Asus P9D-X User Guide - Page 96

Key Management, Image Execution Policy

Page 96 highlights

Image Execution Policy This item only appears when you set the Secure Boot Mode to [Custom]. This allows you to manage the Image Policy on Security Violation. Aptio Setup Utility - Copyright (C) 2013 American Megatrends, Inc. Security Interval FV Option ROM Removable Media Fixed Media [Always Execute] [Deny Execute] [Deny Execute] [Deny Execute] Image Execution Policy per device path on Security Violation. Internal FV [Always Execute] Configuration options: [Always Execute] Option ROM/Removable Media/Fixed Media [Deny Execute] Configuration options: [Always Execute] [Always Deny] [Allow Execute] [Defer Execute] [Deny Execute] [Query User] Key Management This item only appears when you set the Secure Boot Mode to [Custom]. This allows you to modify Secure Boot variables and set Key Management page. Aptio Setup Utility - Copyright (C) 2013 American Megatrends, Inc. Security Factory Default Key Provisioning Install All Factory Default Keys [Disabled] Install Factory default Secure Boot Keys when System is in Setup Mode Platform Key (PK) Set new PK Delete PK NOT INSTALLED Key Exchange Key Database (KEK) Set new KEK Delete KEK Append Var to KEK NOT INSTALLED Authorized Signature Database (DB) Set new DB Delete DB Append Var to DB NOT INSTALLED Forbidden Signature Database (DBX) Set new DBX Delete DBX Append Var to DBX NOT INSTALLED Factory Default Key Provisioning [Disabled] Configuration options: [Disabled] [Enabled] Install All Factory Default Keys This item will ask you if you want to Install Factory Default secure variables. Select Yes if you want to load the default secure variables, otherwise select No. Platform Key (PK)/Key Exchange Key Database (KEK)/Authorized Signature Database (DB)/ Forbidden Signature Database (DBX) Configuration options: [Set New] [Delete] [Append] 4-38 Chapter 4: BIOS setup

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152

4-38
Chapter 4: BIOS setup
Internal FV [Always Execute]
Configuration options: [Always Execute]
Option ROM/Removable Media/Fixed Media [Deny Execute]
Configuration options: [Always Execute] [Always Deny] [Allow Execute] [Defer Execute]
[Deny Execute] [Query User]
Key Management
This item only appears when you set the Secure Boot Mode to [Custom]. This allows you to
modify Secure Boot variables and set Key Management page.
Aptio Setup Utility - Copyright (C) 2013 American Megatrends, Inc.
Security
Image Execution Policy
per device path on
Security Violation.
Interval FV
[Always Execute]
Option ROM
[Deny Execute]
Removable Media
[Deny Execute]
Fixed Media
[Deny Execute]
Image Execution Policy
This item only appears when you set the Secure Boot Mode to [Custom]. This allows you to
manage the Image Policy on Security Violation.
Install Factory default
Secure Boot Keys when
System is in Setup Mode
Aptio Setup Utility - Copyright (C) 2013 American Megatrends, Inc.
Security
Factory Default Key Provisioning
[Disabled]
Install All Factory Default Keys
Platform Key (PK)
NOT INSTALLED
Set new PK
Delete PK
Key Exchange Key Database (KEK)
NOT INSTALLED
Set new KEK
Delete KEK
Append Var to KEK
Authorized Signature Database (DB)
NOT INSTALLED
Set new DB
Delete DB
Append Var to DB
Forbidden Signature Database (DBX)
NOT INSTALLED
Set new DBX
Delete DBX
Append Var to DBX
Factory Default Key Provisioning [Disabled]
Configuration options: [Disabled] [Enabled]
Install All Factory Default Keys
This item will ask you if you want to Install Factory Default secure variables. Select Yes
if you want to load the default secure variables, otherwise select No.
Platform Key (PK)/Key Exchange Key Database (KEK)/Authorized Signature Database
(DB)/ Forbidden Signature Database (DBX)
Configuration options: [Set New] [Delete] [Append]