114
SuperStorage SSG-1129P-ACR10N4L User's Manual
SHA256 PCR Bank
Use this feature to disable or enable the SHA256 Platform Configuration Register (PCR) bank
for the installed TPM device. The options are Disabled and
Enabled
.
Pending operation
Use this feature to schedule a TPM-related operation to be performed by a security (TPM)
device at the next system boot to enhance system data integrity. Your system will reboot to
carry out a pending TPM operation. The options are
None
and TPM Clear.
Note:
Your system will reboot to carry out a pending TPM operation.
Platform Hierarchy (for TPM Version 2.0 or later)
Select Enabled for TPM Platform Hierarchy support which will allow the manufacturer to utilize
the cryptographic algorithm to define a constant key or a fixed set of keys to be used for initial
system boot. These early boot codes are shipped with the platform and are included in the
list of "public keys". During system boot, the platform firmware uses the trusted public keys
to verify a digital signature in an attempt to manage and control the security of the platform
firmware used in a host system via a TPM device. The options are Disabled and
Enabled
.
Storage Hierarchy
Select Enabled for TPM Storage Hierarchy support that is intended to be used for non-privacy-
sensitive operations by the platform owner such as an IT professional or the end user. Storage
Hierarchy has an owner policy and an authorization value, both of which can be set and are
held constant (-rarely changed) through reboots. This hierarchy can be cleared or changed
independently of the other hierarchies. The options are Disabled and
Enabled
.
Endorsement Hierarchy
Select Enabled for Endorsement Hierarchy support, which contains separate controls to
address the user's privacy concerns because the primary keys in this hierarchy are certified
by the TPM or a manufacturer to be constrained to an authentic TPM device that is attached
to an authentic platform. A primary key can be an encrypted, and a certificate can be created
using TPM2_ ActivateCredential. It allows the user to independently enable "flag, policy, and
authorization value" without involving other hierarchies. A user with privacy concerns can
disable the endorsement hierarchy while still using the storage hierarchy for TPM applications
and permitting the platform software to use the TPM. The options are Disabled and
Enabled
.
PH (Platform Hierarchy) Randomization (for TPM Version 2.0 or later)
Select Enabled for Platform Hierarchy Randomization support, which is used only during the
platform developmental stage. This feature cannot be enabled in the production platforms.
The options are
Disabled
and Enabled.
SMCI BIOS-Based TPM Provision Support
(Please confirm the description.)
Use this feature to enable the Supermicro TPM provision support.
The options are
Disabled
and Enabled.