User Manual
GFK-3066 Rev. A
3.4.3.1
Secure Boot
Enable or disable secure boot. Secure Boot can be enabled if: 1. System running in user mode with enrolled
platform key (PK); 2. CSM function is disabled.
3.4.3.2
Secure Boot Mode
Select secure boot mode: standard or custom. Custom mode enables users to change image execution
policy and manage secure boot keys.
3.4.4
Key Management
This section enables experienced users to modify secure boot variables.
3.4.4.1
Default Key Provision
Enable or disable to install factory default secure boot keys when system is in setup mode. When enabled, a
pop-up window will display. Select "Yes" and press <Enter> to install factory default keys.
3.4.4.2
Enroll All Factory Default Keys
Select "Yes" and press <Enter> to install ALL factory default keys, including PK, KEK, DB, DBX and DBT.
Change takes effect after reboot.
BIOS Setup
Section 1
May 2019
53