Copyright
©
2013
congatec
AG
TU87m12
111/114
Note
Use cgutlcmd.exe version 1.5.3 or later.
Built in BIOS recovery is disabled in the congatec BIOS firmware to prevent the BIOS from updating itself due to the user pressing a special key
combination or a corrupt BIOS being detected. congatec considers such a recovery update a security risk because the BIOS internal update
process bypasses the implemented BIOS security explained above.
Only the congatec utility interface to the SMI handler of the BIOS flash update is enabled. Other interfaces to the SMI handler are disabled to
prevent non congatec tools from writing to the BIOS flash. As a result of this restriction, flash utilities supplied by AMI or Intel will not work .
UEFI Secure Boot
Secure Boot is a security standard defined in UEFI specification 2.3.1 that helps prevent malicious software applications and unauthorized
operating systems from loading during system start up process. Without secure boot enabled (not supported or disabled), the computer simply
hands over control to the bootloader without checking whether it is a trusted operating system or malware. With secure boot supported and
enabled, the UEFI firmware starts the bootloader only if the bootloader’s signature has maintained integrity and also if one of the following
conditions is true:
• The bootloader was signed by a trusted authority that is registered in the UEFI database.
• The user has added the bootloader’s digital signature to the UEFI database. The BIOS provides the key management setup sub-menu for
this purpose.
Note
The congatec BIOS by default enables CSM (Compatibility Support Module) and disables secure boot because most of the industrial computers
today boot in legacy (non-UEFI) mode. Since secure boot is only enabled when booting in native UEFI mode, you must therefore disable the
CSM (compatibility support module) in the BIOS setup to enable Secure Boot.
A full description of secure boot is beyond the scope of this users guide. For more information about how secure boot leverages signature
databases and keys, see the secure boot overview in the windows deployment options section of the Microsoft TechNet Library at
http://technet.microsoft.com.
11.7.1.2
Hard Disk Security Features
Hard Disk Security uses the Security Mode feature commands defined in the ATA specification. This functionality allows users to protect data
using drive-level passwords. The passwords are kept within the drive, so data is protected even if the drive is moved to another computer
system.