Page 2
This product, including software and docu- mentation, is the property of Supermicro and/or its licensors, and is supplied only under a license. Any use or reproduction of this product is not allowed, except as expressly permitted by the terms of said license.
Preface Preface About This User's Guide This user's guide is written for system integrators, IT professionals, and knowledge- able end users who wish to add additional data security levels to their systems to protect highly sensitive applications. It provides detailed information on configuring, provisioning, and using the trusted platform module (TPM).
Page 4
Super Micro Computer, Inc. 980 Rock Ave. San Jose, CA 95131 U.S.A. Tel: +1 (408) 503-8000 Fax: +1 (408) 503-8008 Email: marketing@supermicro.com (General Information) support@supermicro.com (Technical Support) Website: www.supermicro.com Europe Address: Super Micro Computer B.V. Het Sterrenbeeld 28, 5215 ML...
Table of Contents Table of Contents Preface ......................3 Chapter 1 Introduction ................1-1 Overview of the Trusted Platform Module (TPM) ........... 1-1 Supermicro TPM Features ................1-2 Motherboards Supported for TPM ..............1-3 Intel TXT ......................1-3 ® An Important Note to the User ................ 1-3 Chapter 2 Deploying and Using the TPM ..........
Chapter 1 Introduction Overview of the Trusted Platform Module (TPM) The Trusted Platform Module (TPM9670) is a special add-on module that may be installed onto Supermicro X11 Dual Processor boards, and single Processor boards with socket 3647 only. Types of TPMs Note: TPM module must be provisioned in order to use Intel TXT.
Super TPM User's Manual Chapter 1: Introduction Supermicro TPM Features 1. TCG 2.0 compliance 2. SPI interface 3. Microcontroller in 0.22/0.09-µm CMOS technology 4. Compliant embedded software 5. EEPROM for TCG firmware enhancements and for user data and keys 6. Hardware accelerator for SHA-1 and SHA-256 hash algorithm 7.
Chapter 1: Introduction Motherboards Supported for TPM Please refer to the Supermicro website (http://www.supermicro.com/) for a com- plete and most up-to-date list of the motherboards that can support the TPM. As a general rule, these are most X9 motherboards, all X10 motherboards, and some AMD motherboards.
Super TPM User's Manual Chapter 2: Deploying and Using the TPM Chapter 2 Deploying and Using the TPM Follow the instructions below to begin using the TPM. Installing the TPM Onto the Motherboard To install the Trusted Platform Module onto your motherboard, follow the steps below.
Super TPM User's Manual Chapter 2: Deploying and Using the TPM Enabling the TPM via the BIOS and Intel Provision Utility ® There are two components to the process of enabling the TPM. After you have installed the TPM onto the motherboard, you must first "verify" the TPM for the motherboard;...
Page 11
Super TPM User's Manual Chapter 2: Deploying and Using the TPM Disable "PH Randomization" and "TXT Support" only. Using the arrow keys, select each option, press the <Enter> key to select Disabled, and press the <Enter> key again. Press the <Esc> key to bring you back to the "Advanced" tab options. Use the arrow keys to toggle to the "Save &...
Page 12
Super TPM User's Manual Chapter 2: Deploying and Using the TPM B. Provisioning Intel TXT (Server) Note: If the TPM part number is AOM-TPM-9670V-S or AOM-TPM-9670H- S, you do not need to get the Intel Provisioning tool. Please go ahead ®...
Page 13
Super TPM User's Manual Chapter 2: Deploying and Using the TPM In the command line at the bottom of the screen, follow these steps below after typing “FS0:” 1. Go to directory “TPM2ProvTool” 2. Type the command “TPM2TxtProv.nsh sha 256 default”. The Provisioning process is now completed.
Page 14
Super TPM User's Manual Chapter 2: Deploying and Using the TPM C. Enabling TXT Support The last step is enabling TXT Support in the BIOS and UEFI shell. Go back to the "Advanced" tab in the BIOS and enable Platform Hierarchy, Storage Hierarchy, Endorsement Hierarchy, PH Randomization, and TXT Support.
Page 15
Super TPM User's Manual Chapter 2: Deploying and Using the TPM After enabling TXT Support in the BIOS, you will need to run TXT in the UEFI shell. In the command line at the bottom of the page, type "getsec64. ef1 -l sen -a"...
Page 16
(Disclaimer Continued) The products sold by Supermicro are not intended for and will not be used in life support systems, medi- cal equipment, nuclear facilities or systems, aircraft, aircraft devices, aircraft/emergency communication devices or other critical systems whose failure to perform be reasonably expected to result in significant injury or loss of life or catastrophic property damage.