Supermicro H13SAE-MF User Manual page 79

Hide thumbs Also See for H13SAE-MF:
Table of Contents

Advertisement

with the AK. Set this feature to "System and Storage" to protect and have secure access to
your TCG NVMe devices/system/motherboard with the AK.
The options include Disabled and Enabled.
KMS Security Policy
Set this feature to Enabled to enable the Key Management Service (KMS) Security Policy.
When this feature has not previously been set to Enabled, the options are Disabled and
Enabled. Changes take effect after you save settings and reboot the system.
Notes:
Be sure that the KMS server is ready before configuring this feature.
Use the professional KMS server solutions (e.g., Thales Server) or the Supermicro PyKMIP
Software Package to establish the KMS server.
When this feature has previously been set to Enabled, the options are Enabled, Reset, and
Key Rotation. Set this feature to Key Rotation to obtain an existing Authentication-Key from
the KMS server and create a new Authentication-Key. To disable the KMS Security Policy, set
this feature to Reset. When this feature is set to reset, the system and TCG NVMe devices
chosen in "Super-Guardians Protection Policy" will be in the unprotected mode.
KMS Server Retry Count
Use this feature to specify how many times the system will attempt reconnecting to the KMS
server. Press <+> or <-> on your keyboard to change the value. The default setting is 5. If
the value is 0, the system will retry infinitely. The valid range is 0 to 10.
TPM Security Policy
Use this feature to enable or disable the TPM Security Policy. When this feature has not
previously been set to Enabled, the options are Disabled and Enabled. Changes take effect
after you save settings and reboot the system.
Note: Install a Trusted Platform Module 2.0 device to your system before configuring this
feature.
When this feature has previously been set to Enabled, the options are Disabled and Enabled.
To disable the TPM Security Policy, set this feature to Reset. When this feature is set to reset,
the system and TCG NVMe devices chosen in "Super-Guardians Protection Policy" will be
in the unprotected mode.
Load Authentication-Key
Use this feature to toggle whether the BIOS should automatically load an Authentication-Key
named TPMAuth.bin from a USB flash drive. The options are Disabled and Enabled. Set this
feature to Enabled to load the Authentication-Key. After an Authentication Key is loaded, this
79
Chapter 4: BIOS

Advertisement

Table of Contents
loading

Table of Contents