• Value 1 use string “NeitherTpmNorTcm”, which means TPM_PERM_DISABLED.
• Value 2 use string “TpmOnly”, which means TPM_ALLOWED.
• Value 4 use string “NationZTPM20Only”, which means NationZTPM20_ALLOWED.
Locking the TPM policy
Steps:
1. Read TpmTcmPolicyLock to check whether the TPM_TCM_POLICY has been locked:
OneCli.exe config show bmc.TpmTcmPolicyLock
--override
--bmc
<userid>
:
<password>
@
<ip_address>
Note:
The value must be “Disabled”, it means TPM_TCM_POLICY is NOT locked and must be set.
2. Lock the TPM_TCM_POLICY:
OneCli.exe config set bmc.TpmTcmPolicyLock "Enabled"
--override
--bmc
<userid>
:
<password>
@
<ip_address>
3. Issue reset command to reset system.
OneCli.exe misc ospower reboot
--bmc
<userid>
:
<password>
@
<ip_address>
During the reset, UEFI will read the value from bmc.TpmTcmPolicyLock, if the value is 'Enabled' and the
bmc.TpmTcmPolicy value is invalid, UEFI will lock the TPM_TCM_POLICY setting.
The valid value for bmc.TpmTcmPolicy includes “NeitherTpmNorTcm”, “TpmOnly”, and
“NationZTPM20Only”.
If the bmc.TpmTcmPolicy is set as “Enabled” but bmc.TpmTcmPolicy value is invalid, UEFI will reject
the “lock” request and change bmc.TpmTcmPolicy back to “Disabled”.
4. Read back the value to check whether the “Lock” is accepted or rejected.
OneCli.exe config show bmc.TpmTcmPolicy
--override
--bmc
<userid>
:
<password>
@
<ip_address>
Note:
If the read back value is changed from “Disabled” to “Enabled” that means the TPM_TCM_
POLICY has been locked successfully. There is no method to unlock a policy once it has been set other
than replacing system board.
bmc.TpmTcmPolicyLock is defined as below:
Value 1 use string “Enabled”, which means lock the policy. Other values are not accepted.
Procedure also requires that Physical Presence is asserted. See “(Required) Assert Physical Presence”
on page 199.
.
Hardware replacement procedures
201
Содержание ThinkSystem SR635
Страница 1: ...ThinkSystem SR635 Maintenance Manual Machine Types 7Y98 and 7Y99 ...
Страница 5: ...Index 231 Copyright Lenovo 2019 2021 iii ...
Страница 6: ...iv ThinkSystem SR635 Maintenance Manual ...
Страница 10: ...viii ThinkSystem SR635 Maintenance Manual ...
Страница 12: ...Figure 2 QR code 2 ThinkSystem SR635 Maintenance Manual ...
Страница 22: ...12 ThinkSystem SR635 Maintenance Manual ...
Страница 88: ...78 ThinkSystem SR635 Maintenance Manual ...
Страница 133: ...Figure 102 Riser 1 assembly LP FHFL removal Chapter 3 Hardware replacement procedures 123 ...
Страница 136: ...Figure 105 Riser 1 assembly LP FHFL installation 126 ThinkSystem SR635 Maintenance Manual ...
Страница 214: ...204 ThinkSystem SR635 Maintenance Manual ...
Страница 232: ...222 ThinkSystem SR635 Maintenance Manual ...
Страница 240: ...230 ThinkSystem SR635 Maintenance Manual ...
Страница 245: ......
Страница 246: ......