Dell Latitude 3190 Owners Manual - Page 57

Secure Boot screen options, Intel Software Guard Extensions screen options

Page 57 highlights

Option Description • Activate-enabled by default NOTE: The Activate and Disable options will permanently activate or disable the feature and no further changes will be allowed. CPU XD Support Allows you to enable the Execute Disable mode of the processor. Enable CPU XD Support-enabled by default Admin Setup Lockout Allows you to prevent users from entering Setup when an Administrator password is set. Default Setting: This option is disabled Master password lockout SIMM Security Mitigation This option is not enabled by default This option enables or disables additional UEFI SMM Mitigation protections. The option is disabled by default. Secure Boot screen options Option Secure Boot Enable Expert Key Management Description This option enables or disables the Secure Boot feature. • Disabled • Enabled (Default) Allows you to manipulate the security key databases only if the system is in Custom Mode. The Enable Custom Mode option is disabled by default. The options are: • PK-enabled by default • KEK • db • dbx If you enable the Custom Mode, the relevant options for PK, KEK, db, and dbx appear. The options are: • Save to File-Saves the key to a user-selected file • Replace from File-Replaces the current key with a key from a user-selected file • Append from File-Adds a key to the current database from a user-selected file • Delete-Deletes the selected key • Reset All Keys-Resets to default setting • Delete All Keys-Deletes all the keys NOTE: If you disable the Custom Mode, all the changes made are erased and the keys restore to default settings. Intel Software Guard Extensions screen options Option Intel SGX Enable Enclave Memory Size Description This field specifies you to provide a secured environment for running code/storing sensitive information in the context of the main OS. The options are: • Disabled • Enabled • Software Controlled (default) This option sets SGX Enclave Reserve Memory Size. The options are: • 32 MB System setup options 57

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65

Option
Description
Activate—enabled by default
NOTE:
The Activate and Disable options will permanently activate or disable the feature and no
further changes will be allowed.
CPU XD Support
Allows you to enable the Execute Disable mode of the processor.
Enable CPU XD Support
—enabled by default
Admin Setup
Lockout
Allows you to prevent users from entering Setup when an Administrator password is set.
Default Setting: This option is disabled
Master password
lockout
This option is not enabled by default
SIMM Security
Mitigation
This option enables or disables additional UEFI SMM Mitigation protections. The option is disabled by default.
Secure Boot screen options
Option
Description
Secure Boot
Enable
This option enables or disables the
Secure Boot
feature.
Disabled
Enabled
(Default)
Expert Key
Management
Allows you to manipulate the security key databases only if the system is in Custom Mode. The
Enable Custom
Mode
option is disabled by default. The options are:
PK—enabled by default
KEK
db
dbx
If you enable the
Custom Mode
, the relevant options for
PK, KEK, db, and dbx
appear. The options are:
Save to File
—Saves the key to a user-selected file
Replace from File
—Replaces the current key with a key from a user-selected file
Append from File
—Adds a key to the current database from a user-selected file
Delete
—Deletes the selected key
Reset All Keys
—Resets to default setting
Delete All Keys
—Deletes all the keys
NOTE:
If you disable the Custom Mode, all the changes made are erased and the keys restore to
default settings.
Intel Software Guard Extensions screen options
Option
Description
Intel SGX Enable
This field specifies you to provide a secured environment for running code/storing sensitive information in the
context of the main OS. The options are:
Disabled
Enabled
Software Controlled
(default)
Enclave Memory
Size
This option sets
SGX Enclave Reserve Memory Size
. The options are:
32 MB
System setup options
57