3.3.2.1 Key Management
Factory Key Provision
Install factory default Secure Boot keys after the platform reset and while the
System is in Setup mode.
Disabled / Enabled
Restore Factory Keys
Force System to User Mode. Install factory default Secure Boot key databases.
Reset to Setup Mode
Deleting all Secure Boot key databases from NVRAM.
Platform Key (PK)
Enroll Factory Defaults or load certificates from a file:
1. Public Key Certificate:
a) EFI_SIGNATURE_LIST
b) EFI_CERT_X509 (DER)
c) EFI_CERT_RSA2048 (bin)
d) EFI_CERT_SHAXXX
2. Authenticated UEFI Variable
3. EFI PE/COFF Image (SHA256)
Key source: Factory, External, Mixed
63
http://www.tyan.com