Secure Boot Custom Policy
| Item | Options | Description |
|---|---|---|
| Enroll Efi Image | Enroll the SHA256 hash of the selected EFI image binary into the Authorized Signature Database (DB). Note
| |
| Secure Boot variable | Column shows PK, KEK, DB, and DBX | |
| Size | Column shows the number of key bytes | |
| Keys | Column shows the number of certificates (integer) | |
| Key Source |
| |
| PK | Enroll a PK (from a Public Key Certificate file format) or delete the existing PK. Note
| |
| KEK | Enroll a KEK entry (from a Public Key Certificate file format), or delete an existing entry from the KEK. Note
| |
| DB | Enroll a DB entry (from a Public Key Certificate file format or an EFI image file), or delete an existing entry from the DB. Note
| |
| DBX | ||
Message box information for security boot
| Message Box | Comment |
Secure Boot Violation An unauthorized EFI image is detected. To use this image, enroll this EFI image or disable secure boot at "Secure Boot Configuration" in Setup Utility. Ok | This message box is popped up when booting form an unsigned shell.efi or OS with secure boot is enabled. |
Give documentation feedback