Enable TPM
The server supports Trusted Platform Module (TPM), Version 1.2 or Version 2.0
Note:
For customers in Chinese Mainland, integrated TPM is not supported. However, customers in Chinese
Mainland can install a TPM card.
When a system board is replaced, you must make sure that the TPM card policy is set correctly.
CAUTION:
Take special care when setting the TPM card policy. If it is not set correctly, the system board can
become unusable.
Set the TPM policy
By default, a replacement system board is shipped with the TPM policy set to
undefined
. You must modify
this setting to match the setting that was in place for the system board that is being replaced.
There are two methods available to set the TPM policy:
• From Lenovo XClarity Provisioning Manager
To set the TPM policy from Lenovo XClarity Provisioning Manager:
1. Start the server and press the key according to the on-screen instructions to display the Lenovo
XClarity Provisioning Manager interface.
2. If the power-on Administrator password is required, enter the password.
3. From the System Summary page, click
Update VPD
.
4. Set the policy to one of the following settings.
–
NationZ TPM 2.0 enabled - China only
. Customers in the Chinese Mainland should choose this
setting if a NationZ TPM 2.0 adapter is installed.
–
TPM enabled - ROW
. Customers outside of the Chinese Mainland should choose this setting.
–
Permanently disabled
. Customers in the Chinese Mainland should use this setting if no TPM
adapter is installed.
Note:
Although the setting
undefined
is available as a policy setting, it should not be used.
• From Lenovo XClarity Essentials OneCLI
Note:
Please note that a Local IPMI user and password must be setup in Lenovo XClarity Controller for
remote accessing to the target system.
To set the TPM policy from Lenovo XClarity Essentials OneCLI:
1. Read TpmTcmPolicyLock to check whether the TPM_TCM_POLICY has been locked:
OneCli.exe config show imm.TpmTcmPolicyLock --override --imm <userid>:<password>@<ip_address>
Note:
The imm.TpmTcmPolicyLock value must be 'Disabled', which means TPM_TCM_POLICY is
NOT locked and changes to the TPM_TCM_POLICY are permitted. If the return code is ‘Enabled’
then no changes to the policy are permitted. The planar may still be used if the desired setting is
correct for the system being replaced.
2. Configure the TPM_TCM_POLICY into XCC:
– For customers in Chinese Mainland with no TPM, or customers that require to disable TPM:
OneCli.exe config set imm.TpmTcmPolicy "NeitherTpmNorTcm" --override --imm <userid>:<password>@<ip_
address>
– For customers in Chinese Mainland that require to enable TPM:
130
ThinkSystem SR250 V2 Maintenance Manual
Summary of Contents for 7D7Q
Page 1: ...ThinkSystem SR250 V2 Maintenance Manual Machine Types 7D7Q and 7D7R ...
Page 8: ...vi ThinkSystem SR250 V2 Maintenance Manual ...
Page 20: ...12 ThinkSystem SR250 V2 Maintenance Manual ...
Page 42: ...34 ThinkSystem SR250 V2 Maintenance Manual ...
Page 176: ...168 ThinkSystem SR250 V2 Maintenance Manual ...
Page 180: ...172 ThinkSystem SR250 V2 Maintenance Manual ...
Page 183: ......
Page 184: ......