\r
extern EFI_GUID gEfiAuthenticatedVariableGuid;\r
extern EFI_GUID gEfiSecureBootEnableDisableGuid;\r
+extern EFI_GUID gEfiCertDbGuid;\r
+extern EFI_GUID gEfiCustomModeEnableGuid;\r
\r
///\r
-/// "SecureBootEnable" variable for the Secure boot feature enable/disable.\r
+/// "SecureBootEnable" variable for the Secure Boot feature enable/disable.\r
+/// This variable is used for allowing a physically present user to disable\r
+/// Secure Boot via firmware setup without the possession of PKpriv.\r
///\r
#define EFI_SECURE_BOOT_ENABLE_NAME L"SecureBootEnable"\r
#define SECURE_BOOT_ENABLE 1\r
#define SECURE_BOOT_DISABLE 0\r
\r
-extern EFI_GUID gEfiCustomModeEnableGuid;\r
-\r
///\r
/// "CustomMode" variable for two Secure Boot modes feature: "Custom" and "Standard".\r
/// Standard Secure Boot mode is the default mode as UEFI Spec's description.\r