Dell Latitude 7350 Detachable Owners Manual - Page 127

Security, TPM 2.0 Securty On, Advanced Setup, Attestation Enable, Attestation, Enable

Page 127 highlights

Table 44. System Setup options-Security menu (continued) Security For additional security, Dell Technologies recommends keeping the Trusted Platform Module (TPM) enabled to allow these security technologies to fully function. TPM 2.0 Security On Enables or disables the TPM. By default, the TPM 2.0 Securty On option is enabled. For additional security, Dell Technologies recommends keeping TPM enabled to allow these security technologies to fully function. NOTE: To view this option, enable Advanced Setup mode as described in View Advanced Setup options. Attestation Enable The Attestation Enable option controls the endorsement hierarchy of TPM. Disabling the Attestation Enable option prevents TPM from being used to digitally sign certificates. By default, the Attestation Enable option is enabled. For additional security, Dell Technologies recommends keeping the Attestation Enable option enabled. NOTE: When disabled, this feature may cause compatibility issues or loss of functionality in some operating systems. NOTE: To view this option, enable Advanced Setup mode as described in View Advanced Setup options. Key Storage Enable The Key Storage Enable option controls the storage hierarchy of TPM, which is used to store digital keys. Disabling the Key Storage Enable option restricts the ability of TPM to store owner's data. By default, the Key Storage Enable option is enabled. For additional security, Dell Technologies recommends keeping the Key Storage Enable option enabled. NOTE: When disabled, this feature may cause compatibility issues or loss of functionality in some operating systems. NOTE: To view this option, enable Service options as described in View Service options. SHA-256 Allows you to control the usage of SHA-256 by TPM. When enabled, the BIOS and TPM use the SHA-256 hash algorithm to extend measurements into the TPM PCRs during BIOS boot. When disabled, the BIOS and TPM use the SHA-1 hash algorithm to extend measurements into the TPM PCRs during BIOS boot. By default, the SHA-256 option is enabled. For additional security, Dell Technologies recommends keeping the SHA-256 option enabled. NOTE: To view this option, enable Service options as described in View Service options. Clear When enabled, the Clear option clears information that is stored in the TPM after exiting the system's BIOS. This option returns to the disabled state when the computer restarts. By default, the Clear option is disabled. Dell Technologies recommends enabling the Clear option only when TPM data is required to be cleared. NOTE: To view this option, enable Advanced Setup mode as described in View Advanced Setup options. BIOS Setup 127

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149

Table 44. System Setup options—Security menu (continued)
Security
For additional security, Dell Technologies recommends keeping the Trusted
Platform Module (TPM) enabled to allow these security technologies to fully
function.
TPM 2.0 Security On
Enables or disables the TPM.
By default, the
TPM 2.0 Securty On
option is enabled.
For additional security, Dell Technologies recommends keeping TPM enabled to
allow these security technologies to fully function.
NOTE:
To view this option, enable
Advanced Setup
mode as described in
View Advanced Setup options
.
Attestation Enable
The
Attestation Enable
option controls the endorsement hierarchy of TPM.
Disabling the
Attestation Enable
option prevents TPM from being used to
digitally sign certificates.
By default, the
Attestation Enable
option is enabled.
For additional security, Dell Technologies recommends keeping the
Attestation
Enable
option enabled.
NOTE:
When disabled, this feature may cause compatibility issues or loss of
functionality in some operating systems.
NOTE:
To view this option, enable
Advanced Setup
mode as described in
View Advanced Setup options
.
Key Storage Enable
The
Key Storage Enable
option controls the storage hierarchy of TPM, which is
used to store digital keys. Disabling the
Key Storage Enable
option restricts the
ability of TPM to store owner's data.
By default, the
Key Storage Enable
option is enabled.
For additional security, Dell Technologies recommends keeping the
Key Storage
Enable
option enabled.
NOTE:
When disabled, this feature may cause compatibility issues or loss of
functionality in some operating systems.
NOTE:
To view this option, enable
Service
options as described in
View
Service options
.
SHA-256
Allows you to control the usage of SHA-256 by TPM. When enabled, the BIOS
and TPM use the SHA-256 hash algorithm to extend measurements into the
TPM PCRs during BIOS boot. When disabled, the BIOS and TPM use the SHA-1
hash algorithm to extend measurements into the TPM PCRs during BIOS boot.
By default, the
SHA-256
option is enabled.
For additional security, Dell Technologies recommends keeping the
SHA-256
option enabled.
NOTE:
To view this option, enable
Service
options as described in
View
Service options
.
Clear
When enabled, the
Clear
option clears information that is stored in the TPM
after exiting the system's BIOS. This option returns to the disabled state when
the computer restarts.
By default, the
Clear
option is disabled.
Dell Technologies recommends enabling the
Clear
option only when TPM data is
required to be cleared.
NOTE:
To view this option, enable
Advanced Setup
mode as described in
View Advanced Setup options
.
BIOS Setup
127