Skip to main content

Security

This menu allows you to configure system security settings.



Secure Boot Configuration

Item

Options

Description

Secure Boot Status

  • Disabled

  • Enabled

Display the current secure boot status. Disabled is the default setting.

Secure Boot Mode

  • Setup Mode

  • User Mode

The system will do secure boot authentication when this item is set to [User Mode] and secure boot is enabled. User Mode is the default setting.

Secure Boot Setting

  • Enabled

  • Disabled

When enabled, the Secure Boot feature is Active, Platform Key (PK) is enrolled, and the system is in user mode.

The mode change requires platform reset. Disabled is the default setting.

Note

When you attempt to enable secure boot while CSM is enabled, there is a prompt:

WARNING: Legacy BIOS will be disabled when secure boot is enabled.

Secure Boot Policy

  • Factory Policy

  • Custom Policy

  • Delete All Keys

  • Delete PK

  • Reset All Keys to Default

Secure Boot policy options:

[Factory Policy]: Factory default keys will be used after reboot.

[Custom Policy]: Customized keys will be used after reboot.

[Delete All Keys]: PK, KEK, DB, and DBX will be deleted after reboot.

[Delete PK]: PK will be deleted after reboot.

[Reset All Keys to Default]: All keys will be set to factory defaults and "Secure Boot Policy" will be [Factory Policy] after reboot.

Note
  1. "Secure Boot Mode" will be [Setup Mode] and "Secure Boot Policy" will be [Custom Policy] after PK is deleted.

  2. The options cannot be loaded to default in Setup Utility.

View Secure Boot Keys

N/A

View the details of PK (Platform Key), KEK (Key Exchange Key), DB (Authorized Signature Database) and DBX (Forbidden Signature Database).

Secure Boot Custom Policy

N/A

Customize PK, KEK, DB, and DBX.

This page is available when "Secure Boot Policy" is [Custom Policy].

View Secure Boot Keys

ItemOptionsDescription
PKN/AView Certificate in PK (Platform Key).
Note
The system can only have one PK.
KEKN/AView all Certificates in KEK (Key Exchange Key).
DBN/A

View all Certificates in DB (Authorized Signature Database).

DBXN/AView all Certificates in DBX (Forbidden Signature Database).

Secure Boot Custom Policy

ItemOptionsDescription
Enroll Efi ImageN/AEnroll the SHA256 hash of the selected EFI image binary into the Authorized Signature Database (DB).

Trusted Platform Module (TPM 2.0)

ItemOptionsDescription
TPM 2.0N/AConfigure the TPM 2.0 Setup options.
Update to TPM 2.0 firmware version 7.2.2.0N/A
Note
The latest TPM toggling configuration only supports TPM 2.0 firmware update from version 7.2.1.0 to version 7.2.2.0; therefore, this setting is not available for other TPM versions.

When you are trying to degrade to TPM 1.2 or an earlier version of TPM 2.0, the following message will be displayed:Note: This action is irreversible, you won't be able to change to TPM 1.2 or an earlier firmware version of TPM 2.0. The updated firmware will be effective after system reboot.

For TPM 2.0:
ItemOptionsDescription
TPM StatusN/A 
TPM VendorN/ADisplay the TPM Vendor.
TPM Firmware VersionN/ADisplay the current firmware version of the TPM device.
TPM SettingsN/A 
TPM2 Operation
  • No Action

  • Clear

Select [Clear] to clear TPM data. This will erase the contents of the TPM. System reboot is required.
SHA-1 PCR BankFor Ice Lake processor:
  • Enabled

  • Disabled

For CPX platform:
  • Enabled

  • Disabled

Enable/Disable SHA-1 PCR Bank.

Update TPM Firmware from TPM 2.0 to TPM 1.2

ItemOptionsDescription
TPM 1.2 Configure the TPM 1.2 Setup options.
TPM VersionN/A 
Update to TPM2.0 compliant 
Note
  • When update TPM version to TPM2.0 compliant, do not boot a legacy OS due to security consideration.

  • Change is effective after system reboot.

  • You can only switch TPM firmware 128 times.

In latest TPM toggling configuration, only support updating TPM 2.0 firmware version 7.2.1.0 to 7.2.2.0, so this setting will disappear with other TPM version.

Table 1. Trusted Platform Module (TPM 1.2)
ItemOptionsDescription
TPM StatusN/A 
TPM Vendor Display TPM Vendor.
TPM Firmware Version Display the current firmware version of the TPM device.
TPM Device StateDynamic String depend on current TPM status.Display the current state of the TPM Device.
TPM OwnershipDynamic String depend on current TPM status.Display the current status of ownership.
TPM Device
  • Enabled

  • Disabled

Enable/Disable the TPM device.
TPM State
  • Activate

  • Deactivate

Activate/Deactivate the TPM device.
TPM Operation
  • No Action

  • Clear

Select [Clear] to clear TPM data.

WARNING: This will erase the contents of the TPM. System reboot required.