Supermicro X13SCD-F User Manual page 85

Table of Contents

Advertisement

Client Private Key
For the client private key, use this feature to enroll factory defaults or load the KMS TLS
certificates from the file. The options are Update, Delete, and Export.
Private Key Password (Available when Private Key Password has been set)
Use this feature to change the private key password.
Super-Guardians Configuration
Super Guardians is a unified security solution to facilitate KMS, TPM, or USB-based
authentication controls for Supermicro X13 motherboards. Use this submenu to configure the
authentication policy, method, and KMS server settings.
Super-Guardians Protection Policy
Use this feature to enable the Super-Guardians Protection Policy. The options are Storage,
System, and "System and Storage." Set this feature to Storage to protect and have secure
access to Trusted Computing Group (TCG) NVMe devices with the Authentication-Key (AK).
Set this feature to System to protect and have secure access to your system/motherboard
with the AK. Set this feature to "System and Storage" to protect and have secure access to
your TCG NVMe devices/system/motherboard with the AK.
KMS Security Policy
Set this feature to Enabled to enable the Key Management Service (KMS) Security Policy.
When this feature has not previously been set to Enabled, the options are Disabled and
Enabled. Changes take effect after you save settings and reboot the system.
Note 1: Be sure that the KMS server is ready before configuring this feature.
Note 2: Use the professional KMS server solutions (e.g., Thales Server) or the
Supermicro PyKMIP Software Package to establish the KMS server.
When this feature has previously been set to Enabled, the options are Enabled, Reset, and
Key Rotation. Set this feature to Key Rotation to obtain an existing Authentication-Key from
the KMS server and create a new Authentication-Key. To disable the KMS Security Policy, set
this feature to Reset. When this feature is set to reset, the system and TCG NVMe devices
chosen in "Super-Guardians Protection Policy" will be in the unprotected mode.
KMS Server Retry Count
Use this feature to specify how many times the system will attempt reconnecting to the KMS
server. Press <+> or <-> on your keyboard to change the value. The default setting is 5. If
the value is 0, the system will retry infinitely. The valid range is 0 to 10.
85
Chapter 4: UEFI BIOS

Advertisement

Table of Contents
loading

Table of Contents