Lenovo ThinkAgile VX7820 User Manual page 170

Table of Contents

Advertisement

Notes: You can use Lenovo XClarity Essentials OneCLI to update the TPM/TCM policy. Please
note that a Local IPMI user and password must be setup in Lenovo XClarity Controller for remote
accessing to the target system.
1. Read TpmTcmPolicyLock to check whether the TPM_TCM_POLICY has been locked:
OneCli.exe config show imm.TpmTcmPolicyLock --override --imm <userid>:<password>@<ip_address>
Note: The imm.TpmTcmPolicyLock value must be 'Disabled', which means TPM_TCM_
POLICY is NOT locked and changes to the TPM_TCM_POLICY are permitted. If the return
code is 'Enabled' then no changes to the policy are permitted. The planar may still be used if
the desired setting is correct for the system being replaced.
2. Configure the TPM_TCM_POLICY into XCC:
• For the customer in Chinese Mainland with no TCM:
OneCli.exe config set imm.TpmTcmPolicy "NeitherTpmNorTcm" --override --imm <userid>:<password>@<ip_address>
• For the customer in Chinese Mainland that has installed TCM module on the original system
(TCM module should be moved to the FRU prior to changing policy)
OneCli.exe config set imm.TpmTcmPolicy "TcmOnly" --override --imm <userid>:<password>@<ip_address>
• For the customer outside of Chinese Mainland:
OneCli.exe config set imm.TpmTcmPolicy "TpmOnly" --override --imm <userid>:<password>@<ip_address>
3. Issue reset command to reset system:
OneCli.exe misc ospower reboot --imm <userid>:<password>@<ip_address>
4. Read back the value to check whether the change has been accepted:
OneCli.exe config show imm.TpmTcmPolicy --override --imm <userid>:<password>@<ip_address>
Notes:
• If the read back value is matched it means the TPM_TCM_POLICY has been set correctly.
imm.TpmTcmPolicy is defined as below:
– Value 0 use string "Undefined" , which means UNDEFINED policy.
– Value 1 use string "NeitherTpmNorTcm", which means TPM_PERM_DISABLED.
– Value 2 use string "TpmOnly", which means TPM_ALLOWED.
– Value 4 use string "TcmOnly", which means TCM_ALLOWED.
• Below 4 steps must also be used to 'lock' the TPM_TCM_POLICY when using OneCli/ASU
commands:
5. Read TpmTcmPolicyLock to check whether the TPM_TCM_POLICY has been locked ,
command as below:
OneCli.exe config show imm.TpmTcmPolicyLock --override --imm <userid>:<password>@<ip_address>
The value must be 'Disabled', it means TPM_TCM_POLICY is NOT locked and must be set.
6. Lock the TPM_TCM_POLICY:
OneCli.exe config set imm.TpmTcmPolicyLock "Enabled"--override --imm <userid>:<password>@<ip_address>
7. Issue reset command to reset system, command as below:
OneCli.exe misc ospower reboot --imm <userid>:<password>@<ip_address>
During the reset, UEFI will read the value from imm.TpmTcmPolicyLock, if the value is
'Enabled' and the imm.TpmTcmPolicy value is invalid, UEFI will lock the TPM_TCM_POLICY
setting.
The valid value for imm.TpmTcmPolicy includes 'NeitherTpmNorTcm', 'TpmOnly' and
'TpmOnly'.
User Guide for ThinkAgile VX7820 Appliance, ThinkAgile VX 4-Socket 4U Certified Node
160

Advertisement

Table of Contents
loading

This manual is also suitable for:

Thinkagile vx 4-socket 4u certified node

Table of Contents