2. Configure the TPM_TCM_POLICY into XCC:
– For customers in Chinese Mainland with no TPM, or customers that require to disable TPM:
OneCli.exe config set imm.TpmTcmPolicy "NeitherTpmNorTcm"
--override
--imm <userid>:<password>@<ip_address>
– For customers in Chinese Mainland that require to enable TPM:
OneCli.exe config set imm.TpmTcmPolicy "NationZTPM20Only"
--override
--imm <userid>:<password>@<ip_address>
– For customers outside Chinese Mainland that require to enable TPM:
OneCli.exe config set imm.TpmTcmPolicy "TpmOnly"
--override
--imm <userid>:<password>@<ip_address>
3. Issue reset command to reset system:
OneCli.exe misc ospower reboot --imm <userid>:<password>@<ip_address>
4. Read back the value to check whether the change has been accepted:
OneCli.exe config show imm.TpmTcmPolicy
--override
--imm <userid>:<password>@<ip_address>
Notes:
– If the read back value is matched it means the TPM_TCM_POLICY has been set correctly.
imm.TpmTcmPolicy is defined as below:
– Value 0 use string “Undefined” , which means UNDEFINED policy.
– Value 1 use string “NeitherTpmNorTcm”, which means TPM_PERM_DISABLED.
– Value 2 use string “TpmOnly”, which means TPM_ALLOWED.
– Value 4 use string “NationZTPM20Only”, which means NationZ_TPM20_ALLOWED.
– Below 4 steps must also be used to ‘lock’ the TPM_TCM_POLICY when using OneCli/ASU
commands:
5. Read TpmTcmPolicyLock to check whether the TPM_TCM_POLICY has been locked , command as
below:
OneCli.exe config show imm.TpmTcmPolicyLock
--override
--imm <userid>:<password>@<ip_address>
The value must be 'Disabled', it means TPM_TCM_POLICY is NOT locked and must be set.
6. Lock the TPM_TCM_POLICY:
OneCli.exe config set imm.TpmTcmPolicyLock "Enabled"
--override
--imm <userid>:<password>@<ip_address>
7. Issue reset command to reset system, command as below:
OneCli.exe misc ospower reboot --imm <userid>:<password>@<ip_address>
During the reset, UEFI will read the value from imm.TpmTcmPolicyLock, if the value is 'Enabled' and
the imm.TpmTcmPolicy value is invalid, UEFI will lock the TPM_TCM_POLICY setting.
The valid values for imm.TpmTcmPolicy include 'NeitherTpmNorTcm', 'TpmOnly', and
'NationZTPM20Only'.
If the imm.TpmTcmPolicy is set as 'Enabled' but imm.TpmTcmPolicy value is invalid, UEFI will reject
the 'lock' request and change imm.TpmTcmPolicy back to 'Disabled'.
8. Read back the value to check whether the ‘Lock’ is accepted or rejected. command as below:
OneCli.exe config show imm.TpmTcmPolicy
--override
--imm <userid>:<password>@<ip_address>
Note:
If the read back value is changed from 'Disabled' to 'Enabled' that means the TPM_TCM_
POLICY has been locked successfully. There is no method to unlock a policy once it has been set
other than replacing system board.
imm.TpmTcmPolicyLock is defined as below:
Value 1 uses string “Enabled" , which means lock the policy. Other values are not accepted.
.
Hardware replacement procedures
213
Summary of Contents for 7D31
Page 1: ...ThinkSystem SR850 V2 Maintenance Manual Machine Types 7D31 and 7D32 ...
Page 8: ...vi ThinkSystem SR850 V2 Maintenance Manual ...
Page 52: ...44 ThinkSystem SR850 V2 Maintenance Manual ...
Page 60: ... Three backplanes on page 57 52 ThinkSystem SR850 V2 Maintenance Manual ...
Page 70: ...62 ThinkSystem SR850 V2 Maintenance Manual ...
Page 71: ...Chapter 3 Internal cable routing 63 ...
Page 78: ...70 ThinkSystem SR850 V2 Maintenance Manual ...
Page 114: ...106 ThinkSystem SR850 V2 Maintenance Manual ...
Page 236: ...Figure 133 System board and expansion board LEDs 228 ThinkSystem SR850 V2 Maintenance Manual ...
Page 258: ...250 ThinkSystem SR850 V2 Maintenance Manual ...
Page 260: ...252 ThinkSystem SR850 V2 Maintenance Manual ...
Page 264: ...256 ThinkSystem SR850 V2 Maintenance Manual ...
Page 273: ......
Page 274: ......