1. Installing Internal Optional Devices
Express5800/R120h-1M User’s Guide
56
Chapter 2 Preparations
9. Please
see
Chapter 2 (2 Installation and Connection)
in this manual to conduct installation and connection,
and turn the power supply ON.
Important TPM Kit once installed cannot be removed.
Ask your sales representative if you want to remove the TPM kit.
Enable TPM
Procedure
1.
During the server startup sequence, press the
F9
key to access
System Utilities
.
2.
From the System Utilities screen, select
System Configuration
>
BIOS/Platform Configuration (RBSU)
> Server Security > Trusted Platform Module options.
3.
Verify the following:
"Current TPM Type" is set to
TPM 2.0
.
"Current TPM State" is set to
Present and Enabled
.
"TPM Visibility" is set to
Visible
.
4.
If changes were made in the previous step, press the
F10
key to save your selection.
5.
If F10 was pressed in the previous step, do one of the following:
If in graphical mode, click
Yes
.
If in text mode, press the
Y
key.
6. Press
the
ESC
key to exit System Utilities.
7.
If changes were made and saved, the server prompts for reboot request. Press the
Enter
key to confirm
reboot.
If the following actions were performed, the server reboots a second time without user input. During this
reboot, the TPM setting becomes effective.
Changing TPM bus from FIFO to CRB
Enabling or disabling TPM
Clearing the TPM
8.
Enable TPM functionality in the OS, such as Microsoft Windows BitLocker or measured boot.
For more information, see the
Microsoft website
.
If you need detailed information on the update of firmware and the procedure of hardware, refer to the Web Site
of NEC Support Center.
Retaining the recovery key/password
The recovery key/password is generated during BitLocker setup, and can be saved and printed after BitLocker
is enabled.
When using BitLocker, always retain the recovery key/password. The recovery key/password is
required to enter Recovery Mode after BitLocker detects a possible compromise of system integrity.
To help ensure maximum security, observe the following guidelines when retaining the recovery key/password:
Always store the recovery key/password in multiple locations.
Always store copies of the recovery key/password away from the server.
Do not save the recovery key/password on the encrypted hard drive.