removable Media, Fixed Media
Use this item to determine whether or not to load an image from the above device
paths in the event of a security violation. The options are Always Execute, Always
Deny, Allow Execute, Defer Execute, Deny Execute, and Query User.
Key Management
Use this feature to congure key management options for the following items:
Platform Key (PK)
Set PK from File: This item launches the Filebrowser to set the Platform Key from
le.
Get PK to File: This item stores the existing Platform key to le name PK in se-
lected lesystem's root.
Delete the PK: Deletes the Platform Key
Key Exchange Key Database (KEK)
Set KEK from File: This item launches the Filebrowser to set the Key Exchange
Key Signature Database from le.
Get KEK to File: This item stores the existing Key Exchange Key Signature Data-
base to le name KEK in selected lesystem's root.
Delete the KEK: Deletes the Key Exchange Key Signature Database.
Append an entry to KEK: This item launches the Filebrowser to append the Key
Exchange Key Signature Database entry from le.
Authorized Signature Database (DB)
Set DB from File: This item launches the Filebrowser to set the Authorized Sig-
nature Database from le.
Get DB to File: This item stores the existing Authorized Signature Database to le
name DB in selected lesystem's root.