# Enable UEFI secure boot

UEFI secure boot enhances the security and reliability of the system by ensuring that only the verified and trusted software loads during startup.

## Configure an UEFI secure boot to generate keys and certificates

You can setup an initial UEFI secure boot configuration and convert the keys and certificates into a format that UEFI can understand. See the workflow to understand the off-target preparation and the on-device execution.

![../../../../../_images/uefi-secure-boot-prep-updated.png](data:image/png;base64,UklGRi4jAABXRUJQVlA4TCIjAAAvvIN0EPfjIJIkReqFuwcB71/N22GY2e3peRLhMJJkVdl7/+MQAvknQUjunOye40aSFKl295jZf5vOgfszDM90VzNoJElR5QydfytnAZ8ZEgAAf7aZ2YiUGiELyRQMGJ20oo4OhqIDeiy6EI1EmCr+B0Ej8RP5AwgACoAOYE7gKcAE6ya0ZQCjZAeA4R9AL9adAH4Afx1dKr2M1QbrGto00jZesc7l8SPR8xuxRFCxBD8rXRfojv+F2BkuRBihIoGpmMBS002QphvR+F9lg/+UhWPhWHjmzuE4s19v1M3L5pC1dVasY/9MohHVzCao7NPDFL1+iUQskW1qL1l+sETWxJT3/EYzm/vbY4nbywmq28uR6Hi6ySb7Ghid4koiieZngeNFopkNS5TaMt6xhER2PpGK4rZtI2n/sZO2Sa93REwAHoytNJEnFOzMuIhx0X8zL5WCoiCsDPGaHFXJUbXMSz6DCEguc2YOXEZJRHBpGHw0BzCp5CrbgYm1SKNJK/ilHIJKFasinSUOFPDEsLrTZWmhi7O9vbblSLJrW6ucDBLOrbXWWjl8SwrfyhEIOPh1a61F7UTC4VvL2j/ebczp7pG5WLUrPixL29PSrKYlbUb0XxYkyUHdjCqKUYy9e5yEQDyq8ktd2/a0jXTBn3QhZ9J2mMqU9pplHmYuDvPJJ9In2VHl77NnKtvrRB7LliP6T4ltJEmSRN9JbGUdiHCPPssru/L70Vp++Lt/8uZavvMHfuIjKD/+XfpNX/PZT91Uy2fKN37HT/8I/PmZb831Bls+/VX94ZXvSk/1Nlu++lP/L8/6mXqrLel75bu/qd5s+Zz+hH7N7ZaqP6qfveGSflDrDZdv+cR/vgZy5izdQgopV1Uo3t+7dZVs8Sd/+z9fe5gLt+5RblX97tcepihHnnDxzfkPj/LyHulW1df+fn45SHov9aSLr/2zfw44rP4/2sUf/ttB3mSeeGFPwYxKTzxf+MODfPtGPfEPg46KfKvqE/8x/jP+M/4z/jMr+vk/epXSU3b8XkqPfHnT2uIozv7ZxHnMevfE2nQs7fPEMxnFxH1VFDbFrHz3ypW7XOvzK0dmIdZ+DkM1cXPIXlmbY1dhmSiOnMI+Q68/Tff/8qnP37mOL+k1jAFPtX78eMfdCMl13KeUwjWptT4O3nU38v0rgcRJ+e/grJBc+ReabHT+fv/GadOn9Abm9N6J/bxPyYcKMwYy/vjXKb1xAp40BZgkPjm9flX4svJ5Ten1B6qL+El4MgKzz6uJuvT9uRSptWM0knT/qeoO5lN9SS9/ndizwofX6e7JkZ8gJSR5mPkFSVpr+GvMkyr3qeLpg1H4ISUn8y5jejmeMD8h9e5evXmBDHYGIHXvniGTP+9OPDuPCWp8uQ0pfdiPBynP2LvfMFO/cA/T/A1QIQoIz6DiBfWm9ESU1kB0ET8sz/TKwbJDLbFI0wumhTKpwZ0yMHlIcoXPp5TrU9K6Qq/kQn1KkHIORqGzke9XMTS96l+jun28prmamEjR6A12eDjScHyr4jUZo2bNo5fq0187/qXW+zU/wt3KU7oLec0N2CC8zk7hyl1wmaJOdHjz6v5lVXkP54f1nwR0MX5w3ALcRcP5/sCYAeTWjrFozRIye8bUuGP+EhjCV57dYf/r9FJfp+fqkzhQlU9POYGQOwenMKSk6TWXXi8uT56SZ8BmB2Ten6Z7qJjvLnELzgzKNNNDf1fdYf88aMNUlPSnPC/VJYgTwCl8w+pFW6CL8cPxedCW2fv+GbfuUOoF8oMklodMAT2+1g+rgCcYIzLg09MqRp5dKtWKl+qcQpgHfODSC2b6QWQXf+205pReVvLBSHMs+peUXsjGfp7dPB4BnRW5T1B0AxCGfD5hEbwRA8bc/I9A/PCgp8JW6KSvPNnYRpMgniRJ/Xy6f157v4OZ+wkR9WGFUQiJdc+mF2ZtrRvwBlbhDAi9yd4N16dXdlWEAxWF0SspcRA/m1UQbfB5Ew4obMUMBffJJR6tgDc8LwRU8KYGjte7cfY2K4Q+0C7uk2DKvRDY5pekudbsMs/vaH4hSeqEMc3qBN4ROD84S3c5eU+aAfh8IIbt5jdw6zlXnIS/AKjKpye865FBKqPQjfWrYi69oHn9VhDycg/cEwO0mQGdzSFhH34VtFVV5rQdcPMZ0iywJ4MPhGc09Pk3VOnuKqeUXjZ2QyY+Vxh27/YE2eIrQFPy82Q3dV9wCjX96SpMmPQiE3kh6bfy7Pbjd3sHpWbBxzL38S93cDZI/indO0gG/vVrpy28YCIGZVBN6ZnJyg+a0t0bp/cF8rG+rJI9nRFQPyDghV1fzj0+1WeFxzJ3UD/v052QkwEe8noPKbK1vvxmzQeFdUtG4ZoswU3mAkkvbn05r2pFXdK8UPILSHsLEAHxBk7Wzztn/i87hb66ew/xgQi0eyLL+zcRNPbip2tz4/0c8Sf+Y/xn/Gf8Z/xn/Hd8uc4M8qM7dORZVapb+An9saS255fRv6o2Okq79BMBolDZQUuA2FBaTQFtV2G9lgIxp7KfSMAprCWBxvjP+M/4z/jva2dfXhrVebq+2tOvXYOh0d9wxP7ajq6JzFdg1ItZ7lRDP78j4FvVbtxxcLaP6Hw4NT6xP6TF4yaZKKTF/sGZ5W1J7uNkoWvzdXuqY7gCyX31IAyPh9J4RzVbZDLr99n3ennb4jWZLXrepLqDOAyjcBaPzHsSIkBWylGKfVQYxO0bmoftqQcSID/UCP64wNKh83cDZHH7td32QbwKV84O/GKzx3sz89JIgnNCUBnNrPaqAxzjoDnPqn0xr6pasnqzqVOtBXRVVQ9waqKqCsOoMzV2BoltT5JzlTljvoBr58ir197AKJ1XpqA6gM5VTbeSq+rAABLh1KXVaAbjVUtWdd76mbjznA9xipgAW3Exm95uZAWSDzgdOpt5DVUvmE9cBcH62sYxXkjuFTMrBKXkisfPLgWWLxoi6Shmp+GCYxqsDO7wEytzNiOquTlwQ+9VfaBZu6i2iVwj1io0BSNOZn+ub0bS3mUYNM862OWkK302izFblYwbjhyqWZVppS3mcQbIqbGBrYrMjDH43qIekWrVJXKRy6q0EmZDozM5ISf1VrGXJyvinarJvAIoYph0YOr2oQsFp5XAADY958M3hQtwlmi5b99yVRcmcqyq62rFrEY8OMU+VEGovmbMMUbRUbI5QeeqgEvJF48HLV+TyKWjAFd+sOAexi2npI+YD1OMnGpgw34sDA16xoB4TSQKIkZTMDrJgjMA30x4Luhac515JbkDmOCajMNLdkIX1JXVOxg1G0xtt2nMS+amhUWcKIgCIZCQZAUwBDES7bHaGfLhhFQ9g1c4dXLIDZzYUh8IDTCG9TLktxu5a5YRE8QshGAmniKuYN85mGOMuTephzlcmZYqpSt4wPJ1cOkI38Tx5QcKTghmIKXrQWRiVMNW6fQlRBKZGEgeRzGaghHIN6o9ZoSV00qGY4ZxT3opzMBZWMgF7BzoARwcjJoNYszGGIO0i9U4UnMmKgigOLab4/XsGCDNnDQK41CQOklVK++DwAQ4Sze9DX/QOMDM9qxy0apTUaEAawWor4M7xl4DdtKkk7WHcCmh4nGA5evg0pHfiMo/KDi8m0iXAQ0xqiVsZKHX6awVYFIw6hQzOuqqqipHVhiYKbVTVZ5+dgyyAaOGR1XPxhmzrg+aGDC1glOnDOSyKRbC4FSx6AaQG8DMgtnwQWACDOaH/DZcX/buiIj3rQWfxFiKVoZShgZKdJqLrsOl5Isni0tHnqj8XMG3GDLKizOjWp4Kpl2pBCbJo+4mPeVMTrts5dkDVHR+wErOfcicMfM6nPJmFeq0UUEJlWid2/FIRXUCqQtAtBr1wVfemFJjyG8xmIuRLpjVWtWWWipLGnTD9MHY+SAoJVS8sDaC8gMFf1yVROHdfCOEDIcoZwaSMwXxGlb2NTMcabZJCmfMsshsFO56fovKu5HFNtjbzKcugAyZvQTng4MJ8ED8vtU4awJOZl7kbHIK3vY0w5hjTA7JxcyS9IOolHzxJGw1C/DlBwp+vFnanmYmyaOus6sLMCIsZl6TTf3McXZquhap6m3qHG2H5FDd8Zk2YNRsAKYYY2ZRE0VGcp/Tyd3YaGs2ryOAZwMOcjuW2y273USps7ADG6S4CHI+kp6NDfDiYpbfdruNZl692QSTWdFAmJ6FKghjj3Fti43iQe5ZVEq+eFJCx6WjAF9+oOCYBlELs5sTwKue9lK2d2vEaJJHXk+1l0Z7TxUsxh7tGlW74EBVrXdHqW6uL2/AqNnEqhRiDDwYZYYVQvTo20ghBtrEmZmLZApZ82SSIjZaV0WpY2Yum5hXbT3rw6pGGmDyCy5vw8cyA+RZgPE7GID5xFcQxh/jBdeSYW9RKfniSam715eh8kMFrwfXl9nkSNheXy5CUxCnL4joZobh9vpppnMjN1ykScZVCe/riI3/jP+M/4z/vtQ3VlmPAuopha3Q4IR/VJbVBPBcZd2aBJdV5rM13ftlrP0z7SpeZb67Umvez7/qXu85cs4e9Iqj7dmDvnis/1N/Nf4z/jP+M/4znsvz/Hbev90pogoh/M4/hJA7qno8wcQOVf1FgrJ3mqrOsT56oipPwBW67h4PNHTd7dhv5+jKZX05YW+y0/eWsne7Yu3YE9ZbaxvaPtBOdoq0D9TYc8jRmdF8fLjuNB/doYu6VXXxgdN8zKlu4Sf0x1JHac9r9K+qsjNs1PnXtoXKDloCxIbSahq84QKF9VoKRJbwvgsd4z/jv7jDr7WNdqNZ1csuhnANfuPULGag/HHh99p4oOD08zVtll7Dl8VbVr/f5vtDfJPMFj2v1H2c8nEm9xVSP7ZIDi5ekzaaZRkOIXkjOu/zEOjxobMHLGd2rPi48Nhtrt/ryhHM7H0huQGSx8l2Eu29Fpt7rxons0HMROdGYVQZGq2LEIpqm0CL6sUxgmCnbfKq7ej8BNVhQ7EXlUQUFWp+Vu0vMPsIKqOh/4VSnUTW6UV9VPWWYahbJB8JzqW6KLgNKmhDYnF+t2yOqqo+q0eCE55JaEZaGXNgRFVniGaVxnGbrp2gawJJvYXeoYvlviM0yS7iXf8crYpwgr0mMktncMpb6ZwuAx+jDqxi31Ror+rtIpFOprN1kldqtlnMRvBPqGBlZpyu9MGGJrnvNWvnI8HJEi33wUEFcRLRSJS8ZTO7OAFkXMoxYmhmLRR6YLDCSBaHMZzcNctI6XozgypA50CgN/SVTGRnYSfpMWzjlA/NZJa0wD9ZjFQx9RCqaZPNkicWEqr3Tm9VIf4JsYKIQJ2uVBAPgkXH/cEhIbkMeWXbe4+ybVJPbO7DYwQFxSgDPTAEGdjUxHEPNA5NmwCS/Fzfz2QDu/65qRxeM3aUnWTj5MycYuyntpysarSNcnEQvYx/2om3nCKL4OgjdiQ4WTroyCtUECeR9PJ2Nhn20wXDcaVvIYoUJr4OYslVNqZ7ftk33pH1IJVnEDJOHIJciLOKq0IRs9pp8EYEd6rKknUDb1tOV2iPlRyWLTzMpqg6ZKDuQDEIc9YD9ArFQwTnspsKkssqjdngXHYtXftIq7mt25WwQ9WpQ+8aD1UmR6qLDk21/cEh0ejbvLsi4o5V1ZgyVT2/b6ykScAJ6PpD7G4+BF7VzqziDAJytp7qA6PTFrua075ms/4UzHYHhw0A27xjclDMurgbspRcUGLWYQdfoZtnMo+R7Jm56HiVGWI5iHB+BA03W8ay+CNULTvjsCH5OubLIo20u43MBrmhfACVukrb2u0gsc3mlVUMSqc4wy/I+MgGuu1YiP+ju4Fbr4vZkeBcnKxZXEUF8RK7dg21eGJz9244LuAvGPeQ9GygyGnzbux8SBVeyyEEDTfbDMeoTv8BhmtSRV1bZvAwxJKF1gOYNtpVMTNutfcgU6c6L5JZxV5UC/kFMRProq3XgYGsc/Pry8PG+vISVT0m4NnsUHDGqNoVdn25chLRiHgjNvcBkYsj/oI22R6scuvLmFEMW8auVHZzTdHR+4KIK0w7rWvtUHmMig+mtQ9Xt1iDPeKiZ3xnDn1cx+E7HAEFvzXp3JA78Q/SJBjL8fEYHJ4HXPLUAQC6b6CGG4LHMT+r33A5KZy7zpD6VYtXVS1sHLjggIdL1JNXzzxTtM88Mzt+qnAOMybU3MhleoB0zffFSrvYbrqaLR28HXRY8eMjB7/f4gHv7xoAnTn0cZ2VUMxX60JwRdMb8yANffCHVKLDqlqdjbAqAYDuG/a7KA687HJsueyr2aLFrEY3AYVqQxkNDjDBI0hAzRZlh3lYn21oBC4EmVBzI5fqAdLz5vi0M+MM/QjHFStn1mW/xSPecQCX5gaAzhy+XafPMh/gm/RmlpjndrgHfxBUsZzI/dMTAHTfiCVQ3CecpT+ZtSGYiQdI5SF5wEt2qjzzTJF48rBqliFLAxdqbuRSPUAkfx2xzndv9vlqBIyhLXXYRVC/tZxnMwXuEia9eM0MQPeNWIUbFvCH8zxwbqRo1amoAAQjo8EBut4IJDjw5CWReyzUPTdyqR6g2BTQmcO16wQCanJDIA/+ELJiKQMHN7KqkjVZSjDxPljwSUwWCQ7SbwNNPiAu1COGTA9QfArozOHbdULczG3lK49OtipufuFtrKtVbaml7oYGZ28FTT4gF2q+kuoBik+lkzkDaNcR8E3Y33xajIHOggt/mcsMmBmM7G4pXuRscmr9bpjgOLzkLeDJB8I8jMSNXKoHCEN8A6WnAmaLmg+xeX1oQ/tOCNCZA7TrCBS4p71jt1YL8+APPh4jcHM64A3mAXcDum8gWQZ629pKmeChHtFAmJ4VocFBD7Abi3jy0phQcyOX6gHCkbIl4Ap4LeyN1UHyu2Az0JnDt+sIP4xTo8FDtbDry14v7IM/la4vd4Es7eLADnTfCDDry1KsdYJjMIKvKgd/T8AEJ6vH1eGBRTx5aUyouZFL9QCh1ZaAdwWORLiNr1DlrOkxKkcef0qiAa7TyBM3slQd8RmifjYUMAi3IE7fF0Rr51Oy3MVHoRybtDOrEixIxCs8kcJszMwG894b5nU4xN6kqDrnx6Aca6BkIkB4Mq6HeA24TCKL7UQU5AT6OpyIhr/A5yazr8H1jmEf3KfvmU8XJYTo/cigqkcYQXFWz5Aobrz6W201qbfYGuVo842RzqxKtqE529gypOaMJBVutyKL3eRQVdV+H56sLy+qndeRvr6lw/Vlsyp6fjnmpt3wD9n5j/dlZp/4j/Hflyqeq6xHAfWUwlZocMI/KstqCnxJUFm3JsFllflsrda83xrdy5xXme+u1Jr386+61ztAztmDXnGetGcP+iICzvzV+M/4z/jP+M94LoTw56F/u1PJrL99BWWHqpvGsnGaqn4RyamqZd2g6+4/cDR03e0G9k7RVXly0zm6clnf35S923+nVFL2bqm1T2n7QPLkKMsXNkeOuUsLeo///a1G85Fh54Ee+shHnb/7vNFRWraG/UW1fUltzU8EiHLI6PMn25eURoFVZW1XYWs0eDsNye4bWRknvG8hyfjvky2ZT8DQXHZp6q9EnK/ArxFbQ/vIiHIQuVZAYs/zG6LLLoYQW4vXRL788UXilZjcV/uQMqZmdiVI+YrHWcf3tRulU63ZLEfVfnR41RiArAM5uYuusjojMgPZGFYNi9hFfVX1jkW1v+D8Ny5MZSbLqmzOEUWbV5XkjFXVoZ+pYKIoZfApAVLBTbTKRkyc66jqqQtHjuDCq6oWzpPRgADOQ8D4c/raZM5I0HztiMV1gkQLbW8WY7ZZi0VdLPfdNk2yi3jLMlvuA7LIaFUcoZjXs1kXptVUtlG9hZ5HyipGvIUWBF9W09VZmszrzAkexDnwDiYkXCgGMCohTquLxLjAGHaSoWI8ObiAzDpY7qMRNZXoSys7mEjZhp+xmI7X4ARk6INZV1roLdssTkCH3esyZEDUeXAkp9Hb2QmY1FvXbzQTidFZWuAsCp7INPk0c4J7EJwcTEhoKKhRMRAfuk0XVSvAeHIwAUEvo1YGInuUs2kMP2OxmoaUC/d/bu3bETX1jiZvbhABWXCKu+J6GaWCRuzm1kaTYSesJZDimwxwgoft7ucdRO9ZawCLcC6gXAiMJ2KW0oN2zwCyQSUzkfAzFtft9kFVNcMVZyzHsWludMjAuANtoMSsBwHx6nQSGMEQhg5PuCQkLON+UNbAUDtVJVBPQNZNBo5BUIJjhJ+x2O6CN3L+stDp+TDQr2Kbd1dCjMlRQjdtnjfFuLKoxz/qH6q6aOQqxtO1q/AzFtOJrQEj6fgbmCxboKCqlTRvgqfkYmvzMYomW+GuWBnBWdnBaQ62BWOUy4n8bq8TBxOMKzYzQs9YXGdozjYGOJdl8zpuMQcnhqU0i5PtKnLTuWGxLhQbxePN5HY/WTqD28zWww3qmRMcQ7ECIo2EhIUxCuaE2a0yLtB152g7Yzw5uIBEXXbvxgo/Y6iR1ZU+bTzEgES2qHZeR9fLtE22Ra6qc2SxMa46L+z6cmUBF+LJMu6BDRDvQ2RWhFnBRZXswoSECQWzoC3IyUUXfn05wgy9CV4HNxrohfNkNCDc+jILXV9mhZ8x5MDDk67ERf279AciuvDwymV5UNnYxx+sPKaIYYiF7v8YdDVbatKDplMYzBaZPr48hoihSi/MY3Dg91teVP0KzKXmbFFV5d2YDPPbB+7wHUz+P7bVo4gYsjbMY3BAXx3z250qi9lZBwsxvlNUmA4c7RbmMTjgOQb2Nxm+mXD54aLpFokr7WjMY3DAs/vrWslYgSsbstwkK1xRoY/BAeZXm4KjR1bviPONksw/ZEeJzWO/zTWEI4pItRv+Yh6Do+FumQ/iYYYn+YgiWikLuIFPF263C9kNlWwR0mFFhMJ12XJtcIfWl5nxFfQAHbmGfvTCwweZuVf3hKpaM/emH4FbKoMQxZ55Hw8wImCpAQcNOsKw+YIIegCOXMMAFffqnhw6y+ybfnBSDqg4tZ6+jwcYEdRSwB80KLECHLlmBwnud+LaY9IzfdMPR4bvmFuUNj9ZAoBfr/AHDUq6/lKD7ICq6ILBXRL68SGOceNyPAUBT2wAr8FKrHBHrjlA37iyl8K/jwcEtBQkYPLZrYAbcqG8hzOtvPrEbgMcuaY0aRdkubgwbDcvLXkfj9zu5At05JpQzSoKYMmhg9GAIzVnultxuzHv4+FHBLUUJF8XoCPXXIKqP5GX41BwfTmO/PtuOnZ9ufXs+3jaWdHzy+RE9xdEGP8Z/5nTbVDAtldYjwTmVJbVBHCgMkeDU+1Sme+ulJqP39NS81FlXmX+YBv9qs7QRVxccR45Zw+azeg9Xt91mo/+/xEXds4e9LH2zx7U+M/4z/jP+O9YfCGEPw/9251KZn31FZQdqm7uNM3TvaZpTlPVLyJvqep/y0RD191/AFlF190N4xxd/cLTymm6agfGlL3bf6d0g7J3K63NHGkfSJ4cZbnM/u1xozuj+fiv33aajznkPNDfOx43ln5Cf6x11PY829B8/FFqPoqu2hZ+IkBkKuv0KPAn25V2+ScKRFdhRUsAdSfWeCMrBPqS8DzhfQtJxn/Gfwr5tQZKv4eLjsiX1W9xmlGXt6JYMhEg5rU+ILG/DkOjv/GIcVXKJz0mdYH+83D4rc72iJGZkB74q1GhAq/ldoPXfItg7r1qnHAGLwn6T1T1hNCp1nxVihMKNgRsWEAhI/3P3PrGa2+2qMYLZXBamf+yLRVb8KKiOHpVlVXhogMRxUTIyZhtw3UVmCOMllrVBa8uUiAVaeVFQ60BxFjptZhngEmHwIRkEEBQIqo6v39EF8t9Z1bkYkMzroTJvCYgt53lGK9Jlmi5DyAE2rN0ZjXwOPldmCxKJtYHNHd2I0KMBnatnia2UldF9ZyolT6vemS0qn7DdXIm5wB6ikSogFSwM++kn1bRhQSGBSXdKhEASqss7xsrKNl1LbNBzGSBTr2SzKyPgNfJLOl5B1BGKqBQcGwoQwYb1nZgyXmhoJWzMxfUIy0R3PWo0TwMJ2HZQTDjRF3QChiMe1yLotjkESAV6WA0I3XuJTMbUNLPWiEiIN9csN5Xbjjohaw4RqdEgK416NxXrbpgRkYFW05GpwssGTohdHXGOriUwbBvdxEHkx30ZowoyrDSR9Y1Gh6bs1UF2Q4oFRwquuuNgU86aoPw4OhRNL3nJMyqqgxNdvTqylUB+UO2Steu+nkfA8raYMhoIs5E7CD7YERtseHanbAXmEd0GjzCp0KsJ/hBHoCkD4LBKlULRMW/5yR0066qGhSWs6ZjwO2uNosKiuj2VuSu82OqNlybhSUoiYh0WPGpwMrmxKVStToUeNIZjqT5LqsjdaxXacQrmmxls3mA69qCdC0qng4xkA6ZZVjJGZtDk4omlopd0a7f3LPNu1DG0yBNcXJQDINPhci7Q7M0LTnAV6GPOyjSZSsx5iuSHwUk71YjX4YTozpC4XfLjMazLgY3fA9RnLYoGZRP/WxZIg43cG+aYjVcbBRPb7Qzu6GAHOAsPTm1m3CiRESzdtGDaCQ0sogZDcUWO3ZzUndzxSHz+8JoIyRzWnkgAkiZZLgiZvZYiPC2TG5jjKq+jbvWl+PIrt623ox7LFMCyO8KWZZdDJXPwezSqnqh2KIq/vj6Mlwglw04UaILwlkbmvKCRkKrnoZiC1xfTsN4frltZ6v9SDNLdKSmOC6Yb0UH0FLxgYDK5CxzGAF6F9KsO7ljN7s8ojgRg2PsVRcyvEw65GYmJrwZ64sTcZG40oaJU3UhOSeoeYyqVeUGGygPo8JOV1WqZ1iI82M9xUSbQXAq5lcm6VxHTVZbctXSx8mKntmqnEa7tHHrlO61FJVkU9sRqhQbZSWptwIrhBPoW6Ezv2XDFyMCpA6NcEJECzxbwMBsAHkYmC0HwyWcrto7Fx3M3op6xyzQdwNeo5wWMqMLMwdO9qomYGCohZx2+XtYw0rocVCBFc+utRVGVd7wxYnogujCCumCwU2TPYB5GFVbTFrIxmuX373ooUcOkh0y09O4DPBPHYwBNVCYc7zMexgcTTaiHTmrJ9P6rrdJPeCJ3LzhixORRQIrhLrcVYF5GFXlwHyc/jpi6W3En7eSdUDOtrRW3DZZnOcYcFSQbnuDwWn1A4Us76u3pFPS4KDiOV/bIhb1rBDmrtgeoDzE9ayd3cl9q6p6Pnl6zjXbVW1/y6EKSz75Wo2vGF/bIqa1yqwQicgtorJBYjRgDqTZLESdaN8Ptqt58wdxbDWTDl+cpl6Ssc1ew4YvTkTfltPMCKHzeVks1APNsb0JVp743aC/RzPLMV6sxBmpLbfb9sMhm1gNZDevA7kmryrZjN9twxcnwmsyr4kRwu02yCqkbUYzGQnvFtuzWfIKu75szO3ivKiqZ0YIHcj68o7HMjm215cTs/jfzkYwryp+wxcn4iIVvmEiqpj1ZXTTe4evKg8/vwxJeI9aeSyNjaepvWo7rtSoOsDVXQdXVgN5+PlmSeNtavHtWvhhpstJ6UeKzrdO6EepJrOkF7rwsQKrj/4mCjc0yLKS9FK0OobbKlmh3Gox8ajmRkuM8BWHb6bbKeSB2ZajNN6meCOFvPkqcFhqtPVab7xPdn3iP8Z/xyvaIMFJw3iFbZPAgcrmKHDWMKXKGgrY9irz3ZUe8tfUmptSma8I8O3c3NCRJ9Tmswb58bzj4w30WVXGf8Z/xn/Gf8Z/xjb/9rvUY08B3aCeC0F981+ltPO1f/bPAYd17wzxXH0TUP2f8izl+Hx4Pv6yJt2q+iEr66Dqt3u3rpIt8t/K134q8H+UW1V+nP0wFZj3ZwkX9SolH9Etau9l3FCLMdinb7t89obLt/3QT3/udsunf/JHv+//b7d8w09/9KJfc7P9+zt+QOT7nz5zo/3zrd/5Ex+JfPe3f90tls9+28/82EeuvPzkd3zTN9xYyzcm/Z6fECw/Hr77Z2+t5fuhVQA=)

**Figure : UEFI secure boot workflow**

Note

Secure communications and cryptography are facilitated by the OpenSSL toolkit, while keys and signatures for UEFI secure boot are managed by efitool.

## Install OpenSSL and efitools

1. Install [OpenSSL 0.9.80 June 2010 (or later version)](https://openssl-library.org/source/) on the Linux host computer.
2. Install the [efitools](https://pkgs.org/download/efitools) using the following:

> 
> 
> - cert-to-efi-sig-list: converts OpenSSL certificates to EFI signature lists
>     - sign-efi-sig-list: signs the EFI signature list
>     - hash-efi-sig-list: creates a hash signature list entry from a binary

## Generate key and certificate

To enable UEFI secure boot, generate a pair of keys and certificates for signing and authentication.

The key generation supports the following algorithms:

- RSA 2048/4096 with SHA-256/SHA384 hash algorithm
- ECDSA secp256r1/secp384r1

The following procedures provide instructions to generate keys and certificates with RSA 2048 and SHA-256 as an example.

Note

- Create a directory and run the commands in the same location to perform these steps on a Linux machine.
- For ECC, replace `rsa:2048` with `ec:secp384r1` or `ec:secp256r1`. For SHA384, replace `-sha256` with `-sha384` in the following commands.

### Generate UID

You can generate a GUID and create three new keys with self-signed certificates in CRT/PEM format and keys in `.key` format:

GUID uses `uuidgen` to generate the signature owner GUID:

uuidgen --random > GUID.txt
    Copy to clipboard

### Create PK key

1. Create a PK key pair (RSA-2048) and certificate:

openssl req -new -x509 -newkey rsa:2048 -subj "/CN=Custom PK/" -keyout PK.key -out PK.crt -days 3650 -nodes -sha256
        Copy to clipboard
2. Convert the `.crt` file into the `.cer` file:

openssl x509 -outform der -in PK.crt -out PK.cer
        Copy to clipboard
3. Convert the `.crt` file into the `.esl` file:

cert-to-efi-sig-list -g "$(< GUID.txt)" PK.crt PK.esl
        Copy to clipboard
4. Sign and generate the `.auth` file with the `.crt`, `.esl`, and
`.key` files:

sign-efi-sig-list -k PK.key -c PK.crt PK PK.esl PK.auth
        Copy to clipboard

### Create KEK key

1. Create a KEK key pair (RSA-2048) and certificate:

openssl req -new -x509 -newkey rsa:2048 -subj "/CN=Custom KEK/" -keyout KEK.key -out KEK.crt -days 3650 -nodes -sha256
        Copy to clipboard
2. Convert the `.crt` file into the `.cer` file:

openssl x509 -outform der -in KEK.crt -out KEK.cer
        Copy to clipboard
3. Convert the `.crt` file into the `.esl` file:

cert-to-efi-sig-list -g "$(< GUID.txt)" KEK.crt KEK.esl
        Copy to clipboard
4. Sign and generate the `.auth` file with the `.crt`, `.esl`, and
`.key` files:

sign-efi-sig-list -k PK.key -c PK.crt KEK KEK.esl KEK.auth
        Copy to clipboard

### Create dB key

1. Create a dB key pair (RSA-2048) and certificate:

openssl req -new -x509 -newkey rsa:2048 -subj "/CN=Custom DB Signing Key 1/" -keyout db.key -out db.crt -days 3650 -nodes -sha256
        Copy to clipboard
2. Convert the `.crt` file into the `.cer` file:

openssl x509 -outform der -in db.crt -out db.cer
        Copy to clipboard
3. Convert the `.crt` file into the `.esl` file:

cert-to-efi-sig-list -g "$(< GUID.txt)" db.crt db.esl
        Copy to clipboard
4. Sign and generate the `.auth` file with the `.crt`, `.esl`, and
`.key` files:

sign-efi-sig-list -k KEK.key -c KEK.crt db db.esl db.auth
        Copy to clipboard

## Sign images and copy (.auth) key/signed files to EFI partition

The EFI system partition consists of EFI, loader, and ostree with information relevant to EFI when using systemd-boot. The DTB partition consists of dtb directories.

The EFI system partition holds essential files for booting the system and managing updates, while the DTB partition contains hardware configuration information. This section provides instructions to:

> 
> 
> - Sign various images.
> - Copy `(.auth)` key and signed files to EFI partition and DTB partition directories.
> - Signed and executable images such as the `bootaa64.efi` file (systemd-boot) are placed in the `efimountedbin/EFI/BOOT/` directory and the `vmlinuz.x.x.xx` file (Linux) image is placed in the `efimountedbin/ostree/poky-xxx/vmlinuz-x.x.xx` directory.

The systemd-boot validates the signed images and is also used to enroll the following:

> 
> 
> - UEFI secure boot keys are placed in a specific directory in `/keys` for key enrollment. The systemd-boot uses these keys and provisions them in the RPMB or UEFI variable store during UEFI boot time services.
> - You can configure the wait time (in seconds) in the systemd-boot loader configuration. Kernel loading is delayed during the wait time, allowing you to review and select available options in the systemd-boot menu.
> - Device tree files are stored in the `dtbmountedbin/dtb` directory. These files are used by UEFI during runtime, and the device tree files are initialized. While signing, `.sig` files are created and placed in the same directory as these files are non- PE images.
> 
> 
> Table : EFI system partition (efi.bin)
> 
> 
>     | `/EFI` | `/Loader` | `/ostree` |
>     | --- | --- | --- |
>     | `/Boot/bootaa64.efi` | `loader.conf` | `poky-xxx/vmlinuz-x.x.xx` |
>     |  | `/keys/authkeys/db.auth`<br><br><br>`/keys/authkeys/KEK.auth`<br><br><br>`/keys/authkeys/PK.auth` |  |
> 
> 
> 
> 
> Table : DTB partition (dtb.bin)
> 
> 
>     | `combined-dtb.dtb` | `combined-dtb.sig` | `/loader` |
>     | --- | --- | --- |
>     |  |  | `/keys/authkeys/db.auth`<br><br><br>`/keys/authkeys/KEK.auth`<br><br><br>`/keys/authkeys/PK.auth` |

### Place signed images and keys in EFI partition

Follow these steps to place the signed images and keys in an EFI partition on a Linux host machine.

1. Locate the `efi.bin` and `dtb.bin` file paths in the `contents.xml`, file to
obtain the `efi.bin` and <cite>dtb.bin`</cite> files from the meta.
2. Mount the `efi.bin` file into the `<workspace>` directory and create an `efimountedbin` directory within the `<workspace>` directory.
3. Mount the `dtb.bin` file into the &lt;workspace&gt; directory and create a `dtbmountedbin` directory within the &lt;workspace&gt; directory.
4. Mount the `efi.bin` file:

sudo mount efi.bin efimountedbin
        Copy to clipboard

cd efimountedbin
        Copy to clipboard
5. Mount the `dtb.bin` file:

sudo mount dtb.bin dtbmountedbin
        Copy to clipboard

cd dtbmountedbin
        Copy to clipboard
6. Create an authkeys directory within the `<workspace>/efimountedbin/loader/keys` directory to enroll keys.
7. Select and copy the `.auth` files (`PK.auth`, `KEK.auth`, and `db.auth`) to the authkeys directory.

sudo cp <selected algo PK/KEK/DB auth files from the files location>
        <workspace>/efimountedbin/loader/keys/authkeys/
        Copy to clipboard
8. Create an `authkeys` directory within the `<workspace>/dtbmountedbin/loader/keys directory` to enroll keys.
9. Select and copy the `.auth files` (PK.auth, KEK.auth, and dB.auth) to the authkeys directory in `dtbmountedbin`.

sudo cp <selected algo PK/KEK/DB auth files from the files location> <workspace>/dtbmountedbin/loader/keys/authkeys/
        Copy to clipboard
10. Sign the `bootaa64.efi, uki.efi and dtb`, `vmlinuz-x.x.xx`, and `combined-dtb.dtb` image files with the keys and copy to the respective directories in the `efimountedbin`
directory.

    1. Sign `efi` images:

        The sbsign tool is designed for signing EFI boot images, such as `bootaa64.efior UKI.efi` that follow EFI specifications. This tool, which is used for UEFI secure boot signing is available for download and use on Linux systems. It’s important to note that
sbsign can only sign PE images with a `.efi` extension.

        1. Copy the `bootaa64.efi` file from the `/efimountedbin` directory `/EFI/BOOT` and the `vmlinuz-x.x.xx` file from the `/ostree/poky-xxx/vmlinuz.x.x.xx ` directory to the :file:`images` directory on your Linux machine.
        2. Sign the images:

> 
> 
> cd <workspace>/images
>                 Copy to clipboard
> 
> 
> sudo sbsign --key <workspace>/keys/db.key --cert <workspace>/keys/db.crt bootaa64.efi --output <workspace>/bootaa64.efi
>                 Copy to clipboard
> 
> 
> sudo sbsign --key <workspace>/keys/db.key --cert <workspace>/keys/db.crt vmlinuz.x.x.xx --output <workspace>/vmlinuz.x.x.xx
>                 Copy to clipboard
    2. Sign the `dtb` image:

        All images authenticated by UEFI secure boot are regular APIs and typically in the PE format. The signature header and size are appended to the existing PE header, and the signature is appended at the end of the signed file.

        However, when images in non- PE formats require UEFI secure boot authentication, the absence of the PE header and its magic number to recognize the image format fail. As a result, it’s not possible to use standard tools and paths for image verification.

        Currently, among the list of images that UEFI secure boot verifies, only the dtb files are in non- PE format images. As an alternative to the sbsign tool, you can use the `OpenSSL cms` command to generate signature files for signing images in non- PE format.

        Follow these steps for signing non-EFI images:

        1. To sign the dtb file and signature file, run the following command:

> 
> 
> openssl cms -sign -inkey < .key file > -signer < .crt file > -binary -in <input dtb file>–out < Output .dtb.sig file > -outform DER
>                 Copy to clipboard
        2. To sign the image, run the following command:

> 
> 
> cd <workspace>/images
>                 Copy to clipboard
> 
> 
> sudo openssl cms -sign -inkey <workspace>/keys/db.key -signer <workspace>/keys/db.crt -binary -in combined-dtb.dtb --out combined-dtb.sig -outform DER
>                 Copy to clipboard
11. Copy the signed `combined-dtb.sig`, `vmlinuz.x.x.xx`, and `bootaa64.efi` images back to their respective directories `(dtbmountedbin/, efimountedbin/ostree/poky-xxx/, and efimountedbin/EFI/BOOT/)`.
12. Configure the wait time in systemd-boot:

    1. Open and edit the `loader.conf` file at `/loader/loader.conf` with sudo access:

> 
> 
> sudo vi loader.conf
>             Copy to clipboard
    2. Add the line `timeout 2` to set the boot menu timeout and save the file.
13. To unmount the EFI binary to retrieve the latest `efi.bin` file, run the command:

> 
> 
> sudo umount efimountedbin
>         Copy to clipboard
14. To unmount the DTB binary to retrieve the latest `dtb.bin` file, run the command:

> 
> 
> sudo umount dtbmountedbin
>         Copy to clipboard
15. Securely place the signed images and keys in the EFI partition on target.

> 
> 
> Bring the device into the Fastboot mode and flash the latest `efi.bin` file with the fastboot command:
> 
> 
> 
> > 
> > 
> > fastboot flash efi <efi binary location>
> >         
> >         fastboot flash dtb_a <dtb binary location>
> >         Copy to clipboard

For more information, see [quic/host-signing-tool](https://github.com/quic/host-signing-tool).

## Enable UEFI secure boot from systemd-boot menu

The EFI binary is composed of signed images and secure boot keys, which are generated and then flashed into the system. For more details, see [Sign images and copy (.auth) key/signed files to EFI partition](https://docs.qualcomm.com/doc/80-70022-11/topic/enable-uefi-secure-boot.html#section-sign-images-copy-auth-key-label).

When the UEFI is loaded and run during the next bootup, the systemd-boot manager displays the **EnrollSecure Boot keys: authkeys** and **Ubuntu1 8.04.6 LTS** menu options on the screen.

Note

These options are displayed when a timeout is configured. For more information, see `loader.conf` settings in [Sign images and copy (.auth) key/signed files to EFI partition](https://docs.qualcomm.com/doc/80-70022-11/topic/enable-uefi-secure-boot.html#section-sign-images-copy-auth-key-label).

![../../../../../_images/uefi-secure-boot-serial-log-fig1.jpg](data:image/jpeg;base64,UklGRigrAABXRUJQVlA4TBsrAAAvoYEZAP8nJEjw/3jrBEzA/Ce2e2cobts2kvcfu7mT/iNiAhAajxagQmrvIDbRsqkXQSNuaZqJsihc910QrxDvGFvYQ0b64/9/sZT+/55n5kycMyd3l86lO5buEsFOOsUuLBDE7u5GyiBsDBqkWbrBBaRVShEW2Dg1fyyf/vi6vP6cuT+fj3lG9H8CvGHbdkiStm1nRmZUVnePZ9oY25dt27Zt27Zt27Zt22Orp7qr8kdE5Mx0dvaS/es6YjvOPY6I/k+AnSTKpCjtjSUeEXFOs3fDHXxMgDy6aCklMrCJmui/9l2Hqk1ECZvgkQSH+nTv2rPLtRq7ceohJYdm7tc1iGtjzZwTl5e0TY+UIbqsW6/O8EbpwJHdpRMz99auaiK8uWO3Tl1577bJkShdLDmXna7R2PMSQR07dBVXnblfHfNrXVtXVWPPPk4XeWlrW6IUiQ5dOva4SmPbTt3J8ZxuV5u5h3ftFdorXblrdHtCuD3alyHqxnkX98rNbjvZkXutrjBzb69ydSS7pho7Eue4tEWmku7odm3fqbld3ZhmBKEvm7mz7tirXM3j8mN0btclz2lhSxmiDm5H12sbuTZ0xgfvT5ySt/uvjze8kZzfHGGQs97+2shveevb9KZt3szIWXrN66Vsb1QYOWPxmpCyvVEAZpAxM/SW3Pi61xs5YxEGOb/5ta8zcoY35/pXv45MxBvydh/I+c3SmFDLLqKz0/qKjZdt2yu1bVN7120bja0rvsuJKLm43ddFdsm1eWHENu+NSBKuZiQJl+RI0lZckpxG18XrhqvRXXJnu28G7u759ep06NiZe1dovGxEG+1xSzWynfTadI1Ns94qk9LU3SItSrpAk+oa052tXacxzXBbGF2MbnYxSC5JdAuMpu2KWrU7tm3dpsvlG9uuu0IXxy5JRNyDEC6NLcu9nbb/Ff0ia6skNIHeKDngclVtYSQHXHIksVliizFevTdeBNGBT5kldeu3bdlWiMs2XjrnTD5msYI2rVq7sm1smv12Kg0nsf0zWHJJBu6SDGTCtr1mMFwSXpHAcEmicnG6U2vgrqqDmS1s8VEtm1umytr6ddq1EbJ1c9C2wdE1jptHsqUam+a8A/tfcclV664xL1zSBLm7JCH5ls4kd5ckJLcOb2IMSXJwV62Z4RrXJQmz6eDuvqB6rQ5t8ppLNV9GOj6O2lojW4g85MbG5d63iTJp3+5Lkpt1kuRmndnmf1+4MNLSNl/BtnSqXTjffTT2QicfSTUO+Jiqd0lysy0a113j+nZfkjuwsm6uaNEmr3lujpyP05FdTV4LCDQ3zXknDftfki2bzz9PElva87P0ydt+bWHUagIXF9p8ztk15DP+fkIsjqStNeQz/njC5pGWFl3enZnPM425cOJf/nzC5pGkxS3t+Vm68OxTTvj3v/5j/z3x9PO2jnTK7/90hrQwmo5L7stza7Rs3qKZoDFfOmP5iC0juXTM0XFsNB+216tG0zFVSlQ8pdeiTCKZste2eZOct7R3iErIoSS5RIkyDqWdDNEFENF5InKIyCOACESUIQIVk4u5V/bKJ0qVEB/YuGHe6J1JO0MJshP2xjua12r80G6iFGVIXtr8lWKeKLFTRGk688FljRu2nJhwHCdp/9TqiyKbHm7aIq9R82Zo1Xm7fXxcy6aNr/kmaU/PlbnVWjiiabPmo4IwDhqNoebD9pwWlHLSiceiM20iysy2BlHyff+HHhGVUppQRJRJJblD3CEi0EUT9w89ZTtUNmF7Ce7ZZfkfj9YzQkuTKZuvqN3wqbf7hYce4wmyKZnY1ztn1OOk3Xwy5dj09y06G3meKEMOldJf95TvPu6JYS8W2WmizEf6A0SJD4YMvLEc6ztsxOg9p0dqfcfd2WHU2X+ZZmj6P3mkjg2ziqSjOUrefOj0oFSangp+m3KIaE58ZJLewrR0hv7nORF4EkREHhGcjjUPZwglBCKQw4mIPE73N322X2QxT9kXRsR/Ivr7uqzF9sWfU59M0rGBgU9sTjS5zuWxAWfKEBWnpoZvOZHgdB5I2kSTQ+OphEqLM6cGN1iRTJC9Onj1mXTpvk0l/ypVmzWVjZs04+GKA+s4Aqf5kD1qlqYBcXpWzLCJeOrH+M1E78am7p70+MT9lKQDXxbYRIWzV2XSR1yiiU9MP2on9nycm/PkG8vtcz8uTCRtWvHTeSJKZIq+XsPvD7s2pc72q7KOKDOqsmtTmkpL/uzScB8RzdDvzRD92XXgF7GRRXYmSZROnehZ/4+SlJemsiidLMYTiDJUOih3GxEVz1DHeyWUIcIUqVmlaeMmDdHc4UegBjusM+saD9r9ldMiyYk/EfosmUgDP8ZH2fSaeWXXxvXDl++m1ORaEylNa+vcWERzat58ff2mkRsO2z92CrvN6r1s7287yCM6fV2DnTalKOMQJe4OL7WJ6HXlttPpX6r3PAa7hIjys4ZdQDIhQ9edt/FczQ2rAyPPl1CGkLA3V7qJ6FSGEy9NZlKJKbFxdomXcejC9VU3JTLc3lyu7kKbCJSZJpUbN2hEDZvVmeyoA+q6Qw7tDvPGA3erLC1OgRSIno19Y5f9SYxI0nv+0L3r197JxpbS1AofZSiVX/H6DJ9lhQat3DGYvVZ8emPH3B93/Enbm/W7kEmdvi63oIiIiJdmnDvCi9LJFB0eKIe83eWSxTZRhtK0Sh2X9oj2V3NOpfNr32b/Yg4oIiIC0eyKA9+/uf99M8/aF/3EGmdniKepsH/uGs4pXfQgq/bCzoSd+Fep1LBeA7f+mFKrI/ev84MPOczbxgN2nRrEE/YzkZlElE79ELuphN41R/5DVFCn7R80qeIH5+zUavRL0nfBq/el7VXlbkrZ1L3+YZu8bc2HFRNduCpnL2VS5BBPJm7Phs2J06FLGMIfO5RO2ES0kI2nDKcDDVucTN/SaC3mm8OLeYo4EU2KZ7Uf2q9a8JlCSoNSH1uP8DQR8b+va7DWdihhn3yzGmv+wjH7X3RljYoN6tar4455qFt7RFN3sLs1ttMDIHo6/jVPE9Gc7JuJ3gxNLSYqGVh+ZelnlT6wCZuqjkjQ91nP2kTbmgwuzCQ6NP4tZfO9TQaesensgBr7yClDTuLO6AI7SZnjj+SOeKhxg7eK7DQR6Af2eIaIjjTqfHRujfdsWha+8xxRppTSmQ/VG3YWFuc3Kbc+lbEJ0+LjqQyd71djI6WISjLY8mgOu+X3zPRY5VWsX6ee5x7c2LZt1x6+n6SlRR16UGcHNm/c7dVa0lRMcJs/YX3F09zmP2XfRcn3YlPShKK7yq0p/aQSAVhXvn8q+WXsUTuNXQ36Fdpet3pHbC+xv+UNp238dU3tw3aKqIQyHHfkLLeT9M+9lV857S3OK/+VTUTpzBr9Hs4TqT0Vrj9yadXZm399W+2z6kLSJkrTF9ajKRt0j386iEoSn4kH7BKiTOqfoVXzHSJKcodKF7cMfm1Pz+XVy9erXVfUyY37t13XdRtr/NAud+PsWuNToOxH0acpk6TS92MvpenVwPtEmbM3Vt+ZmJL1tg1aW2UY0YzYhGSGdjcYWmgXd693IAm+q1WfCzadv6rK3hIi8ojIu81alHKwpvbgQpvkbDac0kQ4v6l8r1OUoTXmXRvblqtZvWqFQKjqu6V2OpmiebFbiYge9c0soUyaJgefsNMeERVeWy+fUwpEVJqhxw3+b1KtvFu7Tq3/qdx1uaLFpUMO8Ly/N27Y9dXSVEgRT9LyKj1O2URFN4Rnw36X3V1oJ3fU7fJHalHOQ0TeVG1owvvOetIm+rXOoJOlxZdV303Ej7VrhVR6S8uau22iVIYIifuiK22ihfrgFIHyleE2HT9BcLpmLaEUPRv6vHTxl7Mmfz3BwKQdSfvoeUr9Wq/tsVK78Prya4mcNE0KP5UhohQV3Vg7n1Mx/fEPUSo9JjLxX2RFtXJ1cmu7tZr3C3f3DZUl7yL2j+Z1u0wLShPRubv9gxdsWH6nNfyETW+z8Jhtm4bh+aR9pE6t+QXv1sewtP1N8Gmi5I4m110gujf42uYDdGaQ8eLe+b19uQV2mqiY9i1ddqXx9trt9v725T/f+5d7bfaU5MnbnEPpohdY3/w9n1Xodtg+Q5RMLdOGlFBmUZeXXCq82Tdhz4HngkNOZ2wimmhePWf297P2Zc7fUHt9qU0lL/SbtXHnx+Ua/JqeJjm1a+R67n7NXRvRrq9ZzJtyl5vXrnhVhe0fJ6IkFdwWqNS8YvbIXRmb3osPb98gNzZ8v11U+mokJ6/e7dWH2amvY08S0e76A86laH590fDZYntFs2AT76YODfbZRCUZPqZK3YhasdGgU/zn5uHOPRpXfuy8vbuxuoHo6KhogxblMT9lZ4g4LbVGFpWkJ7MhZymxoado0i5y/S6bkmkqnR5WZHZEvG6X9Ku+kQg0uWK0aUOzxXcZe5pk50KgRm7scpdzt85HkhYP2LiBlsbVy6dFMgOPJ+zzP79+/3tzT6btJG2ZeTR//ONfHLczqWRizpPPrTo1Y5Fdum/yhqJk5q9Z89IAFj768HqbUmvfGMePL5t8LpMqIaJVUz79/JuZny0oJdrx6Zi7Xl9VWJIunTfjNGXI/WbCgxP3EaeLHhWLbeK/fbSGeJL2TrufppyyU1T25Pdfzvr68ymbMueXTPzTThLRunfHTJi6g1KZKVI1q0YVV1bf2JjJLXltzdb9Y12MuWpZjW3/KElpIgIRJbhNVEJEICICJWxK2ESlIMp4RASPyAPRBRCIyAORR+QQgYjIIQIROUQg8ohAxInAE3ZZcIcTPM8BuUREnAhERAkbpY5DBKIMcSIQgcq6nBK2V+oRgTj3aJrEq1eqUtmNxk1tG9GuWazZb/260DivnBaUJHLII3gZIk5EIJBDRJw4eQ45RAnHdkAgInIoYZdNlNogEDLEiQhUQhycEyFhJ2wizyEiECciQik5BKJiIkrYBKILRBnOiVPC/h8WEVEpcYcoSUSUokTGdgjkUDF5RESpqVKtYuVK/xMb21ZqVy+OBMp5zapMY5b/HeJpImbuy6tblSpTTbGmcXXOuc17jxps5TjBdxM2JZKjmfvyurEK5XOcyuOQ11OzpDXW7UPXGNHeKU1TKrk0c18qzQrlsuPuqmYzW2d7jSR3dd0+bbey0TUm2hniac3c11bVq1V0KzsrG/eRtFp71q3cZ69Oezda+tP79ux36Q8z9+m1rLgezYnt3exmK9s8krTkreW8T9fo+nNbNGreDLP3umooO+qKyJ7Ne+W8t3mddbt7mxtdYfj8DoPP3LVoluA8kp2bO9+t69qaRctta02WEwxnR2PCZ+6hHESdCI83eW6jy+2S5K4277J7tBPLDSk9bnF4bjzGXQnpCWlJHvJi2ZwLj1sBEXE94ZHreoE4QtmRGJflOCzXldlcRoSMe67rBWTEdWMyAFghIJLjegEvGuOekHEhZSjHikSlG3diZoi7OVErLLgXy0bEDXgRLj3JJby4w7kjLelxCU+6HKKCF/I4D2R58exIwORORIR42I17XLqGkAiEIpzriHkWj0W0bevuLpfwnHhI9XjYCng5EeHGJaI5UTOb84BTjrtOKDvHizmBqCviPOS5nieywx4C8eyQJyQCknMR5xHXlZIL0U4s0YZHjGpi913amFxHeCLgRaRlusLLDgcE9+AJNxLgngEnmwsgEo9JyzMDoUg5za8HeTgOS7qxkBsww5EsF5aUUsa460rJHcuNcyldLhzXcwNeTJoGwB2IEDzOw5Yb4UJ4bkxKbnFpxsOuK4VwPSFCUnpCkCfgxjzPzRZmwAOPkB72pPQA1+HwnJg0Nelyy43HwjzHC0SsaLnsSMiLiGjb1n1m2POibpBi0oLHXTfmOEJ6PA64VrYMGabmRlwRk2HPNXUrIGJxL2K5PDsUlgEZj5giHAoGXC8i4MZ5yIuJJaJra7SkriW6yTWjumdokigQDFumCEu4wuNOPCICoYgX0K1IzEXAkm5Vl2LxCq4puRWSXoTrTLrSy/asQDAcEbrnctcSbtyDjlDABDxpCSmkF5ZSCiIhAOEJeJJLXYOA4ppWjgh64SiXnielJwAvwrn0PE9IGATXFVKgYmVhSi87FnEFtwIi/D803EjMtYSUQeFy6cZ3qUaEy6XwXBmIiIAXi0fATQkZCpMH6fqlblqVqnPdCyASJjdeI+RKz0LANWVEuFyIsODCE3og7nGXLB5y3W5i267L0XV1uWtzZmKjXlal3Go1aiEetGRIBDzAi0YCWkQ3rKDnaZ4IBryI0NznX4lT7Nm3cgJGiFyT/JXr1or7RFCXrkQ4BM2LBGBaQoajwpRBAQi4rkSWIUlCC7smIOIRPRgIQVasXrsc93SfZQjheZ4IAnBFlAvpcnAnIl3F8zxDIhvu029XE15El0HPs+C50g3rwnUNuDEvAJieC0tKSHI9RFlI6bkUFjr8ZElpyggFhB6WwmKDZ7Yk07W8oI5rZ3U3wm7EJAh45CcrykXYFfCgC9cKmK4LwcS2ObeZvFTxliFtTCwqPLt404a1K5bdEFHNcMAwXcXnun4jRORFQLoiAq4XBZXbsqeqxrf8Xk0wz7CURs+v2LJmWhtTBoIwNApGJERAF25IE1YkbFIQQpMiIPSwcF0VrnD/hxBmuOfny/KXfD2hIYvySCho6kIGEJHS9fyKIYQIhJnrBDVLNynI+Mq9tZWAp7uua0rXlZZrSBEO6qYgVzgU8TQZUE0ebJutsEeaGdbJDHqWKz2NwqSakbDQ4ZDnqu/YPUwroMugoU6whymWaRCEK4VwpUsapBQhkp4gLxKkgEBMLq3aYLEm2jJiOLGotiW97Ls5P86+PBAOqpbUpCHcoKmohqOYrhEikE8xdBZbv6uC31xzqJKiWY5Rc0rh3Pe+O/JiiAUN05KKTwvoMhIWKkwpDSGCLnkqPBElxxWa5blmkAikkPQCpI9OHv76501Fso4wNfgdYUiBoCArJKWneQEKqv2/7cXgkgz7spfvrKdHAqbmulAcAUMIKBxWUCNdGhQk4bpaMCzmI0KSNMVxLQlEdCGl5TnRYEDopAVduuyL6zSmmu8muqqabvmFzh5OXq8YQc0KBTwdBFUIYTFHBKViCIdc15SSJrhVKbU1DGXS3MRqtbduahkMx0SUFE2HoTgAHAc+5gQ4NMGEAQiNRTcWZMNac6C8EnCBAcXTy/tj7WXYDTJoQZXJoOswOATSHAZHY46Pk+4KTTLX1RwWZCTBhaG5JOXD554Mxht9U3Ir8/kVDtIM4agCDJqQXAow/nTmJsWnayJC2Qu355LGpUGSKYbGNACOA3KESXAYHMsBV6EMpbmcSwKCXFI4pOBMaGQwU2MOqVLg3vOPACZeL+oN+MANjY23B0P3GZoMMqhCIVNqLlzhdwUJi4Gk5rhzEzuMbOTYWpOHfamcWNZo87qaGvOBW2h2SbjpfaPbaK4qm/St0GnsNRF/uMeoB/vV0Ris/F3Zeii/oLJP0QkPX5gAaJwMhYfybn7g6moMAR3Vb3zwPjJRr3uTsIKKVzX3q9E+dSvcxWsSq3j53aO7Rv2GShp8Y87c70g2/J+XNROs8iW33XlVLlMDDrJ63DK6Xx0fqyzmnv1kZJ+I33SQtWBvFR8a9K8TZDlX3HdTj0rQO12e61MQaNSzPspdNXZ0l2jQEJWkuVzCQJhSZbHOt91/b2u/5vCO3aOK1Ntcmu3r/cW5L0dcHXdevyDrjbqzXZQpeKh0APkq92ttqP5Od95+RXXG61zTjCOA3F7SiLS+c+yVFVk5sXPzuQ+qLMo9JpnV2LoxGwoBIjLGeW2Vc+j30ZbGH9396ra/vq9c/uO9m/P/3Hip3xdcuytbQf6+vdMySr/T4qqmip9x0twJu9Yv3zq/E1OVriuOrP5t+yB25f47/BprvW1KyJ+396Ovjh+5Co2+37M4/+BLFTQfZ4r/rjP3aAzPnHkQGsv97OCOrX8u7AxQ9Y+PrN3urLpCrf3ZOdvZ+XktpjE9sHRrHSVv3da2LHfmroWr9r2co9x//BY9wLI+2dQmMvnAz+vWXsvU9suev6xYPkyD0mEmYi/t3bho1+G7TVT5cUENIDK5oIP+8V/2oV2zm7LXEx/9svbInxMMaI9cGKhWm/LbbXrFJwvWLN07pzm7rGB6CH6M/nuwcceW9cv3jDX7E1ukAMVonGJiec1N+4dfc6XXkDP9Ufu3J9r1P7q3BcPz6bOfXNm9/Jv2B20a3ntkU54RyN+Zxd01e/cYzKcyrfxoJn94ZQUOBp6Z3LLGyJM/BdUay/64t9Ul0yf4rv5rLAPaHZ0d9bf4p3jpkKtqhmd599RuPvH4bYrKCLi75N1WnUft/LEWlOinyRdbtxh7bk0tX+Td0jfzcOfxLfW1Bp+ce7JNQ4P5uBr55ddQ9WV/XMu9jwsfqt/0rX8eZh2Ozy8PX5uDX4X7nX+iSqOh7Rj62Z/emzL1KZkOVH7l/jb1btxb0JBVXbe+BhCafrQ7Gr9a+HYnhNhL6d+fb3/9rsMdfGx8or/+zj8vhnx3nP6wae27Ts2IVFp0orFPMRf+Ubf+nrn1q/W/IlBMbqXXlKIQEyurbEydLb1Q/EaWj54uek6V7PmzQ03+VGJGnKP97z9FFaiP2Q8zc832GJOr9uyT6AMHvXXanjfS8GUvWucCyvtHOuDm4icBxaqA/qceVJnW4bcZQX+Tol1tGdD12DMMKL9viQ8KObi95OSBQxn+WlWGy05PCcGHFxM3oe2Jby0d6pNFT6jy8b/7+1QmBYe1bFPHb34bwrSuR9/0O072bpEV+OJ0T6ncnLxVjr0wgvkBoPptN7AU9EABhxFSALx5opdRcfmq2gze5H2dgBGnH1B0jhftJywVE+yRPtx/fuQY59EoKi9ZXcEHPu1ID4wuHsPQ6eRHWtszkzjj8DOxdWoqfIJ4zQ1H7hzWb2geQ/CV45eqDDceG83wbLIPJG617/QzyJ5nP7SM1duioJUFTh96FOFen6W88b6axzaMGDlw8MwSUiemr/AxjTOz79EHVM7aH/girDRLvMdU+G8+88nQgWLEkV+rMPg1dmfhzOG3PPHL6bf86gP2cFVKdl3idYjC0T4GdPh7qo7HL/RTAD+g++aeXHy8H4NvcPGnVw8bOmTf3vLqsKLnmPnT7jze5tDB0TWZziFQLAP6AhpMBqNpj+u/OXylv8qK/Eqqz/jiSC8pbyscywIwX0u1hab2KxrjZw8Vrjz5XICh+YnlA/oN6/9T8XC1yW6KGWPO9pOV5xS+0SLA/h++CAl3n6S168srADj0F073Yhz9jk3w4xG7L4N6B90A6GaTo18ZYtXF9gLmCwSfHHXyRIsmZ08uX7sifxt1ZVOTrQEfgCuOPQiutz3+VRTNEq8bUDAmVbAyf7X4bUqE+QB99IlbGdBy1bHL/E/Y3VQGk5+ZFH3g7DAdQLuDn4Ux/twwAAqgBub8sbToZubDPcn9K9atWbnv2yy1xvaNVus/p0qGG1ec2D6unM9gKkG1JAaJdjNXr1rjHO3Dqy7eUIWr5udHOjHcenosALyS7hZg6g2J8fDdd37zuQ8tH7oXOvmbV6zbvbynLzjreAf8sLWW5mv1xeEDHzUwJ6dHAYzDJOduW+Equh9Q6cnjl3KBIX+MZc4Tmd4+Rdxqj4IPapvCicxYXWZVwV69YpDoB0jiHXtwnXPfV6+X63kVVfZmqqcOGBzXnRoDoNHhr8JoWPqmD+APnRiXW8utybNZWd+d5+9hUPFicqzyiH054Df7ljzH7vz7DuZT0OnwNBWPnR7AFB8A6Mu2Xb7laHfg7vTjtXiD3Jo5zIe3/ulx17FhTAHK37j07Fjy+ZmWOX0UDkD1lhfcnFfrjYOXKznLNlcin/+zQ52BW049oAPOc+keDDS4+EH4R1+4/dWUy9Dh/IzcmrK+WznIfCMLH2rx92tMhT/c+bPS6ZUmzZsmu+rmDVXgg8qhvPRnX0b60GNjoDxn9wasXhc+CzBFu8seo5hrtseYXLVn12TQW9mHCXyYujRnyxIB+AEHj2bu1xiMKLr9+aGrsWEnv4kqjey3mKopN5x73ieZ5mcag5S4++z94Fz/pPAWbXjqdaEQe9y+A73PTFYBPHj+IZ09XDQMF1VCC3fEeh/aUB99/3qVaQwag+a7Yt8XC5ZXVSUY0PzPuTlAvEwFA4QPZF5b+KoKvHKqLwvO2VtXY9WX7e8JDDr9HBHhxdJOgH9gyXgoE0qvqrj4795q9d3LYgyKH4BTbcuaj4/1YYAPSvCnY222Jz6xSuUte69qmUdtKwMvneqlMmfoyfGa72m7h+qwCvNKRteodt3edc2ZuWZHHIHVe1YNgOUveX6v2s3uPb6uDnus5A2RU7XjpVHWaVdBn5qtnQm63Pz7FTUGbLM/DWtN6G2F+X3e0mMDKsXr9uysKeT3sfvPv9+sTafHzy2syWqsPnNr1erDD86v58vJL7yvcq0B+zc3UtTBiWktqkWkjzNzoaiCsUWfxyovOjqwWqRun+6Kn+X8XHjuTYJ+Q98q5W48M0VnTRc+bQgU4ANw+V8zy1UeuvfMJY7+ePqtmk0mZX7vorIe/yyoUS+LvZnsyoAR/HGIh7z+rM+pbQ3xSsmzNStU7NwnylT5YuG5edyvdBySG2i6dnud3uQmH8+Z5HVfXvzdb375u1/cteg/8/TrSak77Ynw7C1XZ3kqbvST87/++ZO+d/0k/7qCLPjX71sJfXZ//Jkn/PhXm79z7V6x3xvyLz/w5T9+bG3i/v855Tu/PfleiYf978Qf/+TDv3nv7r0jRi91HyZu8ou/f+G9P/3TozQHxbJ7n3r6b379tzO/eI1iwE1+d9r3v3vCT64J3NhO//7XT8o3TEX/8C+d/aOP7J+QdvviH/djxTsvHIvuG39fNH3Z756+DHjK4r+u2U97vP6/n/vA739649S/xegLe/YGARQM2fCesz7/8R/6328Ol/751h/84mv252v0WPuZ8379sSN40cJV+8Xgzuc/oZcev/kORTz49A8uO+jDZ3/9k/znfavSPLqesh9mqhxasGr6mpN3mGlinWL7MXf9R9gD9SiOL/waj9kvwREPvpT7lZ92AECx6aEvf/VDji4gNFwG/caQO+cTBmuu/Yw3vubBRyQGvVW3esEbX/zw41LB8us8/w3Pump/kOZu8fyX3GafW90ErX3stRAwPOhRr3rD83zvVLvvPR788Ac97OZrE0Ec/sBXvfL+h6SA3mEPerX54RQwd7lnvfXeEhC3e8DcQOsf1U/zeUM/mPjC7VZ5mbjGGd/arVDacN9Xv/2xl5nrccCTbjWAMmWjeuAD3/TC6x919wMSHP+YVzzq4OPuv39S79gnvPEhK9M1HrW66GnTY67A4MqPO7THsHvQeva63fPf/ML7HpHAyNr5R3sNLDz01U+f7KOxHQIoB6mc84IECCf3w4dB1YOCcFyQKEvuYQJKTzIsB9g8tX3HCYTPA2QAOQ59gJwZNygT2QgwKFPVjKrAAaesCPAAggQsA6UnD+5zzvOSYxRijmoEIjAwIARlUuCOlckcQCotZfK8OwIwAAOByfoO5qDBgflhFUKBYwCOsyPgFIDKSJIR5g4OuEOpBAFEIAHHcQigEB6i1oFwEKJqCsflGhYMDRyjcGB5AoLIArmDwqk6IHMcBHk+g8rk9IEyDcnUKhzcAbQkyKs+feLlcZO7U++IWvUFiDIRjgNlArKhMjU6KJBHGE7VQRmy3Hj69FjGAQUAh8SOQBAQAA5gkMtU7+4ADhQlA8AhNE/NHg5BVWCAA2QwAMNcZEAEUCYEkgRysKBeIADlAMeptdKNBCFwA0fi4g4c++P3ZmcA4BUhA3APRNWHVgAYY4qqcNwIhQF4VIyqOxCeu6oBK6v4oKnsP4IxhwAF4AHCMackIuHOuB4VOdWQmC+TliFApVwJHBxA0CcHgbsAOW4wdLMoUyF3KEMkAgjw0lM1AwgMd4R7mQKAcCBlZuisvOKhQwgremWOVC1VgSFBLAvmca84XnpyAxyMog9IDqIaDL0QMssApTltGxIYiDvQCaAdgiJKJSTD8TKVqRoCGWBlAsrkIM6hcYZyAAQmd3AwnMAcB83j1ncwWijTsAAhE5QJA6PWATzMIOQCRakESA5kAkcoh5VKgWmMA+BguScEENSGy8CdqEgOICcHjhtIQLRghoMwR1QzEIGXCQxkACTI5JzDAcCh7gjMg4MDfQMHylTglAkc5JSunJASEhRkAiSFPMPQC8ODDLgcwAAXgnCqhgJA4OBCPo/jBn1AuLsIgACnTCxPASAQCETV4eBcAgG4Q4CDAsAMlZ6EAUFVZDKCAEEEuMPyJBwyZTIHA3AMHMIBNGJwAMfB/9uXmLtvO7Nkt22ncGbyZcKJ7NtGrc/eDHco2BYKwCNmcCDGvyQod9kj77Zr283c2+W27ay71p3vccdb3+oOM/e72LpErxhsEyv2O5LDOfbomfvxB+2a+gVjXhKDKNydGbyXCYe5bWHn4f8VIAEOwIICkHCBz0ECBAlAQkgQ+EUMcI0p0gDAwSXnOFYmCgAc4FoiovQKAdAuRgRAQmr8YgReRoKcWYgBhRxACHCAQIwpJYiIAxwAcfyPJUdZSQBACKBMUgqOiwaZAAYgwCE5FHBwOARwaMQAgsaZhOPgP8kdGUfhIjueJQGAOEfVAY0BfgDgJgEkQOAhFRwAEQfAAUJZhyEWAWCqjlNQKzMcNeCogJWTpQDQiMEHSJIEQEJjkJDyvyLgNV9fNueHF5sxQIXGijm8TIgTDC3AwAFwvxBA+KVHAU1lCkgKcD80Bo0RgPHwN00QwNEHAy77zDeL3qjNoLV/e+53d4Z8DIDpV1SAoEmmMc5hQNJ/RXSl8a4f7nhx33STVJ2BHMAJKeHvMQZlOaqObc61rCnPMABEMFBW8RGgDSxRKj13YjYADg599zkePvmBZ/74ogKvl7/knneO3BVgPkCBCphQOQc4/ADA/ysCvdGO2+F7cV9zQKvbPW/FoEisucxlqzA0/mT3dS1iGuPxew6/0a4ay6uNkIhWbN1AY3XbRVQf/NU7tx5CYXBoU2nUrBprJef6PRx2kRR472An+ciGJiz42epcpvskGnbwODi83g0ggXAbMPCZiNZ81+0Mz29pAO3mJSvWvP8Y71/9gz/56YLB0dt/vbDkraoMWsuFpQU/9g5+Mk7W/XTSjHXzho8WO96rwTDou5WLX7S+KJPKZ70Rsl769O3VG5+5W6I/6AEHT29qxubPZAru3tkJQHDInCXfXcXKPb/QmzcyqMjPli1+JYfNQjgab5111wubn2IYVfBWzwG/+cLeB/z0k9e5Hn7tXGMS+rQIMhPWbfuf6hhTf/lQrbPh4EPu6sKv+435/U522a5H2l/166cN6MEbFoVD355+s+8b/7huqvXptZd+Kc2NHzC/PuJgX0XVqq2c3Prqrt6E5YM7Pra+S4VZq67qN6mXMgsBGu/cOH3+0U8rq98srsRw6689b/+tHdPyCp7yj1kaVhk0xddh8ygwZ847aLT2NfjH7u/pD/z0kvXGvkFten3ya2sSvcFLftCtr2dnsbqbHoQfDgec9/d0R/lNr0PFkANXM6DiktktGGqv+65N5xt/fa7Pvpt9SvkcbSaitNo5IbvCgD3jwj++HYCv28EbHl6TA5Rb9zbGbSiPi3ZdP8LH4gve5TVXP8Rw85KWCC16wfvg729mz/rSq+cTZf9Ni/zR7z/xsfIrnlVgAKBHdtwCJ7xwGghDCrprzMCl36yc2KLW7l1ffPvjgjsGFfRiPr+KmQhabhoZQHTuzMrf/xxlxsAj3e7Z31JB/V2PsfEbLI35uMba77wFPPbTm0ad1RM4bl7byh+Z80z0w9319fCgXxapTK+cp0d+nBowq694EvAZGn9g45Aggzp1RZCzZ1Y35gyA0kF+2Uq8Z4UiBrv+0BA/C0b+K8Idufu1pnn37x9vPvD7uBaXrfy5csuDs9o2m7a1m/++P0fUDusMaLvjw9bZ1vx30HDbBMW8fXszNTjntcB1BeNy617nMr1BMt4xPxz6cXqQVV7/GCs76sTEvHpNJUYUjGt1s3g+Ao4GA+rl/TCnyivrr6nR+Jrq9dcs6NThg6v/KwLUXVSw/JcVL1VkOU9vXrZuelumDluydsXiG+Fv/tO+t3MBIOe5XYv7WFOeQ52fHgAGzqmD2IzHYd69aMH3H717vxA8Z1o4OPFVnVX5YbRggDXjxLL5q9cONkLjNon893MBTWk8beF872q17ke//Dzvo6bsikUbljgNtFmIjkCPq6+9oaUBTWXtru6VzSRHgxtENYUz1LumvQkO8EjPa6ur7Rsg1CmX+6t0DTKjVW3oaDjw+uNSH3rR5Zm8VQsNSpuaDoNjtLv2isuuc+qp8HvXdrMgFQlU63tNI+lnomv/qyoyoFG/3kH2H+SODAC/BACpAMQBgKMsNzQGKOAkcXEpiYO4BDRJJInBAQXAnMEdQAAA5wABHAQQLspxce5wQGP/Q9IYjP+KOJrBwDUGhUAESEBjXCMmAXIACYIJckAOVAAEjYGDYEhAYyCIABRCWe4QOC4upIThAAEAnAAFBDgACNAEsbLajsgWXUA52JGYKZaJcknSVktQ7JQY0EMjaUnqkTHf6dhilIklSQujMkGZdj6GwZCR5O6UvbQzMsoUVKStS5JdoJ2OnbZK2ixpsZUvjEzsdBRyl0sCAA==)

**Figure : Systemd-boot menu options**

You can use the volume **+/-** buttons to navigate and select the appropriate option to enroll the keys.

When the key is successfully enrolled, UEFI automatically switches from **SetupMode** to **UserMode**. The logs for the UEFI secure boot enablement are listed in the serial logs when the systemd-boot triggers a system reset to apply the changes.

By default, UEFI starts in **UserMode**, and the UEFI secure boot is initialized during the next boot cycle. The logs for the UEFI secure boot enablement are listed in the serial logs when thesystemd-boot transfers control to the `KERNEL EFI STUB`.

![../../../../../_images/systemd-boot-oprions-uefi-secure-boot-fig1.jpg](data:image/jpeg;base64,UklGRl49AABXRUJQVlA4TFE9AAAvW8EXAA1AjCQ5blM7BxAAd5F/wCD9yA4gov8TsNaSkth6zKObz0vKH6UN/cMxAkHsWYJSq51VNRj9RqP6LkdzznXf9+fkBbPZULBIkc1InABse3JdP8EDkhA/gCp76LUSS6JJkZQkJSl1XWNI1e9WbchLqip1tyCcWNjmIQc403Om35yeUiuJMwkPIpLot5Qky6kaIglA4pSkA3jrD/3hbNgQHynInVaw6HlePvdXklQjSb6QTNvu3XZi28vnS7xXIjDHOoDEOeyX9zeyxhyWJETKzZYEEElqlJ7tva1f7V2xj0q8xhiRRCJwbJuzScATYu9rI8mWeOBrQ+Lt7COJeE9s50tkJAD71u+/SApjDKmkJA85Eust0SMflOS+x7hWrapQKe20VlUFopq1mVprcrk9AL8HycxZIiEhSRpSAJLEaXFOxOcAx9Lx7ur24SSbZTsyAeVjPNJmKSEBX1mtNUAHiSSVvCVLkT6G3u1IgA0jJckDnay19NEv80lJgCsNNiQ2oLxKfFojABdJZMu2IWg1kLT06S8wG5DTJ94Bwuk/1NpIA0aP9bzFlQRi/50tCUC983KShPBH/udAPdlJ/YgT+fPEgEkkya4afvj8q1sJJ+CznBNiCEmSpEQogP38qQ7hBTDMRlJRzp9mEQbkHv2fAAAgBwQACFDuAMANBAAhhIAbbzirLUXOiICG30BEZAPa30yRYqQYoSXPk7biDvNj7SlO6tgufEQryAm45xYLYR7hLAULWXQWixt0MKK16FAdKOq2SghR5FZSRyBAbNtGkORITv9F78z9/94XEBETkMw/nMyFH0Ae8C1kZjKqtKRV11XZXV12cVmG3ffMY27bw3W13pfdV53VXdtabvjz3d0hSYZrEpiBGeASuCHQpgiwKFd5qrhgEgRFcwCdYeDSudXtEY+Nv97EZ1Xb4jOp9Q4XXW27F7s/2Zup9dpWtbZ+zlHZJ9ddrgLDMaCQJDMzNJmZSefjJDvDHFXXXVuP1LQV1VIhSZvzI7nkR5n7g6q2N709sU2fybwXMdklcvK2IhbaJE1eVSv75FRcReWp7QIlXaQtr1ClPj/wpPhxdT2+R3VPva26VuseVA59B4WwgOICLAGUT4UVCvISldZfXDzursK8/bG/40Vt2/d1pUXcOdLD4jKZb/VZfF72oDJfrK6iuz3N7I1v2qqrbG5p8lVJMklmYGaSyXEyMwMzfEGYZD7MZP7HZKjctjVHbo7kt3rdzB8UVGZBQcGGBQv6Jxg2NDQ0DAw0DAxs2LChYUHPFnyZb7yeVaCHzAOMiAmgI0myHbjJBiEGjqej0tQRaPIoNBEhLMZ4D79d8sGV3EiSI0mWOUtSrN2Ra4+fUPdiGt1zSE8kxUaSHEmSZSxLoY/fCV3474mKCfDiWts2SZK2rTSdCh3whAYNJgyYsGANp4fVsIaQMGHChA4NXqB+DpUuWf93R8/Ak2Pbsm1JkkT/YDJjNvuAS9ystEnMIhOCJYcpN7Zt22rqHU2h2XTI/CEsNx3SFFo+xARomW3rcbXt3dSqrw5YwGE7b3jBCzZs2LChoKCgoOCBggcKCgrKWc4NG7bzBS94OW/nDb6wynXqc6Kj2rZtW2k8VjDCXVz/7vAVydAi7bAjC6Hc2LZrWyl97cbEn5B+k5A8nLBoEpKHIbSFIr1s2163tm1bL6i1trf14wcFBQUFDQ0NDQMDAwMDCyywwMDAwEBDQ0NBQcGvn79+fkH+QT/gkFvbtms1cwzcDinphpQEsjdUWSpryY6YAJrT/2mS5EF9ojfhC/Pyw8TCwsLCxsbBxsHFxcHBwcXFw8bFxsbGxsLEvPdfXOzLNzYyho6OY9uubaX0tIOFadAPN/42Cc/Uk/m7OYQeFv42h3AFR0+UHElyZDv2H3qR/1Meh8ui7iN9/QPEE30kaib1O1IuCg+RRyoqrAL9qqBNAEheACiq39ASAAzaMrgYqiZeNgDsAFAXgKrFmwUACv7nH6JAgVCCq3ZCtQ/CBLbyDVgAElCXAgABwKDlYvQ7qrvDL+8AwBuggkIIoSnTadWgDZ2A42t20HLRt8BFfwYbWgEA4Qp2diawAwS0CZzldsZ/6wMIjgt6FEXRVAVAMigAKEgAKAAQ9BncqcACwADgAlAABlDQEswtACiuBGBaQHomqiABwAIXAOkADADu8PVQsZ1cEz0nYf6WZ/Dq3RypvoMnR+wJDoDYD2A/TVmWkkZ3VNkSZYf3UhCAP1PT9wDr/ZWD1f4xsCxY83cJBdEn7M3KawFCse7PTQcFT+7jxgZgT3Ce4HTYDqehKCEggYVLBQAWdGMB4wqnww5fKAUo1VDQ40d3tIzis3JYXPf5/HhArFxSAAx++vd/vFdlsJhHuw6AAkC93Y4NTAFAAAAE4CACg+2ri+rl8TwAJEDCiu/BCKRA6BsKRAkBAvfAEkDAn/44EKttFd/AL4AACjaESSACACFAEAAwXICNABgQIIxgA0BhBCUjiCQRraA+Pz/spSr2mXtNutcj3XRLUIKQDG0aMDDD4/lAAdYBUJYCrCxAe0AwlLL5xlvZCjw8q/M6r/M679hgHjsrATo6LzkFS4UAo5AoQRlEg61bKANBDIR8EC0lWCNgHJAEIAAQi1MxSwhGCIEfbdGMIPEEyRUEEPCLSISDAAFwHQICIkrd2MBUgI/RAMAASWZJAMEtokrBrw+/MbqrW7tXNQEGAIM5AcrK3CEGACQkOplZymEBsLLv54CijcZFTY0nI4vHHzC8xcQOen5vmm/3/MxPZkruJCBmcMbZ62lV4AIiJIktxICiXPYILGAgJklcaTX37cFZMzAISgCsiAyUqiEANDM+goCECECSAFGMOJSXsQ9vffG2bvXGjaGiWBBQjECCIAKLNgAc1As59nu4nRcLJXogAsDgfyUYJQufkj8VgP97zC7A+xnBi3A4SoPR+GXxdGsNz8MqJwkqGKPjgw8QJDeMtuIBKCZLlPuw+oMzz3ozD9ovCtsfZXOBElGImvNN1uCKzO2E2ZA6zGhP67e0M8/HE1FlwZzwARMr6zgxzkzhO0sIxkyxBi1DRNs3td6m9LLNNm3EoKEMMzGLK9+3JwyioZk5vE21rK/O7/ypXoQibl5JMiuT/AFePNsJhFgHv39/YZ7Hz395vHx82+j7ubRgtClobvxp9+dXH7ox9CJJLAc7g0Fh5E1jp7ApLZRYgNXEzixZrcv5MVm6YO7EwWmrgtleKiFOgG2QANPSC2YunChU1o2WjDG7zo8mWs3MQYyFQqDpmaZm2s44Qi51EQwdFuI4juiQG+WriNFmScOZiLpt1H/bwQDQtkHRYS+KTpyyUFTt/E9GMuy8gV5vwMq51gRarjgYAsS4tk8UPB0ET7d3V3Q7tRd7la1E6a92esfYAZpYIAeALBihBDHSlGyogqrEDox5W+020bWaNgYj4cir0j6dTYQIwWCTzZtt08sQO2JhnkbW2cNvmxAOtwe9oELgJI0rycS2sQygCCWgY0EAEfgUggwaoyTM0vEhjZmzDRJgJQxQOW3iX3Ci4pyASbMdBACMkh24ZsCcOHFeLiDTKAZIIjxIyEjQ2Z0Je3E7+eXX8fc/hbFDgcGLY4zC4ME+2IAABqaESyHOpRO8Y5sY3FRyG3OMPe2z0DUClBIEYzV417sMQzydIadUq24nOC0lA/DedmIzRCcJlhCykWoExIxIYAGagG0TciOcbUcFDBFTxuhwptmUkNyAAGIHFDlkIKQwaGf4vLDztAnDMTvI5EJPplydVlmCICFxUg+SdFlX6v1RP/zovUi4P0IxdNyksgXGBHE6vYRNHY9BSgAMePlkQPOW/ePtB2yTWlW2tEmFCXyUx8lclBCVAZgxZoATpJXNMshw7px1BkyUgDL60ubpw0FI2dcG0EgkMpM8SU6B1REFaZBhRTGwbaqcgQOOrDFYuBegHPDEtdJovHmSNslMyC8TBc5SyaDNVif5LUGOXn7nRcAnxA1YjmeBm6CfZg4nZPXcKh0YtOEvQKv1En8W5cQN8s3Cxk3FDnoWrXUGGlcMYMvMdlYh+Fp3a3Hsw9IZhaEMUh6zc3Ldtd2TQ+jM9jNIjqzlktmetiHdbeYmQaac24diF84cvFggnZM9sFpwUiUWALjyskS1b6jTWNt0bARY+rNnLlRgTWamwcydbZhfYFNinLed2VTswkHKjVQaR/0UZt7Ei7PcGm9WLjif+t68lhlpcGs8OCEkLxxPPo/tXBFUeYan2wEUCu9AYUMDfM9/tyGMhAvmEGIOXDCgYMAFk9gNKBhG4HkAzIG7trhgoJAl03CQoAxzOMhDpwB2Q2BoAATc6aqqAjaQAA53kwcPQoHnA8UOZqpVaxIAqgGodqYg4FKCBy8ssBwbWNeErDAPSwEn+8g1YWps82Pbi9sKC1exB3YVVYho3LScOxQZQEgS0EiS2caFUGAsBiBt3/zQIYYyJIoZ4A3oFdtCYWTgA6Imdmw7Uzim0BCaSpoAA6UOGUk2VeIZcmTaCBk4rD5zDg3gfF2ync4ESHwbIQVuI122TXW14MFWYN8mXGmdKjcS7Fh9Z4EbmAEFAHMxr652LjBQrs0rgvDBhWwSTzZcIEgu5SqEbMP7GNjcKZe/eACEgHKZmIMCAJcSCgIMQkDByfYjdgig3GQIGAZMCLGjTW0HWtsB4sINtE5AeUceMAcgcy6Xw3K5D6QGHw3398AFCCfgPMDtcAAQDfGyLcLGjlE31Yqq4upiD/BUvAUwAABhSIgCgRAAAP4XAkA4BJqKYLj1vNNjA0fTURxuYgN0EkMIQ9EwHFE4U/htChgBzJCMCEFgKGw9pogGIQkBMCgPR4BfGKMxcEDIOQw4ZKiNy9fbBhs7sBxCgAIkbIZKDApWmJ0UMaiCTgcEBKaEglCUILcj8WQGcC4PD1pr2qpQQIAwAQzDAAANn0E4eHwQgBBwIeDuySg8AEBSFFEb/+3l8gAg8PQ+e3h3gGRw1Nzhf3kBMAyXoeCCqTOx68Z9Vy8Yxg3AB+5tMCIkQbQRQBf8ntF2DzdoGABui4BfF/yBD0CB3kgA3kgM8YWgYOC6cIiChEDajCBiZQP+G2l/xjUpAhhECMLgXEASbF5unF8Vk1Da7/XrAAG+nC9+AXAAMEvJSsWGfB0kASbxCy+Q0BLhgISQgFhkCcLt9wI6Ry4gGgRDfi8AYJQQAYFgiVAZhiOGA8AwyB6J4XMET3ywy+2/CSnK8O1jGyC4arPisLFSLqWgFIyMl6sCj8ellIIygoKAYrtcgF3EZlQOuAA35g4bG+vs9gTwBDWEonZTR4/AXQF877fnCQWAzgx27tuoGIDrRsA9wO2J+IV8OQAkaa/Dgy9+EQDDwH08A+EKygIQTCASpQB6E/pXCQEYhoFDKlWNYeKbP9zclSijGYgREAGoaTNU2nY4QJQJz5Mk22kzoYE5NyQF2aplGYAQBdQQLcimMYSy/PU0JhDUveMmGSa5DsuhLIAQtC8BFjcZYYEvEGgBCAEqDAOYyIEyF0EAoiM2IoJtA6FgAAzQ+DAaAABKwzmGwCXAeADA4ALCkkGgiWiCAHH1csEwVDEOmdtcLtm0MADjEG0ycmJkwJpuTcO9m2S43O/98Hjg+YAnHSAAIQDbx/nez/PgTwF/BhIC6vOFoIJQIAT0K/8gcFWM6MQQ6n4BgQjILOFKB6IA6Bym3h+feEL2CKAEyEwA4spSCnyaDJUHQ0HA3BU1FINSwrhjHeACPAnjjGUH+evn8ZNvj+tvCY9ACUBhq4c1HMWXC4hACRaJzQqFS3VCAUCx+msdYx0qMVAuKGGAgGB0CwoosBFwD/j/1YBDmAQKhgEAAiAsAaYEsEQK4ZbwY5oiAaMbHIB7bABuOwdoCyASBEkS6KhgGCZQezcAXPD/G5TAN4RHE0EAEIkBoBBDCrt8+MD3ARjiewCAMCASIwCIAEAhFiIDDt2EQixDtRPcggzJe/KeILhgSQAAOkiYEx5eSWW8+LcfgIB7B2QGrJU5CMCzQge1HhuskJw//Q8w4B4x3DNcAA4ASkaBXxDCoAJObIAgoVvbQEx5wEQWoMCmDVUw/H9LGMmtgQAbLQdYlO20WFA7ys0RAbCNJh0KSoKNJYRBUCBJmCYsjAdxQ0FIa1pAQIHJMAHguMDxUkr53vmue+xIfO+NSwjVgkQCqNZJIHGKEgDIM5jKmQsrkyqrorW3FhOJNlYAAleAcfUZ4Zs3fMENuTSEEf2RkQIKY5kLlYxqaVkAwFDwKnzhCuzcgB8fWF4kHUMAgswsGAcMF/WccHgDlIJoCQ/uwZPvLJWwitOmnSGjOsMFgwAuOQUlhENgyy+sdhrUbAYSMDPOOUsUsCysVpiBHK18s+nys/082i/70qXKGAz2+90EVcy75XBAp0yWNmfnqGn9THlrx7At1OM4psGCIYiKlW1MlZHcOx2n3d2F6XSyJx0AcCRsu/qk/BfbaWdOrFQmTpyodvQzh0MBgAGga4ANAKoB0ASA6XBGScvAeY+UsEw3Vs6cIGeLzOrljNm+9s0EYP0NkQZ2648EgHCTtkVdHAIAAqDhEJxzzhgAIYQmLARjIIRaOIFiCoAAFGeN5BfhrEMAIUAQpWB8MCoTDiAcQBTA+HbRD0aCAqQyEwwCIQgiOADkFAIDUEQAZLZbTQAxaUnyrmVbfYT35tfqVwvYWWfhnuTOXS4CBLjksq1czWrlwsw3xVtdrUxumGkZ3oAbr3Hq9mRlmpaNKwgAxyyoYjpytssmBBGk8MM3k77tqHlmyE5ydaBPxUnypZnd7CGUkIAFgzB9TrwxFp7MdmMxMs83s50ZkAVthh5LyMAwBISRQpcAojAAhEMAAIIAYkE0AhAjEU5hMJhZeEJDGNwVhB8DETY02GuzpBOONUMgEJe7UyMFmFZRuYvH+/VOqtV0DdxVy5mBZDchTi2soddBJxWHceaeBWJz5kolZ+ZmFUDWubCSmIsFARJm5+2KARbukJ03E2cOiPPNN2emzVn55spBsCJoPwWR34NYncnqM3BOOMEGZ4W8WDGM1GyCBmTaGvvWAOBDGX3ZntSJBmYAOo54A3Zmlg1IJpM4LOvIXkmXGNN1eDdd0yRN+kYSFaPSktI2YiOchsFRKtLHltxmM3TZBYIxgixjYUJqZCIxB06zqWZPjTkkJtQ3XDcU4oCj3jNtVbIEcAObQgcNZecNteCwdmebvqwoBDsngkxekmKdLuYKU2aCnPmeAiBAkJXrGCM7yYVkB5zGUHZezNwmstTu3eN5QmDlHiLBJsM0IDKDQxDO2KziDiVrWLRWCfDOizuuzMOlbJeZIhmyC4BQULANGgMwMZEzT4WZWJmZaoYYhbLNTJyZqQoy6P3MGKvOcZDKQmfGx7nHwRjEAShpqTOOphBIBqbzdQkgrPqzUU6ZNaBJU1uHVBRCyHeZEN7LSjpJlAqJgAxH7cRADAQBsGciMxqOSRCBgiozBwNkYiVpe0dD52SbVSRGstCVY4oxEuOgDmnjVilDDoj5ohOGIkASTMyEvQozzZODlXCYVOJMR9Bl360AMAI6PtAwCmBMtGAwlEdM0Gk2YRgXgVRJls3AgKHYR1UF45hBuko7B9R8b7RBggBQOfGmYjNiVMSBUmYgCPH4fAf/tRrugclEkqjSgAjywQwg6GWNxgItl+y3XdyP+3WPm2+7XmLki1sMh86nEw7VoOIQUnEGT3oqPthAoQJebBU4MwmZqV7uBAsz4MyAnKDxZqGy5xA2lbHx4p3OsMHOk5k1PwQXfgYAA4htAwMbJzS2sJl5fSf1ZCcAxtUcAQwUgISPQXJg6JRyxGzDR+AzUusDeNDQ9nWuhiAAJKmBDkwyyfXfHIJAg8AtISJgZlNFNEQABHAGpsJSsT0oCMmCv/gTMGAHtKQLIKj7JoAJwRhXEM0g9aICAAy/xrMLVmM6CREAyAQgLCFhYMyvVmYCx1YlHkySg0VIwXA+7OS0JFYF6F2JgXuTwag2zilOAyzzTicIbGoGO1OeVIFSGO4VRupNswIJ3lQZJhIYCTmYYCRGY+MEAUGSAGqIjHacMBmSsFLSWhCDNgIKCz6DwPCtfraJVINAVGxIH7HxVtjMzuCHh02CJJ2LqrkICBqdBBGxleKGnCVrgGDQaBSMJOfbXrUPEEIIRANAkoCCJ0gzSBKQUgYAuamcNPaPa1ff3asLi7e/PyQDsUyHWGRikzHj2wqQBAfIdp5mGtusIw/rG0WIAQAFIyQI2Kfe1dAQEDiCCBrUACcFIz5ORiDcBBF7fUzBBB+bqHQko04IIEkCVjCIoGAYT6M8MwbFb6wxAAwGhjaoWADzDZA4MZEMeuUUxErdnoLDiVTJWJk0YGPqW6+gjhMQJtAGEWNmp7EEiIxT0gANmwmhjROC+UFQUWXSykqlStXBVAoJaZBEkAucKpEIYNy4enDLDLSy+WTQLbw60bbKgs7EFMxqDqK5srPXNGmaUh3jvC1MZFoICAYnhFOYoGVdclWOn1tYUqnUucQma2XaTmjAirTbYGblzJvO9zhFZX4dRgBuK8BpJXNjwMbQt7nuTI0jZBiVlKi4zTURRHfbaq/Ve3tfQJxtgBPMs/LQYVfeLLrgwAAhVdVWzlYoLFCJM9vEQiE5QllCSeB0wkwocQ40EyBIRNuSqwlqotsxwS9fBVwLmmSZJWXAhHJgZoc7d2O+wO7A1lSJLwcMwGVGfZJT7bIFu1yrYvGIzFwxGgAQl1w0kg0w0wEFYrWNMyGRoY0zM9KR57Mp2PDRIBwiKLdKciAckRQ6JyYaiSCe9gBRCqB+EE0JnII2kMyjJCRIqokMzpUln7JwBmReBNeZcc2BnJKDHenrp/ui6qZNARQBTqGzoZq3NwPbqsgwTq8TJHnRZiFDGoJ0AoE4kyaNAlYgiSWxFFDYHFMji0TlhqCadToToJFQGmI4CagAMDCcTmNF1oQxGAmbAYO4GbKZ0K2Z+YfBawIMNLCd2YQxsdngxosyAWF9uQkQYGGAmoYqUBifgDgWGHJhIhgUdiSuUXAyOUklGDgBqMRWGHQANmDAEsOEcMssiD4gFI2rzuDgDhDGAAFI0JmYtp0Emhl0CnldKgtEpdHpEYCGLhkMhLNsrs5BJzAKZJjL+WAsdDqj5u1SY0Y09klys1AzGw1RqRw4A8NJnEElURUSgBJ+0Jfb5m53nvpw8CBjZhW8kE3DQe6+fgui8RObF5rBO5w7GruBzxn3PO341dvVddZ2YkXBSOdnAIEaG/eaNtghMQwUC17TKQSf+DwZgAfcWCEYyctX15vrNZ4VvAxAAADjXrHBBo+N6mb22BLDv9K2hHFU4otfRPJTeuaYgTeFCiZbJ3A6SAJKDJOBwvYa4h/GVjq7886bjderp6iZjbEzsM3KGNg86KQBkduLG0DCfLjYbkjmk2+edJLEydMwkewUNoeXTwcVhzwTUzA+GLZFGRukEhEqERx8c7DbjSe3IR5SOECWNB8EHGTumwhJaKaDljYTpp0I4Th3N3ed8x1JxAiA3MvTMSXOwVFlHGMn+cskezYZFZ9nBLDN5vOJqQC3XHHn8Rl8GGAsOwOngHnGcERnYqOYQbgFlB8EtA2Cbr+Q4F3cyBth+rUryEi4NoiMHkQPwdFCicOJD3TC8lU7gcNRLKW2eh0Kwpvl3R5QXQ7dJIcbbdwtnaCNBL6tY8B7Ym/KcrjBHSslaGuh0GzKnFrcFWhrX3S+NpDExBwr4qLC21pfhKUYq3U5xhwDTehM2dqGWmi0WHnzu7LybltvDlgOpW2ALRTMDFFsG/SCoRWyoVXCEzycyk3nbonZwNVQCs1lJHqymt93aQlhEIAAAA8Agj6DRy3wsMznT1Z5Swzb9tvvN7/ZCACwJ23/tgL2XwdQbsgxOIAjEhgNqMoIkTOEpLiFcimUAB4Q5aIgGU9KbnmFpZQSChBKQMGgtV0u5eOd3QgKLS1AAtQwJVy+LQyDMu5KKSiXm8MFqM0pSe6dBCXM3QTg7grkKDbCWF0pN1QJq9J7Qjjg4xQs4AIUBFvbtSK5qFA9bSJ63dVJ/vk8TSAoQ8DlEopxYYKQxpvOcEEJAUVm3E9mXZ9YDYO5UsIFk0UBnJ+vkj1zadwvgsNLs4BPv/UBEungY2xEaf7yzrt8AwD/hsfD+8EGdzPitwsUYIBywZLK3Nnf1jESZMevGMEDYgAOECmFIgNAdZZSlkMKnQWHpQy4DCgFZaEUpQjAoIQLQKABiAaf4eH5gFAQSijDBcuxmwyZBriLQFCCQJR7UONQAsrCfjIxgwsIsHZAaGWKh3NlwKVQDEBWeQBcHgBkxgBAHARLAYaAAjy5aBZI5ncNl5JUSdDhkBJsXGrzYHCd+3xyRdjVKnqgEfwNn9JQBDYBTFAMBWAEVTxlAATwaBc8ogABw22RAqAAEwgwN6ftNhJKOLqwQkERDiHUSmxpJf6Xqix3AJhDreBdquauCT7gglJQwnABSuCAgAoHsGk0TlhCOG3BhFNS8wGAz0XMQXXtENAabgzOMFwuk6AAKDXgghLKIoAgwhAABUspoUjKi0RowFYwl4bLBwCACFFGO5cskgj+EzsohCMA/kRw8c+nAIZnKjxPaKTKEEmKe0xGIAyhgj/8vgCAEj6MgAEAyc0ZkAlcMCz5AoYyatEMABwhAlDIjQSoyoQDMA4FsgJGBCAi/P6Lh2+AgN7eQAwGCBACQ06hxiBJomKxvlzoT+9/f/D/BUABHkEydwAAZwwAcC8e4J57524IoCiQQZR0FMgYsiiVaKOAHoEKQhTuDDZaARQ9rgcWf0VLwAY9RU/hUypzXe1Wnm6NEwkRY/uuOic+CILPEXoBIBiKGgBGGGDUcp4ch98AQALQkpWrnbmaVZiTwYwNVTYADlL3uswkUgBkqxPpDKHlYAmABAEmAEAqDBClAKVOfHPLGYdwEwAIBAhCSIQMuEBSMxqJRQ4YIJkEBzC4Gaxq9tJRNssmhSyj5bRlca0oFOa6hREGEyfENVVh/RUA94FF0cef5TUfFYwRDaiIRAiOEcRwAAGgMuEQlWPUMGYBYwaCwsvYSEzR+AhkhKk4CsEojgCJsBKaw0QZjxAoISSFEYkUCbnNkwLElvS4AsVGvi0sGAWEJMAw6gBSmccGFE5VATMz1wyH3EkuUFSQAZWZX3QpQwBetsyMo305zPmkuNg1HaxWgxnbehiWZcQhHMKEyugaEIAlKIobK8Qb/BUMgn7bCP6sh12QkWM8PmGFTg7YbdI+gAACjBNnZvoxx0vUyFAcDrumatopQPhac7J2tzNLTGnDIjt7GFDBbHjquIWafUb5sNFQrYVysMlBKrMt4zVPy93zBhRC9TA7ucy7W7nkTEWRgWFL+gyIbQtXLlZjrDxTDVy5ab1svhQBppokpNp5u/Ev9qIwHJY/8+BBm/Z+8rCd6ZH7IPD0UtyY+ax9e7HslwbFVSMq+D1khGlVIPANPoki+PyWoCCKwMTnEDDTCufYsSKrCh2MBADIb7z8BnBmksyGCJxCic22XdJFdoZVPRhRTFOpQCTBUILlzIg4EnImiQAABDkKLC23KLqdOWo8VqK4nWtGW0I67KEzw0vazIeKE1ioKqwl0wZqFT7smmahZGSTIFc+DPoIS8pIDgRJjIqxiqWpijiLadVCwuEMmGZesp27oAMYmGSyqopNA4CBhjHEHFO3By1esamebCgMSADS33gFUCIJwIwMjEIyqmxDDvSNcbIXw+d6JXFGYpwMKGgbPOlmojXudIgQABsIw6XI010yzZFjM4htQd+I06m4IGG324ElGGZkgIXI3vNdwYKzs8epatwOjbaDdR4RnIQgOMCoxMAEGwNWypyvjRAjDN3gQjabRyPNABcDgJNKQmdgswHyiJUeMREG6L/BzUh8JogzrCOMiYkpmhBKSYpAPsCZ4WwR65g6VNp9K2Xbk2yWBYwTAMbKNBoWyKwqZpRqNgCVamW8cisfEGZVGABQjZEtVGYAMKtERS6cllAYiJBxoId3YIhhm5MkExMiMGJulOy5MCQ7puGB0mC+AcMpoA4KIL4AItjbHMhIMEN70hLJzBNNpDBDs3lqoCqMDPd2CNjACNNKKitnlqmUmXBcTrViE56CgmJmBOFgziSfSS50M8U2EkAf3lveWp6PTIygnWUKHd+qTnOiYlQmDGPOXBMTRtzlHmQXV9ACTlupYAPcER8GziLJpDqZ10jrOJGA5YmFM3MrY6dzZqHXZsY8K40P123RsEd1jIQ4N812Yk7Rsk18ATw+KDHYmVVZASaARisLM7irqm412cCignC2MkWbR2isGOMnvxDAoGtm9Vdqy0HMTAE3JevhFnl49LjS6KTr2PIGY17kxYyKCCiBwE6kiE+jJDWV7GBJQQyesyUAYRDYeGdnhzQMiw/ZEaJAhpJ7ffQMC94x5WOQcjgU0GuYTaMWSo6dtg1mXrzn9+rM+AwOAs55kmx5cDBse9r9hbfhcpOh/MZhCLshC7RqWMfLIR97J9p1q2G9aLN86d3jJ8rmYohGgJgMAlA4hGojy+HWMC8OTx47FC3a2ELRYwumzRya0ZsBIH8FoQCYKYHTaUVgDrTjmLBFPTtPGkm5DGTwmjcNV7dGAAxxAByyQ6Gx7u4IG2oKM5anLe5ymg0YipRnrmwb8nuAUDCQAHDL//789O9fgLy2p54M6Onldw6Adrh8cffSdcEMxIqGA0KYhMAgrBQ5kGKMbzJcIIBXDuZuuEAC2M3YEnAIo4NQAIQSCghshgAjEPcIQ2B8Mn/qAxAECOjLYZPZAG6kFJQEGCQhiuEZJA4YB+UIRwAARhEYpry1aL+6ggGCmW+LAAIGLQXX8wsg5IDlIBEnEQAoH58wuHOHYgREEmfa6sBuKBFDbii0SlwtlGNELggAAr+MFyUAjBwkh5ai4EIwOBgGWEg4hFAKCABQAkjCQRIbIIjQZpVmBklIGkJCCMwBiYAVxiDCAYFhwEaBBYFMCAY2fv6Q61JLNwJAUofxZSwwjCkJJVQgIwFpu1WXxCQIBQMjcwBcJlIkRAIhe6LQ1n4kaQrGJSkLHBuyW9UgAShCElcMiA2zaEhfuEAYiGYUPmIkATgUBgQwYzgXoiWEEg4EAQCBAZzzhTDFYDDY+bW/7EooQYJsQIhhAygauHz7RW2JAABoSBLAoNAAABoMwBAAAApu5w1KOO0AXGCwMAASAwg3hd6PIIkjwMLCCThse0Ao48IhUogClBIKYAgEXEoQBMoAICDCKv+FA5Fvvv0HobdwCAFAUQBhDIADkFK2RSXCxqsjwO/hL8MDgOCOz7GAB1A4HApCp2ImExKdyzMkQK2UEgLQBrAJYIA/BHDzIgqKAOIIR1zwvGUxEE1A1AmV3DgEsrHBMMlSgAQAVmJIICUHIqUs5brmQpDQEC5lEAWsAEeQ5BeSCHEGAgEA9Wgk0W4oKvA5AEGIKFSBFCZABISBgSAQYgKFhgUcpsiGhABkAA4YSikqI+tkLUJabJgBg4PLBTBAy6ZDA1yAQehgmOXziSpnlESSsVYNC1QpExdmzpw2BAgjYZk5HFgCGwAXBpGm3m2gZJVbzo3KAW1ITFphZQGAUAiRzXZhBaH9YYiPSAC6RQEgoHQ7pD1bWFi1DCIIBABkxWTIQAAxoPnRG9YQEO6pzwFHYyThj9h1WBYlATgH4IPYaRUkQiSrOADMzB0AsmpovgECxpImlyEKtnOmLVHOzel0SgnBiKlFGMWKDkYWhdHAHOVQJjEyJHVrTHnlhfcruJdtc564GR4RAxyHRdkUqDSRAGZ2Dlyx+WbKIG41mWott1OVJGaTZjqIqgBBtVsuAEdmxU345qWyra4+CaXmxELabCG87a/yqhfFKdgAAlbehEQrQhewqsOP3i0rW3nRQcBrn98tnnYAmpT79BvlxbwycAZMEAjPtP+sDT99wMSER701tgS4gCcX5j7WfFE04M1YhI2IYKfVoOGkusfJ5UlIQUBSZNADVpKOKDQK4E3hjPQmVbhTCxXQBIPgqAOn1KJqUZGkMAdxuwVDdh02q6BTsQEC6TTu6vZmrkBUTEiBBDcuCOdaIdK2nTDER5nLZhxBFlTXrDgyASwnbtt1qk1c68yEOMN0NsSZZIfUmRhsGLMWrMYGgqiJIwvfudg1hxmzoV5T645o2veAicZJcZLsQ2FVkDq0GdTdxTgnfrixz25TrdsJkFrULPQh7ErRjwUzq2QfxsKUQy0En42TnNk44ABOwm18DzhkE4I2EZsgx6kISDSZkRqbncaTGRDKPx+QNesEYZNOoLDtW6emgjEtCJFmZE0SzAg4JQmSOaLjNpAWzDgBQWHIBGzIQSfsPrWO+cSYAZMhhLbOSgE4FbyYYFkmVmhkZcDJ+GQ6oJM4BYMkzgSpVAQZVILCfRYsUZWCZQLzSJAQilY0JonYGKlCCqNpxde2wiTAwfah1ZkLZwrC6NF8+NiZmYfAjcnEVmMhA0kiBCDS8BALBso9/AClkIMk0gkSw2Jj1VUphvrZbO6SXZjh5CDcAxMx82iJtFBBNc4RQhbp7OVzUeHl0byiJi4XYMhMA20uovpDaEABhWEIQ2urnTcHshtFb3JOOejcgmlh9SRChJD2l63xw4uAvPUGiJbGkpnGQBgEScoYhuq57fR+G1Y3CWYcLNvHruaqWyvfCh99aFMgsqCCMrotcGewE9tUEzJWMhhx8OJZfbNcmccpgIMXE+STZao9qmwPIDEYC+AZ9qBTQdIeTDJAGjAAgMUdJJtGUTAVkZFRpmbAQLBRn5kxjLcsNapYEUALNbRVKlJGRbQNtFEFw8VyXclMMglAAewxDYhwhNTsmIVTEgQcgIggenYJ53FVXWyvAxugdDoCENQ62iQQwEgSEoAAVIwBCQiJMQgsNEqCJRVZUgi7bB/uzLF6etwMBACak3SlJYOVJhX6RkWZCvY5hioNIAQ2VrGVZBQwA3c7qfDDyWbuuH5oGdNtLChsixYunEVmZpE8n1dOzHYCWyjhUFho9Ahi3BA/iCvOZs7gOY4BOVZufM92zzLuApF8a50na3w6WX1bjRMURjAg5qG42usrZYBhLJAHI9fNCAuSBWOwDYNLWYI3P9QQT9tTLLt3tVo3lijlW9kqTgUkoLLNrPywYnInFwOZmVhIggmQbHJEyFM2xx7URqPWjWVswDe3V30p2BDDC2jOdmWvsV2smbOrYUYCMVNYyaCKQpSJlZMBB3BmGQsH5BWMM1R5s5Z3GACEABRjQIwAAMVJ0WgEJgREAAQRCIzwjDEGRFPSzP3mDGsQio1p1rynw4MHpm+dyAAQUmpbc2yiZL5BPRmMMJq5gIYTwDBMZbcypEMqonPiQwazA/q0nWLXTGUdb36MvAz1UZ+UaBzbTNBmIIwAh2c22maQgx0ZBzogIJUDUhgZgJF0DrswjaQx6IU6YE0UOo0hIwCdLFVsRpIsanS7ID4YA9ItWUKHIoHMa2hjx9QsSB0kYsOJwhih7ERrYSjDWn3zw4v31nTnQYcaenDTJyhkQxl0EuABG0EZz86GCbi6nbjQqrZwjAAUTOJYbduTV0x8HNWniCdlH6nCbVQijpKsTVbhexFsM3AM0OkpGCP7AINjLGDlsj2n2cGZU9XXnZukwMtIgnBjvfLiIBn2zg2OXrXVnQfdui+fDhtOgjE8GyQj30FyDDK/mV610Xnx4s6bp/fH+6Ez5s1rU71Jjjw36aAUt6i6Gek3M9TYnEcJIgrKmmywIXakjZ/twYs3d4y0QWFbySQzPRbUjEUBdBsME7BB8OvCxKBbbODSFiEJACBOZAxwkgRmfpNH/upVTpSIRA7hlDkYwZbklmN8XWOjDCO2URrLn7k3jRSWjZqQrMMDgJEc4hiDjuHEJH8IccShTJLpNjbxdY53etIBbiABnrSBKSeQcAxYR1nHuHYQCBeJCyAgGWCMUchIlBgk6Tf5PVdJ55YzgCXdG8JPhlDFEJMYCKCtx/n3ZRhjsxgxfTNUAFBVjFn0W6RvJKYrEbLATAhXMhyjEBRHY5ESLsI4BHpTEpbcFSAAREghVPgcMcVRFUqwHQ1b2XDG0CQkEQBUmXoSDUCGVLmwDr9/METLr4q/UDCvS18LQjQBwqWUgtaaD1hsa3MjCJi4oQSMJYwy0hbQAAAlLY4eEKDwXzNluBQsOGAppSw4LCWjAMVGQDggAIcUP6BkczOQ3KCwHBAKrgNMrHKPdrc3p7AoHIAoOAyDb/7PANoAKCgI3xgqjAt8nvv8eXnZAqVzUBA8SbAgWzUcJq7TskIAgXxMkngaDh0CBDcxAMAQqwEIA7yK9t6hhoMgIp6zhJCryQQcAFEgJE0wBgbICBBHS+kBhiHtvStLKGUx+Cfh71yWC1BDoAiltpTlUAJCKSYgfgkFwPJm6TcVYYwAFL4IGA4hgIKYUEoIgS0DByTlSSkGAowlIUIEA5CEGLTmrXz2+vzC631k4EkAo4C/Co7ikMpBYVcCEE4QwLCBUhaFYABkDGAPodAQSgGCFwoKT4gkA6UUtaGVU1jaSgKUyh0AEYkZFEbWlhAmeXxvuXQLAWXBARcAl8cDZYkyHBAAIFoLN7mgmxbYgARLKaXgUOkIIMJIlgKMOCgYM+roEAoJpQgCyUIpIAEzFonLU3lpePIky7LsWTAv43O4gN5GKYXiglFkYsurDveEsu2ZsCSCpHkVSrnhcKnJPFwiTBAzUFBSHYYnoYQeW2sZgSAwQFhIGyGgMAAGAAHNtyiZI46WUgDE0pZaLBSsBixLQQmdVqFrANqGbiMoieIOIZUlCMfQw9PKUbYYEOYLYArbKRrkDqeizBmZGMIBy6FjJIDjrkRjsW9/ScYC1Pxs9zxqHfLgR/ftbNPceXIeWKHVIBgAQOIQTppBpXsR8gKIrx2QOCCwCaymds/DHrUgAOCggLEgEMZJsAmbxQoJIAAvwIAkESbIoJ2J+myJQSUEwCBGxUmCIEEo7802BQgj5Aig+ARG4ICEACDIDIEM8MGhcHZ4aQzKgrhiIyDxSpC2hG7LIe12AEADBp0kVqLDmIYNy0plBSBIULAqyWTSTBZdGWWZXrU0OyvbDBtK3KoOAMmYIGGJTzfapJliLttUFyIfwMVO22mzARM2ieFUKni1VHyMBWzgD/lyULet5o10bGABHEhmqwLUfOpIJQghaIlSbFISNaZS6TScGqIZTCRBwadSwBBi4cAaFZ1rZUHimemoRJKOYQr7AsB4gTIEjPzv1UlsOp8JA4XBbo2WnQ0RgBh/nlytHpKz7oNzqc04rOesGVto42/ZWTe+Z28GR4Agxmbog203rsx64tu9RhxknVudNX8ZEysFcefMBF8H01gKz0wbDIDkzkpW354YN8iHjZXTJt5VT73OyzhEAOYIcLKLvLb5ZGVm8MK4YdNyzDWdYJ2aeVacfCJWPvIWayyTZ17lmDhZZk4GNe4miDCVkULZgGGnzMjBCKbCbRgAM5hQOhhDRsW/of47PrssyeRw2Bx0EqlnWZmc1wZMr23mxLt2RxCZNoBUyDg3gFYNGkGHW5J2ZNsedIbTIoxkgvQYHPBGulIQAKBuTPamjCBBUidivKtMmdvnmcqZy+gcMABysUvlbOq5ITAvGneQD33OJMFCoyexGNj4AjOOSELW42NYuqwYLx4QYYALDi/ehBI+DEZe+MxsOWQSocf0AKAAIqwBA8G5iQmtx1DYLtUm4pBBx5k3m40D20pJWS4ANG8deEYdWF4/d814d+qbAocZE3OtSN/6jAjS2XlO4Bgb6euRkABAW1qob5UJ1LaBGcPYqJw3TctnxoQA/F7KqA+QwGBajDc7QUAsgzPkBUlAwfCM+dC3NTPNRgwQGJMAYR4AEUhIBGPnr/MvOsYpRmGkI3zqOAWYEGAEGhCxnSUHE1N5NgCYlWzp28LCRt9oMiBMTlBYmFkY23i93vC6+UaU1tawaTCXLZmYKJtTKThOkBgzDuGA33uBM0GyDuRZS3aMKKybkQDOgvGsBd0EB5voxsB69gkaBSQRQWfFeOM4gDQGMwvkw4ZIgDPzJSn+Ibu22cHJ5EboY72xI5ULda5MW8HshCFqFiZmFXUNxQHJKsucwKLxpHLGKq3QmQgODEuZSIMYaYwZOXFmZt5obwrby3J7SWYtjdMUSKuFwloTwFgoBIMTDpAhvw7MjIPtWu/23pzbVvrtlX0WOyVnI0mbALaOu2BTMtUEGBzqTFvqDazKTIQGHYJtykRiKB+Mc7p2G5wpdGBS1g1cLq81Hs2tycVYdteMHYA1nmy86Hz4EBjBmwc9SegEkl2zaTr3VPUcM1EYZnI1qhkATp/PV3lmlRBABi9tvNk4cucAfBTRhqr4BlX2uvCm152dQePDzgsBTlv+K9AQAFfa+YmbYUgjwjbSagMcZD4sDL3bA4LStbOxc2zBQZmkYzypqhBuexGWrLPJt5lgYCOMHGA45MAWBevwKEmksFwfWoSxI7LQe+6i8CAqMRrvvLID6/a0WJHNZgeme/mV8yscdm0cbJTwrLW+tc3DzcAdLqwLmAPgF8DPWgAz+O8Xznqx/oe2BEhdM9ogwsCW7NlBaSsM+7BtAwMoGCiTK2fZ+I2yBJBz8OZEo3ArVexWDKASgF/88OvH118/gQCQwPtUQGLicD4xmL+UEYCARNupBBKgIADlSclws6IZ5YCFJRIz8Z8nIxxJoHo0VI/Ho+CbBzYAherk7gA2QFmqIdk8NBAQUA4Gk+afIW4G83UJmVWOEYkFCgFnCnEjOGTfXVNeb7h8ngfDBQHd1O/68pbH7xwXrxUGgECI2DcfY2uBLwghaAUGiICMJhd6QCKE2Nb2j/8/Jcfzh4coDhx31+aysQMABED1AEC2yN7yhsMYU719REOITCi/9wCvsefPSJMAIMygxAjAQQsWoEoJYB3gdQRcMLl4wzICvo5vOApS2AUZIQnc6oAiQAGA4THgMjDciIwFAEYJIMxgLFOI5mTUwnEZITwCcRRsRAUzviBj44fDGACQTJnASKXCy4PKQAJmGGMAE0UJO9w3hAEwAoMSmHnpmy8X/DpfwAABgAAGUIBxMuESQNHYSBqMwRqDEAIEgS5AEEX1Owh0AcBKdB4EHm4AOLRFjD+8V3CDEiDyZpA4hIABTcoBKpMgVokMAIIKDHQDb5lIRStnTUBEAACAQAwgJwECAqGUCuVMZlBNaWs0yUEwUczY1XB+ERR3fwA+sI7316fhKB9vQpKFCzSwcmECI5yFAsaz1saAVrYLk5HAuXACQ872gmoDXrNCWzlzYqbYQlUBAQUHZjIKjhlNprIAGoM5i4y02ISTmEU6KxLmoIcIANWqNwSU904JVDUBIJEAgA8fjwDsArZQycpSrnlbOXMygTpx22aSykxsuwon1W0ZDlhmpeK4bvoOWIABnt1bT7wb4NjWeNOs8D1XVrAVbnaCRtZcubAyu7nuVEBAIGRKo0JEsFAhgzfMBJHkFH4T/+NkVrVQSVKC7oDWnAIYISE+yWdrRn30lFHxzZKVkK5krhwH9g5SMzGx502m28ETlLKO5WJhFwgQvF4qiUzmaYg7Ixtvo/bJPjJpXspONWh0XQXtYkoGJ0BWeTaCypyq5jJpydx90OiurX+wugVyBtWQwHU2NXFwkBCQEyxcsNfO56VkDCcArWbD5ikixQAU1GK5Yztv5sl8ETEobwCyyKuRE+zzqq4BmLlz4cXMkkwm4sSo2DOo6z3z9jPrpg6lBAx02BhgDG55mcSpc3KxOnvnpPchSFbwdB3GbWbjH0ImyraXKJwo9NeTkcoAqUoypBQJezNREAiKO1wPvn14CWzAlCQEXi1xvBq2Ke850SQqP+a83CI4ExssQDpXDYEFywJI2qYdgwxO0VOrsetmXWU20mJCWHgsNxFt3j78LWZWkoR8SAob95dhaJLAM02nw+QIiGjjoGAoCBe0UQnIq0kKl+3GdcBjrkxcMZ1YEKJRQXFrcO6a5sKThR0FlYllu3Cnbidm1sSJvHzTVaS6BYYkPMam4qZ2sHHjysp5cw4K3xw8WRlxE+/4XLZPGsL5jhn4/xcA4DrvNxVltK7NQGcRHmVnkGDb5iwZzz5C7XRrNMVMKoyV6Ci0pNfOgn+l1HvhZeok+XO2s+FhsWD9et2fXl4ancRok6nVzJIzWOgCXoCGh+fyjaGgT0FejdN58DOJCDYIxRgDNIJGM1Kyg4+eNDPWIaSwdX648+RB5wFQlrfOxbUZe5TxJ/DwUD4FY1YJ5YcHDx3i3b4Neezxp9eeNsWoBeUYhktAGSk67zdsANXgTCgYpHDA1wVLgwxD28gwKUqxhy2AlBoEIEEJJwF0ijU0PSezo10QBFZbI306iW9/eA2zHbpAM3BsOht/gGC0DBSUUoIoyKtJgIuGwWnuAPnVXyEgMWRGQPf3IP/rHAM8GABxSAJsE6RgAN3WEmlMPudmAIwTMj0YxICjfvvy+Z9BkMSMGrj1anxR0DZlqgv6FO/Soljnm/oFCIPgYp3lAICKAdRUccyDz8qDVqygz6IfM205ADGss+jGYKp4hUoBxFw6UNbhFuziNIC5dgEu1gHACAwUBlXOwUJj0JWVJ64fATEAVXCMxgVS/yfOsEFzWQz6G7Ce5Q0L6MuWME/7OgC+Qb/bysHCQaExCoZioB8AuABgHKyMXIbye3WaYxHAQTe04qqR7PsWgBX+lAtY6dxJY0DBSz04aLu405HTiE87juPY/O+ZTdEjtm3igAIoaUIoyhsQVZN9lRSADQKUAqCg67pmAwICgAIFgHBQhACgKMJRAYQAFAfMQSgKACHsIAAIAKQFRQKelIxeBxXcvGH6mglnAIKzIQAhAIjB6SN0OC7OfOaiQAg4qwRAgKSMHlD09E28fcuvXdcV6EePil3CpCgpAKAAygR0i1tdGwAUKE6Eg+IgHBQH4ahAG860AgVGvzsee7AaAA==)

**Figure : UEFI secure boot enablement information from serial log**

The option to enroll with systemd-boot is only available once. This release doesn’t support the reprovisioning and updating of UEFI secure boot keys.

## Hash unsigned images and update DB for image authentication

UEFI secure boot allows image authentication. This authentication is achieved through the hash of images stored in the signature database (dB), even if the images aren’t signed or the certificates in the images aren’t present in the dB.

This process is reserved for content that can’t be signed or altered from its vendor-provided state. If the image hash is available in the database deny (dBX) list, the trust of signed binaries can be removed without having to revoke the corresponding certificates or keys. This is
useful, for example, when dealing with an earlier signed boot loader that’s vulnerable to recent exploits.

It’s redundant to apply a signature and create a dB hash for the same binary. Follow these steps if the image composition doesn’t require any changes, meaning no new keys and certificates are being added or modified in the image, and no UEFI secure boot authentication is needed for the existing images.

You can calculate the hash of images and generate an allowed signature dB file.

### Generate db.auth file for unsigned images

1. Generate a hash of all images to be verified and convert the hash
into an `.esl` file:

hash-to-efi-sig-list <list of efis to be hashed>  <output file name with .esl extension>
        Copy to clipboard
2. Sign the `.esl` hash file with the dB key:

sign-efi-sig-list -k < .key file location > -c < .crt file location > <secure variable name> <Above generated .esl file> <o/p .auth file>
        Copy to clipboard
3. Copy the generated `db.auth` file into the EFI binary and provision
the keys into the device.

For example, on a Linux host machine:

1. Mount the `efi.bin` file to the `<workspace>` directory and create an
`efimountedbin` folder in the `<workspace>` directory.
2. Create a `testkeys` folder in the `<workspace>` directory on the Linux
machine and copy the pre-existing keys to it.
3. Sign the images:

hash-to-efi-sig-list <workspace>/efimountedbin/EFI/BOOT/bootaa64.efi <workspace>/efimountedbin/EFI/Linux/uki.efi mergedhash.esl
        sign-efi-sig-list -k keys db.key -c db.crt db mergedhash.esl db.auth
        Copy to clipboard
4. Copy the `db.auth` file to the `qckeys` folder at `<workspace>/efimountedbin/loader/keys/qckeys`.
5. Follow the dtb signing steps and sign the dtb images to generate a
new `efi.bin` file. For more information, see [Sign images and copy (.auth) key/signed files to EFI partition](https://docs.qualcomm.com/doc/80-70022-11/topic/enable-uefi-secure-boot.html#section-sign-images-copy-auth-key-label).
6. For a Linux host machine on the target:

    1. Erase any existing UEFI secure boot keys and flash the EFI binary
with fastboot.
    2. Provision keys with systemd-boot. For more information,
see [Enable UEFI secure boot from systemd-boot menu](https://docs.qualcomm.com/doc/80-70022-11/topic/enable-uefi-secure-boot.html#section-enable-uefi-secure-boot-from-systemd-boot-menu-label).

Note

All unsigned files are signed with other keys and authenticated with UEFI using this method.

## Next steps

- For chipset feature management and to upgrade the chipset feature packs, see [Install or upgrade SoftSKU feature packs](https://docs.qualcomm.com/doc/80-70022-11/topic/upgrade-qualcomm-wes-feature-pack.html#upgrade-qualcomm-wes-feature-pack).
- To customize memory and SEPolicy, see [Customize secuity services](https://docs.qualcomm.com/doc/80-70022-11/topic/customize.html#customize).
- For common logging and debugging techniques, see [Debug Qualcomm TEE and secure devices](https://docs.qualcomm.com/doc/80-70022-11/topic/debug.html#debug).

Last Published: Apr 14, 2026

[Previous Topic
Enable SELinux](https://docs.qualcomm.com/bundle/publicresource/80-70022-11/topics/enable-selinux.md) [Next Topic
Install or upgrade SoftSKU feature packs](https://docs.qualcomm.com/bundle/publicresource/80-70022-11/topics/upgrade-qualcomm-wes-feature-pack.md)