Secure Boot Custom Policy
Item | Options | Description |
---|---|---|
Enroll Efi Image | Enroll the SHA256 hash of the selected EFI image binary into the Authorized Signature Database (DB). Note
| |
Secure Boot variable | Column shows PK, KEK, DB, and DBX | |
Size | Column shows the number of key bytes | |
Keys | Column shows the number of certificates (integer) | |
Key Source |
| |
PK | Enroll a PK (from a Public Key Certificate file format) or delete the existing PK. Note
| |
KEK | Enroll a KEK entry (from a Public Key Certificate file format), or delete an existing entry from the KEK. Note
| |
DB | Enroll a DB entry (from a Public Key Certificate file format or an EFI image file), or delete an existing entry from the DB. Note
| |
DBX |
Message box information for security boot
Message Box | Comment |
Secure Boot Violation An unauthorized EFI image is detected. To use this image, enroll this EFI image or disable secure boot at "Secure Boot Configuration" in Setup Utility. Ok | This message box is popped up when booting form an unsigned shell.efi or OS with secure boot is enabled. |
Give documentation feedback