Skip to main content

Key Management

Use this submenu to set the secure boot policy variables.

Submenu itemOptionDescription
Factory Key ProvisionDisable | Enable

Install factory default Secure Boot keys after the platform reset and while the System is in Setup mode.

The default option is Disable.

Enroll Efi ImageOK

Allow the image to run in Secure Boot mode. Enroll SHA256 Hash certificate of a PE image into Authorized Signature Database (db)

Device Guard Ready
Remove 'UEFI CA' from DBN/A

Device Guard ready system must not list 'Microsoft UEFI CA' Certificate in Authorized Signature database (db)

Resotre DB defaultsN/A

Restore DB variable to factory defaults

Secure Boot variable
Platform Key(PK)N/A
Enroll Factory Defaults or load certificates from a file:
  1. Public Key Certificate:
    1. EFI_SIGNATURE_LIST

    2. EFI_CERT_X509 (DER)

    3. EFI_CERT_RSA2048 (bin)

    4. EFI_CERT_SHAXXX

  2. Authenticated UEFI Variable

  3. EFI PE/COFF Image(SHA256)

Key Source: Factory, External, Mixed

Key Exchange Keys N/A
Authorized SignaturesN/A
Forbidden SignaturesN/A