Supermicro X13DEG-OA User Manual page 138

Table of Contents

Advertisement

Super X13DEG-OA User's Manual
Endorsement Hierarchy (Available when "Security Device Support" is set to Enable)
Select Enabled for Endorsement Hierarchy support, which contains separate controls to
address the user's privacy concerns because the primary keys in the hierarchy are certified
by the TPM key or by a manufacturer with restrictions on how an authentic TPM device that is
attached to an authentic platform can be accessed and used. A primary key can be encrypted
and certified with a certificate created by using TPM2_ ActivateCredential, which allows the
user to independently enable "flag, policy, and authorization values" without involving other
hierarchies. A user with privacy concerns can disable the endorsement hierarchy while still
using the storage hierarchy for TPM applications, permitting the platform software to use the
TPM. The options are Disabled and Enabled.
PH Randomization (for TPM version 2.0 and above)
Select Enabled for Platform Hierarchy (PH) Randomization support, which is used only during
the platform developmental stage. This feature cannot be enabled in the production platforms.
The options are Disabled and Enabled.
Supermicro BIOS-Based TPM Provision Support
If this feature is set to Enabled, Supermicro BIOS-based TPM provision will be supported.
The options are Disabled and Enabled.
Note: Enabling this feature will lock your TPM on the production platform, and you will
not be able to delete the NV indexes.
TXT Support
Select Enabled to enable Intel Trusted Execution Technology (TXT) support to enhance
system integrity and data security. The options are Disabled and Enabled.
Note 1: If this feature is set to Enabled, be sure to disable Device Function On-Hide
(EV DFX) support when it is present in the BIOS for the system to work properly.
Note 2: For more information on TPM, please refer to the TPM manual at
supermicro.com/manuals/other/TPM.pdf.
Supermicro KMS Server Configuration
Supermicro KMS Server IP address
Use this feature to enter the Supermicro Key Management Service (KMS) server IPv4 address
in dotted-decimal notation.
Second Supermicro KMS Server IP address
Use this feature to enter the second Supermicro KMS server IPv4 address in dotted-decimal
notation.
138
https://www.

Advertisement

Table of Contents
loading

Table of Contents