Option
Internal HDD-2 Password
Password Change
UEFI Capsule Firmware Updates
PTT Security
Master Password Lockout
HDD Protection Support
SMM Security Mitigation
CPU XD Support
Table 21. Secure Boot
Option
Secure Boot Enable
Secure Boot Mode
Expert key Management
Description
Allows you to set, change or delete the password on the system's internal hard-disk drive.
NOTE:
Successful password changes take effect immediately.
Default Setting: Not set
Allows you to enable the disable permission to the System and Hard Drive passwords when the admin
password is set.
Default Setting: Allow Non-Admin Password Changes is selected.
Allows you to controls whether the system allows BIOS update via UEFI capsule update packages.
Default setting: Enable
Allows you to control the Platform Trust Technology feature (PTT) is visible to the operating system.
The options are:
•
PTT On
NOTE:
Disabling this option dose not change any setting you have made to the PTT nor
dose it delete or change any information or keys you may have stored in the PTT. Changes
to this settings take effect immediately
The option is disabled by default
The option is disabled by default
The option is disabled by default
Allows you to enable or disable the Execute Disable mode of the processor. This option is enabled by
default.
Description
Allows you to enable or disable Secure Boot feature. The option is disabled by default.
•
Deployed Mode (default)
•
Audit Mode
Allows you to manipulate the security key databases only if the system is in Custom Mode. The
Enable Custom Mode option is disabled by default. The options are:
•
PK (default)
•
KEK
•
db
•
dbx
If you enable the Custom Mode, the relevant options for PK, KEK, db, and dbx appear. The
options are:
•
Save to File- Saves the key to a user-selected file
•
Replace from File- Replaces the current key with a key from a user-selected file
•
Append from File- Adds a key to the current database from a user-selected file
•
Delete- Deletes the selected key
•
Reset All Keys- Resets to default setting
•
Delete All Keys- Deletes all the keys
NOTE:
If you disable the Custom Mode, all the changes made will be erased and the
keys will restore to default settings.
System setup
19