Supermicro AOM-TPM-9670H Скачать руководство пользователя страница 10

2-2

 Super TPM User's Manual

Chapter 2: Deploying and Using the TPM

2.2  Enabling the TPM via the BIOS and Intel

®

 Provision Utility

There are two components to the process of enabling the TPM. After you have 

installed  the  TPM  onto  the  motherboard,  you  must  first  "verify"  the  TPM  for  the 

motherboard; this is done through the BIOS. (Also in the BIOS, you should enable 

TXT  support.) After  that,  you  then  "lock"  the  TPM  in  the  firmware.  This  is  done 

through the provision utility provided by Intel.

A. Enabling the TPM in the BIOS

1.  Enter the BIOS setup screen. You may do this either from the IPMI remote 

console or from the server directly using KVM. Reboot the system, and press 
the <

Del

> key as the system boots until you reach the BIOS screen.

2.  You will be presented with the BIOS Setup main screen. Using your arrow 

keys, navigate to the "

Advanced

"

 tab. From there, navigate down and select 

the "

CPU Configuration

" option. Press <

Enter

>.

3. 

You will then be taken to the CPU Configuration page. Using your arrow keys, 

navigate down to the "

Intel Virtualization Technology

" option, as shown 

below, and press <

Enter

>. If this item is not already enabled, select 

Enable

 

and press <

Enter

>.

4.  Once you have enabled virtualization support, press your <

Esc

> key until you 

are back to the "

Advanced

" tab. Navigate down to the "

Trusted Computing

option and press <

Enter

>.

5.  The Trusted Computing window will appear. 

Note: "SHA-1 PCR Bank

" and "

SHA-256 PCR Bank

” are Enabled. 

Содержание AOM-TPM-9670H

Страница 1: ...TPM AOM TPM 9670V AOM TPM 9670H AOM TPM 9670V H S USER S MANUAL 1 2...

Страница 2: ...as expressly permitted by the terms of said license IN NO EVENT WILL SUPER MICRO COMPUTER INC BE LIABLE FOR DIRECT INDIRECT SPECIAL INCIDENTAL SPECULATIVE OR CONSEQUENTIAL DAMAGES ARISING FROM THE US...

Страница 3: ...trusted platform module TPM User s Guide Organization Chapter 1 provides an overview of the trusted platform module TPM including its features and uses Chapter 2 provides detailed instructions on ins...

Страница 4: ...Address Super Micro Computer B V Het Sterrenbeeld 28 5215 ML s Hertogenbosch The Netherlands Tel 31 0 73 6400390 Fax 31 0 73 6416525 Email sales supermicro nl General Information support supermicro nl...

Страница 5: ...latform Module TPM 1 1 1 2 Supermicro TPM Features 1 2 1 3 Motherboards Supported for TPM 1 3 1 4 Intel TXT 1 3 1 5 An Important Note to the User 1 3 Chapter 2 Deploying and Using the TPM 2 1 2 1 Inst...

Страница 6: ...mware The following SKUs are available AOM TPM 9670V a vertical TPM module AOM TPM 9670H a horizontal TPM module Horizontal vs Vertical Generally whether you should use a TPM with a horizontal or vert...

Страница 7: ...gorithm 7 True Random Number Generator TRNG 8 Tick counter with tamper detection 9 Protection against dictionary attack 10 Infineon s TPM 2 0 is Common Criteria certified at Evaluation Assurance Level...

Страница 8: ...rotecting firmware against malicious attacks to vulnerable areas It works by matching hypervisor measures with encryption keys upon system launch If the hypervisor does not match the keys then the hyp...

Страница 9: ...board manual If the board does not have this feature then it does not support the TPM 2 Using the key pin as a reference orient and align your TPM with the connec tor key pin 3 Carefully insert the TP...

Страница 10: ...erver directly using KVM Reboot the system and press the Del key as the system boots until you reach the BIOS screen 2 You will be presented with the BIOS Setup main screen Using your arrow keys navig...

Страница 11: ...each option press the Enter key to select Disabled and press the Enter key again 7 Press the Esc key to bring you back to the Advanced tab options Use the arrow keys to toggle to the Save Exit tab 8...

Страница 12: ...on Intel TXT in the UEFI shell Once you have selected UEFI Built in EFI Shell in the BIOS the system will boot into the Unified Extensible Firmware Interface UEFI with a list of available USB devices...

Страница 13: ...fter typing FS0 1 Go to directory TPM2ProvTool 2 Type the command TPM2TxtProv nsh sha 256 default The Provisioning process is now completed 4 After the provisioning process has completed you will need...

Страница 14: ...The last step is enabling TXT Support in the BIOS and UEFI shell 1 Go back to the Advanced tab in the BIOS and enable Platform Hierarchy Storage Hierarchy Endorsement Hierarchy PH Randomization and T...

Страница 15: ...IOS you will need to run TXT in the UEFI shell In the command line at the bottom of the page type getsec64 ef1 l sen a and press the Enter key TXT support is now enabled 4 To exit from the TXT environ...

Страница 16: ...expected to result in significant injury or loss of life or catastrophic property damage Accordingly Supermicro disclaims any and all li ability and should buyer use or sell such products for use in s...

Отзывы: