Tpm 2.0 Security Information - Dell EMC VxFlex Ready Node R840 Manual

Hide thumbs Also See for EMC VxFlex Ready Node R840:
Table of Contents

Advertisement

Table 6 TPM 2.0 security information
TPM
Description
information
TPM
Changes the operational state of the TPM. This option is set to
Information
Change
TPM Firmware
Indicates the firmware version of the TPM.
TPM Hierarcy
Enable, disable, or clear the storage and endorsement hierarchies. When
set to
When set to
be used.
When set to
of any values, and then reset to
Intel(R) TXT
Enables or disables the Intel Trusted Execution Technology (TXT) option. To
enable the Intel TXT option, virtualization technology and TPM Security must be
enabled with Pre-boot measurements. This option is set to Off by default.
When TPM 2.0 is installed, TPM 2 Algorithm option is available. It enables you to
select a hash algorithm from those supported by the TPM (SHA1, SHA256). TPM
2 Algorithm option must be set to SHA256, to enable TXT.
Power Button
Enables or disables the power button on the front of the system. This option is
set to Enabled by default.
AC Power Recovery
Sets how the system behaves after AC power is restored to the system. This
option is set to Last by default.
AC Power Recovery Delay
Sets the time delay for the system to power up after AC power is restored to the
system. This option is set to Immediate by default.
User Defined Delay (60 s to 240 s)
Sets the User Defined Delay option when the User Defined option for AC Power
Recovery Delay is selected.
UEFI Variable Access
Provides varying degrees of securing UEFI variables. When set to Standard (the
default), UEFI variables are accessible in the operating system per the UEFI
specification. When set to Controlled, selected UEFI variables are protected in
the environment and new UEFI boot entries are forced to be at the end of the
current boot order.
In-Band Manageability Interface
When set to Disabled, this setting will hide the Management Engine's (ME), HECI
devices, and the system's IPMI devices from the operating system. This prevents
the operating system from changing the ME power capping settings, and blocks
access to all in-band management tools. All management should be managed
through out-of-band. This option is set to Enabled by default.
Managing basic system settings using the system firmware
by default.
Enabled
, the storage and endorsement hierarchies can be used.
Disabled
, the storage and endorsement hierarchies cannot
Clear
, the storage and endorsement hierarchies are cleared
Enabled
No
.
System BIOS
47

Advertisement

Table of Contents
loading

Table of Contents