User Manual

Table Of Contents
ASUS TS100-E11-PI4
4-43
Factory Key Provision [Enabled]
AllowsyoutoprovisionfactorydefaultSecureBootkeyswhenthesystemisinSetup
Mode.
Congurationoptions:[Disabled][Enabled]
Install Default Secure Boot Keys
Thisoptionwillloadthedefaultsecurebootkeys,includingthePK(Platformkey),KEK
(key-exchangekey),db(signaturedatabase),anddbx(revokedsignaturedatabase).
Allthesecurebootkeysstateswillchangefromunloadedtoloaded.Savechanges
andresetthesystemforthechangestotakeeffect.
Clear Secure Boot Keys
Thisoptionwilldeleteallpreviouslyappliedsecurebootkeys,includingthePK(Platform
key),KEK(key-exchangekey),db(signaturedatabase),anddbx(revokedsignature
database).Allthesecurebootkeysstateswillchangefromunloadedtoloaded.Save
changesandresetthesystemforthechangestotakeeffect.
Save all Secure Boot Variables
ThisoptionwillsaveNVRAMcontentofSecureBootpolicyvariablestothele(EFI_
SIGNATURE_LISTdataformat)inrootfoleronatargetlesystemdevice.
Enroll Efi Image
This item will allow the image to run in Secure Boot mode. Enroll SHA256 Hash
certicateofaPEimageintoAuthorizedSignatureDatabase(db).
Device Guard Ready
Remove ‘UEFI CA’ from DB
Remove Microsoft UEFI CA from Secure Boot DB.
Restore DB defaults
Restore DB variable to factory defaults.