Chapter 4: BIOS
125
SHA-1 PCR Bank
Select Enabled to enable SHA-1 PCR Bank support to enhance system integrity and data
security. The options are
Enabled
and Disabled.
SHA256 PCR Bank
Select Enabled to enable SHA256 PCR Bank support to enhance system integrity and data
security. The options are
Enabled
and Disabled.
Pending Operation
Use this feature to schedule a TPM-related operation to be performed by a security (TPM)
device at the next system boot to enhance system data integrity. Your system will reboot
to carry out a pending TPM operation. The options are
None
and TPM Clear.
Note
: Your system will reboot to carry out a pending TPM operation.
Platform Hierarchy (for TPM Version 2.0 and above)
Select Enabled for TPM Platform Hierarchy support which will allow the manufacturer to
utilize the cryptographic algorithm to define a constant key or a fixed set of keys to be
used for initial system boot. These early boot codes are shipped with the platform and are
included in the list of "public keys". During system boot, the platform firmware uses the
trusted public keys to verify a digital signature in an attempt to manage and control the
security of the platform firmware used in a host system via a TPM device. The options are
Enabled
and Disabled.
Storage Hierarchy
Select Enabled for TPM Storage Hierarchy support that is intended to be used for non-
privacy-sensitive operations by a platform owner such as an IT professional or the end user.
Storage Hierarchy has an owner policy and an authorization value, both of which can be
set and are held constant (-rarely changed) through reboots. This hierarchy can be cleared
or changed independently of the other hierarchies. The options are
Enabled
and Disabled.
Endorsement Hierarchy
Select Enabled for Endorsement Hierarchy support, which contains separate controls to
address the user's privacy concerns because the primary keys in the hierarchy are certified
by the TPM key or by a manufacturer with restrictions on how an authentic TPM device
that is attached to an authentic platform can be accessed and used. A primary key can be
encrypted and certified with a certificate created by using TPM2_ ActivateCredential, which
allows the user to independently enable "flag, policy, and authorization values" without
involving other hierarchies. A user with privacy concerns can disable the endorsement