CLI Guide

Table Of Contents
BIOS.SysSecurity.SecureBootPolicy (Read or Write)
Description
Allows selecting the Secure Boot Policy. When set to Standard, the BIOS uses the key and certificates
from the system manufacturer to authenticate pre-boot images. When set to Custom, the BIOS uses the
user-customized key and certificates. Note: If Custom mode is selected, the Secure Boot Custom Policy
Settings menu is displayed. Note: Changing the default security certificates may cause the system to fail
booting from certain boot options.
When the value of SecureBootMode is DeployedMode AND the value of SecureBoot is Enabled, BIOS
will append a ProgReadOnlyLocal modifier to SecureBoot, SecureBootPolicy, and SecureBootMode. This
means that inband system management tools will not allow users to change these attributes when these
conditions are true.
Legal Values
Standard
Custom
Default Value Not Applicable
Write Privilege Server Control
License Required iDRAC Express or iDRAC Enterprise
Dependency Not applicable
BIOS.SysSecurity.SetupPassword (Read or Write)
Description
The setup password is the password that must be entered to change any BIOS settings. However, the
system password can be changed without entering the correct setup password if Password Status is set
to Unlocked. The password is read-only if the password jumper (PWRD_EN) is not installed in the system.
Legal Values
N/A
Default Value Not Applicable
Write Privilege Server Control
License Required iDRAC Express or iDRAC Enterprise
Dependency Not applicable
BIOS.SysSecurity.SHA256SetupPassword (Read or Write)
Description
SHA256 hash of the setup password.
Legal Values
N/A
Default Value Not Applicable
Write Privilege Server Control
License Required iDRAC Express or iDRAC Enterprise
Dependency Not applicable
BIOS.SysSecurity.SHA256SetupPasswordSalt (Read or Write)
Description
Salt for hash of the setup password.
Legal Values
N/A
Default Value Not Applicable
Write Privilege Server Control
BIOS Attributes 401