Asus PRIME Z590-P WIFI Intel 500 series Channel BIOS UM English - Page 53

Secure Boot Mode, Key Management, Install Default Secure Boot Keys, Clear Secure Boot keys

Page 53 highlights

Secure Boot Mode Allows you to select the Secure Boot mode. In Cutom mode, Secure Boot Policy variables can be configured by a physically present user without full authentication. Configuration options: [Standard] [Custom] The following item is accessible only when you set [Secure Boot Mode] to [Custom]. Key Management Allows you to manage the secure boot keys. The following item appears only when all secure boot keys have been delected. Install Default Secure Boot Keys Allows you to load default secure variables. After you press , a confirmation message appears. Use the left or right arrow key to select between [Yes] or [No], then press to confirm your choice. The following items is accessible when secure variables have been loaded. Clear Secure Boot keys Allows you to clear all default Secure Boot keys. After you press , a confirmation message appears. Use the left or right arrow key to select between [Yes] or [No], then press to confirm your choice. Save all Secure Boot variables Allows you to save the NVRAM content of Secure Boot policy variables to the files (EFI_SIGNATURE_LIST data format) in root folder on a target file system device. After you press , a popup window appears displaying the available file system(s). Select a file system and use the left or right arrow key to select between [Yes] or [No], then press to confirm your choice. PK Management The Platform Key (PK) locks and secures the firmware from any permissible changes. The system verifies the PK before your system enters the operating system. Save To File Allows you to save the PK to a target file system device. Set New Key A popup window will appear if you press . Select [Yes] if you wish to load factory default PK, or [No] to load PK from a target file system device. Delete key Allows you to delete the PK from NVRAM. Removing PK will reset the system to Setup/Audit mode. The PK file must be formatted as a UEFI variable structure with time-based authenticated variable. PRIME / TUF GAMING Intel® 500 Series BIOS Manual 53

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64

PRIME / TUF GAMING Intel
®
500 Series BIOS Manual
53
Secure Boot Mode
Allows you to select the Secure Boot mode. In Cutom mode, Secure Boot Policy variables
can be configured by a physically present user without full authentication.
Configuration options: [Standard] [Custom]
The following item is accessible only when you set
[Secure Boot Mode]
to
[Custom]
.
Key Management
Allows you to manage the secure boot keys.
The following item appears only when all secure boot keys have been delected.
Install Default Secure Boot Keys
Allows you to load default secure variables. After you press <Enter>, a confirmation
message appears. Use the left or right arrow key to select between [Yes] or [No], then
press <Enter> to confirm your choice.
The following items is accessible when secure variables have been loaded.
Clear Secure Boot keys
Allows you to clear all default Secure Boot keys. After you press <Enter>, a
confirmation message appears. Use the left or right arrow key to select between [Yes]
or [No], then press <Enter> to confirm your choice.
Save all Secure Boot variables
Allows you to save the NVRAM content of Secure Boot policy variables to the files
(EFI_SIGNATURE_LIST data format) in root folder on a target file system device. After
you press <Enter>, a popup window appears displaying the available file system(s).
Select a file system and use the left or right arrow key to select between [Yes] or [No],
then press <Enter> to confirm your choice.
PK Management
The Platform Key (PK) locks and secures the firmware from any permissible changes.
The system verifies the PK before your system enters the operating system.
Save To File
Allows you to save the PK to a
target file system device
.
Set New Key
A popup window will appear if you press <Enter>. Select [Yes] if you wish to load
factory default PK, or [No] to load PK from a
target file system device
.
Delete key
Allows you to delete the PK from NVRAM.
Removing PK will reset the system to Setup/Audit mode.
The PK file must be formatted as a UEFI variable structure with time-based authenticated
variable.