3.5.2 Key Management
Provision Factory Default Keys
Install factory default Secure Boot Keys when System is in Setup Mode.
Enabled / Disabled
Enroll all factory Default keys
Force System to User Mode-install all Factory Default keys
Platform Key (PK)
Set New Key
1. Public Key Certificate in:
a) EFI_SIGNATURE_LIST
b) EFI_CERT_X509 (DER encoded)
c) EFI_CERT_RSA2048 (bin)
d) EFI_CERT_SHA256 (bin)
2. Authenticated UEFI Variable
Key: Vendor, Custom, Mixed, Test
(*) modified from Setup menu
Set New Key
Append Key
116
http://www.tyan.com