Asus VANGUARD B85 VANGUARD B85 User's Manual - Page 78

Secure Boot, Key Management

Page 78 highlights

Boot Devices Control [UEFI and L...] Allows you to select the type of devices that you want to boot up. Configuration options: [UEFI and Legacy OPROM] [Legacy OPROM only] [UEFI only] Boot from Network Devices [Legacy OPR...] Allows you to select the type of network devices that you want to launch. Configuration options: [Legacy OPROM first] [UEFI driver first] [Ignore] Boot from Storage Devices [Legacy OPR...] Allows you to select the type of storage devices that you want to launch. Configuration options: [Both, Legacy OPROM first] [Both, UEFI first] [Legacy OPROM first] [UEFI driver first] [Ignore] Boot from PCI-E/PCI Expansion Devices [Legacy OPR...] Allows you to select the type of PCI-E/PCI expansion devices that you want to launch. Configuration options: [Legacy OPROM first] [UEFI driver first] 2.8.10 Secure Boot Allows you to configure the Windows® Secure Boot settings and manage its keys to protect the system from unauthorized access and malwares during POST. OS Type [Windows UE...] Allows you to select your installed operating system. [Windows UEFI mode] Executes the Microsoft® Secure Boot check. Only select this option when booting on Windows® UEFI mode or other Microsoft® Secure Boot compliant OS. [Other OS] Get the optimized function when booting on Windows® non-UEFI mode, Windows® Vista/XP, or other Microsoft® Secure Boot non-compliant OS. Only on Windows® UEFI mode that Microsoft® Secure Boot can function properly. The following item appears when OS Type is set to [Windows UEFI mode]. Key Management This item appears only when you set OS Type to [Windows UEFI mode]. It allows you to manage the Secure Boot keys. Install Default Secure Boot keys Allows you to immediately load the default Security Boot keys, Platform key (PK), Key-exchange Key (KEK), Signature database (db), and Revoked Signatures (dbx). When the default Secure boot keys are loaded, the PK state will change from Unloaded mode to loaded mode. Clear Secure Boot keys This item appears only when you load the default Secure Boot keys. This item allows you to clear all default Secure Boot keys. Save Secure Boot Keys Allows you to save the PK (Platform Keys) to a USB storage device. 2-40 Chapter 2: Getting started

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86

2-40
Chapter 2: Getting started
Boot Devices Control [UEFI and L...]
Allows you to select the type of devices that you want to boot up. Configuration options:
[UEFI and Legacy OPROM] [Legacy OPROM only] [UEFI only]
Boot from Network Devices [Legacy OPR...]
Allows you to select the type of network devices that you want to launch. Configuration
options: [Legacy OPROM first] [UEFI driver first] [Ignore]
Boot from Storage Devices [Legacy OPR...]
Allows you to select the type of storage devices that you want to launch. Configuration
options: [Both, Legacy OPROM first] [Both, UEFI first] [Legacy OPROM first] [UEFI driver
first] [Ignore]
Boot from PCI-E/PCI Expansion Devices [Legacy OPR...]
Allows you to select the type of PCI-E/PCI expansion devices that you want to launch.
Configuration options: [Legacy OPROM first] [UEFI driver first]
2.8.10
Secure Boot
Allows you to configure the Windows
®
Secure Boot settings and manage its keys to protect
the system from unauthorized access and malwares during POST.
OS Type [Windows UE...]
Allows you to select your installed operating system.
[Windows UEFI mode]
Executes the Microsoft
®
Secure Boot check. Only select this
option when booting on Windows
®
UEFI mode or other Microsoft
®
Secure Boot compliant OS.
[Other OS]
Get the optimized function when booting on Windows
®
non-UEFI
mode, Windows
®
Vista/XP, or other Microsoft
®
Secure Boot
non-compliant OS. Only on Windows
®
UEFI mode that Microsoft
®
Secure Boot can function properly.
The following item appears when
OS Type
is set to [
Windows UEFI mode
].
Key Management
This item appears only when you set OS Type to [Windows UEFI mode]. It allows you
to manage the Secure Boot keys.
Install Default Secure Boot keys
Allows you to immediately load the default Security Boot keys, Platform key
(PK), Key-exchange Key (KEK), Signature database (db), and Revoked
Signatures (dbx). When the default Secure boot keys are loaded, the PK
state will change from Unloaded mode to loaded mode.
Clear Secure Boot keys
This item appears only when you load the default Secure Boot keys. This
item allows you to clear all default Secure Boot keys.
Save Secure Boot Keys
Allows you to save the PK (Platform Keys) to a USB storage device.