Secure Boot Configuration
Use this menu to configure secure boot settings.
Check your UEFI firmware version to decide whether asserting physical presence is required before any changes to security settings.
UEFI firmware before v2.02
Asserting physical presence is required.
UEFI firmware v2.02 and later
Asserting physical presence is no longer required, all local accounts and some authorized remote accounts can directly change the settings.
Item | Operation | Description |
---|---|---|
Secure Boot | ||
Physical Presence |
| Dynamic information. Display the current Physical Presence status. Physical Presence is a form of authorization to perform certain security functions. [Asserted] means being authorized.
De-asserted is the default setting Note When the setting is De-asserted, the whole page is grayed. |
Secure Boot Status |
| Dynamic information. Display the current secure boot status. Disabled is the default setting. |
Secure Boot Mode |
| Selectable option. System will do secure boot authentication when “Secure Boot Mode” is [User Mode] and secure boot is enabled. User Mode is the default setting. |
Secure Boot Setting |
| Selectable option. Enable/Disable secure boot. This setting is modifiable when “Physical Presence” is asserted and cannot be loaded to default in Setup Utility. User Mode is the default setting. Note
|
Secure Boot Policy |
| Selectable option. This setting is modifiable when "Physical Presence" is asserted and cannot be loaded to default in Setup Utility. [Factory Policy]: Factory default keys will be used after reboot. Factory Policy is the default setting. [Custom Policy]: Customized keys will be used after reboot. [Delete All Keys]: PK, KEK, DB and DBX will be deleted after reboot. [Delete PK]: PK will be deleted after reboot. "Secure Boot Mode" is [Setup Mode] and "Secure Boot Policy" is [Custom Policy] after PK is deleted. [Reset All Keys to Default]: All the keys will be set to factory defaults and "Secure Boot Policy" is [Factory Policy] after reboot. |
Sub menu. View the details of PK(Platform Key) , KEK (Key Exchange Key) , DB (Authorized Signature Database) and DBX (Forbidden Signature Database). | ||
Sub menu. Customize PK (Platform Key), KEK (Key Exchange Key), DB (Authorized Signature Database) and DBX (Forbidden Signature Database). This item is available when Secure Boot Policy is set as [Custom Policy]. |