Secure Boot Custom Policy
Item | Description |
Enroll Efi Image | Enroll the SHA256 hash of the selected EFI image binary into the Authorized Signature Database (DB). To Enroll:
|
Secure Boot Violation
An unauthorized EFI image is detected. To use this image, please enroll this EFI image or disable secure boot at
"Secure Boot Configuration" in Setup Utility.
Ok
When selecting each Secure Boot variable, you will be able to add/delete it or view the details of it.
Secure Boot variable | Size | Keys# | Key Source | Description |
PK | Number of bytes | Number of certificates (integer) |
| Enroll a PK (from a Public Key Certificate file format) or delete the existing PK. Note There will be only one PK in the system. If a PK already exists, it will not be available for you to add another unless the exiting one is removed. |
KEK | Number of bytes | Number of certificates (integer) |
| Enroll a KEK entry (from a Public Key Certificate file format), or delete an existing entry from the KEK. |
DB | Number of bytes | Number of certificates (integer) |
| Enroll a DB entry (from a Public Key Certificate file format or an EFI image file), or delete an existing entry from the DB. |
DBX | Number of bytes | Number of certificates (integer) |
| Enroll a DBX entry (from a Public Key Certificate file format or an EFI image file), or delete an existing entry from the DBX. |
Add or Delete Secure Boot Variables
The following steps provide the information about the steps of adding/deleting the key items.
Add a PK | Delete a PK | ||||
|
|
Add a KEK | Delete a KEK | ||||
|
|
Add a DB | Delete a DB | ||||
|
|
Add a DBX | Delete a DBX | ||||
|
|
Details of the Key
When selecting Details while viewing a key item, the detail of it will be then displayed:
PK / KEK / DB / DBX | |||||
List | Sig.Type | Count | Size | Owner GUID | Certificate Legend |
The key information of each section above will be listed here. |