Users Guide

Table Of Contents
To support a new driver or firmware on a server, the respective certificate must be enrolled into the DB of Secure Boot
certificate store. Therefore, Secure Boot Policy must be configured to Custom.
When the Secure Boot Policy is configured as Custom, it inherits the standard certificates and image digests loaded in the
system by default, which you can modify. Secure Boot Policy configured as Custom allows you to perform operations such
as View, Export, Import, Delete, Delete All, Reset, and Reset All. Using these operations, you can configure the Secure Boot
Policies.
Configuring the Secure Boot Policy to Custom enables the options to manage the certificate store by using various actions such
as Export, Import, Delete, Delete All, Reset, and Rest All on PK, KEK, DB, and DBX. You can select the policy (PK / KEK / DB /
DBX) on which you want to make the change and perform appropriate actions by clicking the respective link. Each section will
have links to perform the Import, Export, Delete, and Reset operations. Links are enabled based on what is applicable, which
depends on the configuration at the point of time. Delete All and Reset All are the operations that have impact on all the policies.
Delete All deletes all the certificates and image digests in the Custom policy, and Rest All restores all the certificates and image
digests from Standard or Default certificate store.
BIOS recovery
The BIOS recovery feature allows you to manually recover the BIOS from a stored image. The BIOS is checked when the
system is powered-on and if a corrupt or compromised BIOS is detected, an error message is displayed. You can then initiate
the process of BIOS recovery using RACADM. To perform a manual BIOS recovery, see the iDRAC RACADM Command Line
Interface Reference Guide available at https://www.dell.com/idracmanuals.
Setting up managed system 89