Supermicro X13SEI-TF User Manual page 103

Table of Contents

Advertisement

KMS Security Policy
Set this feature to Enabled to enable the Key Management Service (KMS) Security Policy.
When this feature has not previously been set to Enabled, the options are Disabled and
Enabled. Changes take effect after you save settings and reboot the system.
Note 1: Be sure that the KMS server is ready before configuring this feature.
Note 2: Use the professional KMS server solutions (e.g., Thales Server) or the
Supermicro PyKMIP Software Package to establish the KMS server.
When this feature has previously been set to Enabled, the options are Enabled, Reset, and
Key Rotation. Set this feature to Key Rotation to obtain an existing Authentication-Key from
the KMS server and create a new Authentication-Key. To disable the KMS Security Policy, set
this feature to Reset. When this feature is set to reset, the system and TCG NVMe devices
chosen in "Super-Guardians Protection Policy" will be in the unprotected mode.
KMS Server Retry Count
Use this feature to specify how many times the system will attempt reconnecting to the KMS
server. Press <+> or <-> on your keyboard to change the value. The default setting is 5. If
the value is 0, the system will retry infinitely. The valid range is 0 to 10.
TPM Security Policy
Use this feature to enable or disable the TPM Security Policy. When this feature has not
previously been set to Enabled, the options are Disabled and Enabled. Changes take effect
after you save settings and reboot the system.
Note: Install a Trusted Platform Module 2.0 device to your system before configuring
this feature.
When this feature has previously been set to Enabled, the options are Enabled and Reset.
To disable the TPM Security Policy, set this feature to Reset. When this feature is set to reset,
the system and TCG NVMe devices chosen in "Super-Guardians Protection Policy" will be
in the unprotected mode.
Load Authentication-Key
Use this feature to toggle whether the BIOS should automatically load an Authentication-Key
named TPMAuth.bin from a USB flash drive. The options are Disabled and Enabled. Set
this feature to Enabled to load the Authentication-Key. After an Authentication Key is loaded,
this option will be reset to Disabled. Changes take effect after you save settings and reboot
the system.
Note 1: Connect a USB flash drive with the Authentication-Key (TPMAuth.bin) to your
system before configuring this feature.
Note 2: Load the Authentication-Key after installing a TPM device. The TPM function
will not work properly without an Authentication-Key.
103
Chapter 4: UEFI BIOS

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

X13sei-f

Table of Contents