Uefi System Utilities; Secure Boot - HPE ProLiant XL645d User Manual

Gen10 plus server
Table of Contents

Advertisement

UEFI System Utilities

The UEFI System Utilities is embedded in the system ROM. Its features enable you to perform a wide range of
configuration activities, including:
Configuring system devices and installed options.
Enabling and disabling system features.
Displaying system information.
Selecting the primary boot controller or partition.
Configuring memory options.
Launching other preboot environments.
HPE servers with UEFI can provide:
Support for boot partitions larger than 2.2 TB. Such configurations could previously only be used for boot drives when
using RAID solutions.
Secure Boot that enables the system firmware, option card firmware, operating systems, and software collaborate to
enhance platform security.
UEFI Graphical User Interface (GUI)
An Embedded UEFI Shell that provides a preboot environment for running scripts and tools.
Boot support for option cards that only support a UEFI option ROM.

Secure Boot

Secure Boot is a server security feature that is implemented in the BIOS and does not require special hardware. Secure
Boot ensures that each component launched during the boot process is digitally signed and that the signature is validated
against a set of trusted certificates embedded in the UEFI BIOS. Secure Boot validates the software identity of the
following components in the boot process:
UEFI drivers loaded from PCIe cards
UEFI drivers loaded from mass storage devices
Preboot UEFI Shell applications
OS UEFI boot loaders
When Secure Boot is enabled:
Firmware components and operating systems with boot loaders must have an appropriate digital signature to execute
during the boot process.
Operating systems must support Secure Boot and have an EFI boot loader signed with one of the authorized keys to
boot. For more information about supported operating systems, see https://www.hpe.com/servers/ossupport.
You can customize the certificates embedded in the UEFI BIOS by adding or removing your own certificates, either from a
management console directly attached to the server, or by remotely connecting to the server using the iLO Remote
Console.
You can configure Secure Boot:
Software and configuration utilities
105

Advertisement

Table of Contents
loading

Table of Contents