HP Engage Flex Pro G2 Maintenance and Service Guide - Page 76

Save/Restore GPT of System Hard Drive, Allow OPAL Hard Drive SID Authentication

Page 76 highlights

Table 5-2 Computer Setup Security (continued) Option Description Utilities Hard Drive Utilities ● Save/Restore GPT of System Hard Drive Enabling this feature saves the GUID Partition Table (GPT) of the system hard drive. If the GPT is subsequently changed, the user is prompted to choose whether to restore GPT. Default is disabled. ● Boot Sector (GPT) Recovery Policy Allows selection of the default action when a GPT event occurs. ● DriveLock/Automatic DriveLock Allows you to assign or modify a master or user password for hard drives. When this feature is enabled, the user is prompted to provide one of the DriveLock passwords during POST. If neither is successfully entered, the hard drive remains inaccessible until one of the passwords is successfully provided during a subsequent cold-boot sequence. NOTE: This selection appears only when at least one drive that supports the DriveLock feature is attached to the system. IMPORTANT: Be aware that these settings take place immediately. It is not necessary to save. IMPORTANT: Be sure to document the DriveLock password. Losing a DriveLock password will render a drive permanently locked. NOTE: Disable DriveLock on NVMe® drives before using applications for hardware-based encryption. After you select a drive, the following options are available: - Set DriveLock Master Password. Sets the drive's master password but does not enable DriveLock. - Enable DriveLock. Sets the drive's user password and enables DriveLock. ● Secure Erase Lets you select a hard drive to completely erase. After you erase a hard drive with a program that uses Secure Erase firmware commands, no file recovery program, partition recovery program, or other data recovery method can extract data from the drive. ● Allow OPAL Hard Drive SID Authentication BIOS supports drive encryption using the DriveLock feature by creating the storage device's ownership key. If BIOS creates the key, any third-party applications (including other encryption software) are not allowed to perform certain drive operations such as establishing their own key using SID. Encryption software applications may or may not be limited by SID authentication lockout depending on how they are designed. Default is disabled. Absolute Persistence Module Current State Shows the current state of the Absolute Persistence module. Yes: Disabled No: Available System Management Command Allows authorized personnel to reset security settings during a service event. Default is enabled. Restore Security Settings to Factory Default This action resets security devices, clears BIOS passwords (not including DriveLock), and restores settings in the Security menu to factory defaults. Computer Setup Security 69

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117

Table 5-2
Computer Setup Security
(continued)
Option
Description
Utilities
Hard Drive Utilities
Save/Restore GPT of System Hard Drive
Enabling this feature saves the GUID Partition Table (GPT) of the system hard drive. If the GPT
is subsequently changed, the user is prompted to choose whether to restore GPT. Default is
disabled.
Boot Sector (GPT) Recovery Policy
Allows selection of the default action when a GPT event occurs.
DriveLock/Automatic DriveLock
Allows you to assign or modify a master or user password for hard drives. When this feature
is enabled, the user is prompted to provide one of the DriveLock passwords during POST. If
neither is successfully entered, the hard drive remains inaccessible until one of the passwords
is successfully provided during a subsequent cold-boot sequence.
NOTE:
This selection appears only when at least one drive that supports the DriveLock
feature is attached to the system.
IMPORTANT:
Be aware that these settings take place immediately. It is not necessary to save.
IMPORTANT:
Be sure to document the DriveLock password. Losing a DriveLock password will
render a drive permanently locked.
NOTE:
Disable DriveLock on NVMe® drives before using applications for hardware-based
encryption.
After you select a drive, the following options are available:
Set DriveLock Master Password. Sets the drive’s master password but does not enable
DriveLock.
Enable DriveLock. Sets the drive’s user password and enables DriveLock.
Secure Erase
Lets you select a hard drive to completely erase.
After you erase a hard drive with a program that uses Secure Erase firmware commands, no
file recovery program, partition recovery program, or other data recovery method can extract
data from the drive.
Allow OPAL Hard Drive SID Authentication
BIOS supports drive encryption using the DriveLock feature by creating the storage device’s
ownership key. If BIOS creates the key, any third-party applications (including other encryption
software) are not allowed to perform certain drive operations such as establishing their
own key using SID. Encryption software applications may or may not be limited by SID
authentication lockout depending on how they are designed. Default is disabled.
Absolute Persistence
Module Current State
Shows the current state of the Absolute Persistence module.
Yes: Disabled
No: Available
System Management
Command
Allows authorized personnel to reset security settings during a service event. Default is enabled.
Restore Security
Settings to Factory
Default
This action resets security devices, clears BIOS passwords (not including DriveLock), and restores
settings in the
Security menu
to factory defaults.
Computer Setup Security
69