Page 2
This product, including software and docu- mentation, is the property of Supermicro and/or its licensors, and is supplied only under a license. Any use or reproduction of this product is not allowed, except as expressly permitted by the terms of said license.
Preface Preface About This User's Guide This user's guide is written for system integrators, IT professionals, and knowl- edgeable end-users who wish to add additional data security mechanisms to their systems to protect highly sensitive applications. It provides detailed information on configuring, provisioning, and using the Trusted Platform Module (TPM) for X12 and H12 motherboards.
Page 4
Super Micro Computer, Inc. 980 Rock Ave. San Jose, CA 95131 U.S.A. Tel: +1 (408) 503-8000 Fax: +1 (408) 503-8008 Email: marketing@supermicro.com (General Information) Sales-USA@supermicro.com (Sales Inquiries) Government_Sales-USA@supermicro.com (Gov. Sales Inquiries) support@supermicro.com (Technical Support) RMA@supermicro.com (RMA Support) Webmaster@supermicro.com (Webmaster) Website: www.supermicro.com...
Super TPM User's Guide Table of Contents Preface ......................iii Chapter 1 Introduction ................1-1 Overview of the Trusted Platform Module (TPM) ........... 1-1 Supermicro TPM Features ................1-2 Motherboards Supported for TPM ..............1-3 Intel TXT ......................1-3 ® An Important Note to the User ................ 1-3 Chapter 2 Deploying and Using the TPM ..........
Introduction Overview of the Trusted Platform Module (TPM) The Trusted Platform Module (TPM9670) is a special add-on module that may be installed onto Supermicro X12/H12 dual and single processor motherboards that support CPU Socket 3674 only. Types of TPMs Note: TPM modules must be provisioned in order to use Intel Trusted ®...
Super TPM User's Manual Supermicro TPM Features 1. TCG 2.0 compliance 2. SPI interface 3. Microcontroller in 0.22/0.09-µm CMOS technology 4. Compliant embedded software 5. EEPROM for TCG firmware enhancements and for user data and key support 6. Hardware accelerator for SHA-1 and SHA-256 hash algorithm 7.
Chapter 1: Introduction Motherboards Supported for TPM Please refer to the Supermicro website (http://www.supermicro.com/) for a complete and most up-to-date list of the motherboards that can support the TPM. Such moth- erboards will have a specially designated JTPM1 connector, which will be listed in the respective motherboard's manual.
Chapter 2: Deploying and Using the TPM Chapter 2 Deploying and Using the TPM Follow the instructions below to begin using the TPM. Installing the TPM Onto the Motherboard To install the Trusted Platform Module onto your motherboard, follow the steps below.
Super TPM User's Manual Enabling the TPM via the BIOS and Intel Provision ® Utility There are two components to the process of enabling the TPM. After you have installed the TPM onto the motherboard, you must first "verify" the TPM for the motherboard;...
Page 12
Chapter 2: Deploying and Using the TPM 4. Once you have enabled virtualization support, press your <Esc> key until you are back to the "Advanced" tab. Navigate down to the "Trusted Computing" option and press <Enter>. 5. The Trusted Computing window will appear. Note: By default, "SHA-1 PCR Bank"...
Page 13
Super TPM User's Manual 9. Use the arrow keys to select "UEFI: Built-in EFI Shell" and press the <En- ter> key.
Page 14
Chapter 2: Deploying and Using the TPM B. Provisioning Intel TXT (Server) Next, you will need to provision Intel TXT in the UEFI shell. ® Note: If the TPM part number is AOM-TPM-9670V-S or AOM-TPM-9670H- S, you do not need to get the Intel Provisioning tool.
Page 15
Super TPM User's Manual Go to the directory “TPpm2ProvTools-CBnT”. Type the command “Tpm2_CBnT_Prov.nsh sha256 example”. iii. The provisioning process is now Completed.
Page 16
Chapter 2: Deploying and Using the TPM 4. After the provisioning process has been completed, you will need to go back into the BIOS and enable "TXT Support". To do this, type "exit" in the com- mand line at the bottom of the screen and press the <Enter> key.
Page 17
Super TPM User's Manual C. Enabling TXT Support The last step is enabling TXT Support in the BIOS and UEFI shell. 1. Go back to the "Advanced" tab in the BIOS and enable Platform Hierarchy, Storage Hierarchy, Endorsement Hierarchy, PH Randomization, and TXT Support.
Page 18
Chapter 2: Deploying and Using the TPM 3. After Enabling TXT Support in BIOS, you will need to run TXT in the UEFI shell. In the Command line at the bottom of the page, type “get- sec64_v2.0.11.efi -l sen -a” and press the <Enter> key. TXT support is now enabled.
Page 19
(Disclaimer Continued) The products sold by Supermicro are not intended for and will not be used in life support systems, medi- cal equipment, nuclear facilities or systems, aircraft, aircraft devices, aircraft/emergency communication devices or other critical systems whose failure to perform be reasonably expected to result in significant injury or loss of life or catastrophic property damage.
Need help?
Do you have a question about the TPM Series and is the answer not in the manual?
Questions and answers