Dell PowerEdge R760XA Installation and Service Manual - Page 51

Table 53. System Security details continued, Table 54. TPM 2.0 security information

Page 51 highlights

Table 53. System Security details (continued) Option Description Setup Password Sets the setup password. This option is read-only if the password jumper is not installed in the system. Password Status Locks the system password. This option is set to Unlocked by default. TPM Information Indicates the type of Trusted Platform Module, if present. Table 54. TPM 2.0 security information Option Description TPM Information TPM Security NOTE: The TPM menu is available only when the TPM module is installed. Enables you to control the reporting mode of the TPM. When set to Off, the presence of the TPM is not reported to the OS. When set to On, the presence of the TPM is reported to the OS. The TPM Security option is set to Off by default. When TPM 2.0 is installed, the TPM Security option is set to On or Off. This option is set to Off by default. TPM Information Indicates the type of Trusted Platform Module, if present. TPM Firmware Indicates the firmware version of the TPM. TPM Hierarchy Enables, disables, or clears the storage and endorsement hierarchies. When set to Enabled, the storage and endorsement hierarchies can be used. When set to Disabled, the storage and endorsement hierarchies cannot be used. When set to Clear, the storage and endorsement hierarchies are cleared of any values, and then reset to Enabled. TPM Advanced Settings Specifies TPM Advanced Settings details. Table 55. System Security details Option Description Intel(R) TXT Enables you to set the Intel Trusted Execution Technology (TXT) option. To enable the Intel TXT option, virtualization technology and TPM Security must be enabled with Pre-boot measurements. This option is set to Off by default. It is set On for Secure Launch (Firmware Protection) support on Windows 2022. Memory Encryption Enables or disables the Intel Total Memory Encryption (TME) and Multi-Tenant (Intel® TME-MT). When option is set to Disabled, BIOS disables both TME and MK-TME technology. When option is set to Single Key BIOS enables the TME technology. When option is set to Multiple Keys, BIOS enables the TME-MT technology. This option is set to Disabled by default. TME Encryption Bypass Allows the option to bypass the Intel Total Memory Encryption. This option is set to Disabled by default. Intel(R) SGX Enables you to set the Intel Software Guard Extension (SGX) option. To enable the Intel SGX option, processor must be SGX capable, memory population must be compatible (minimum x8 identical DIMM1 to DIMM8 per CPU socket, memory operating mode must be set at optimizer mode, memory encryption must be enabled and node interleaving must be disabled. This option is set to Off by default. When this option is to Off, BIOS disables the SGX technology. When this option is to On, BIOS enables the SGX technology. Power Button Enables or disables the power button on the front of the system. This option is set to Enabled by default. Pre-operating system management applications 51

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206

Table 53. System Security details (continued)
Option
Description
Setup Password
Sets the setup password. This option is read-only if the password jumper is not installed
in the system.
Password Status
Locks the system password. This option is set to
Unlocked
by default.
TPM Information
Indicates the type of Trusted Platform Module, if present.
Table 54. TPM 2.0 security information
Option
Description
TPM Information
TPM Security
NOTE:
The TPM menu is available only when the TPM module is installed.
Enables you to control the reporting mode of the TPM. When set to Off, the presence of the TPM is
not reported to the OS. When set to On, the presence of the TPM is reported to the OS. The
TPM
Security
option is set to
Off
by default.
When TPM 2.0 is installed, the
TPM Security
option is set to
On
or
Off
. This option is set to
Off
by
default.
TPM Information
Indicates the type of Trusted Platform Module, if present.
TPM Firmware
Indicates the firmware version of the TPM.
TPM Hierarchy
Enables, disables, or clears the storage and endorsement hierarchies. When set to
Enabled
, the storage
and endorsement hierarchies can be used.
When set to
Disabled
, the storage and endorsement hierarchies cannot be used.
When set to
Clear
, the storage and endorsement hierarchies are cleared of any values, and then reset
to
Enabled
.
TPM Advanced
Settings
Specifies TPM Advanced Settings details.
Table 55. System Security details
Option
Description
Intel(R) TXT
Enables you to set the Intel Trusted Execution Technology (TXT) option. To enable
the
Intel TXT
option, virtualization technology and TPM Security must be enabled with
Pre-boot measurements. This option is set to
Off
by default. It is set
On
for Secure
Launch (Firmware Protection) support on Windows 2022.
Memory Encryption
Enables or disables the Intel Total Memory Encryption (TME) and Multi-Tenant (Intel
®
TME-MT). When option is set to
Disabled
, BIOS disables both TME and MK-TME
technology. When option is set to
Single Key
BIOS enables the TME technology. When
option is set to
Multiple Keys
, BIOS enables the TME-MT technology. This option is set
to
Disabled
by default.
TME Encryption Bypass
Allows the option to bypass the Intel Total Memory Encryption. This option is set to
Disabled
by default.
Intel(R) SGX
Enables you to set the Intel Software Guard Extension (SGX) option. To enable the
Intel
SGX
option, processor must be SGX capable, memory population must be compatible
(minimum x8 identical DIMM1 to DIMM8 per CPU socket, memory operating mode must
be set at optimizer mode, memory encryption must be enabled and node interleaving
must be disabled. This option is set to
Off
by default. When this option is to
Off
,
BIOS disables the SGX technology. When this option is to
On
, BIOS enables the SGX
technology.
Power Button
Enables or disables the power button on the front of the system. This option is set to
Enabled
by default.
Pre-operating system management applications
51