HP ProLiant DL388e HP ROM-Based Setup Utility User Guide - Page 160

TPM Functionality, TPM Visibility, TPM Expansion ROM Measuring, TPM Clear, Network Server Mode

Page 160 highlights

TPM Functionality Enabling TPM Functionality enables the TPM and BIOS secure startup. The TPM is fully functional in this mode. CAUTION: When a TPM is installed and enabled on the server, data access is locked if you fail to follow the proper procedures for updating the system or option firmware, replacing the system board, replacing a hard drive, or modifying OS application TPM settings. For information on installing and enabling the TPM module option, see the HP Trusted Platform Module Option Installation Instructions that ships with the option. Disabling TPM Functionality disables the BIOS secure startup but still allows the TPM to be visible to the operating system. The TPM can respond to most commands in this mode. Selecting Disabled may prevent the server from booting to a TPM-aware operating system. TPM Visibility The TPM Visibility option provides the ability to hide the TPM from the operating system. When the TPM is hidden, BIOS secure startup is disabled, and the TPM does not respond to any commands from any software. Hiding the TPM may prevent the server from booting to a TPM-aware operating system. TPM Expansion ROM Measuring TPM Expansion ROM Measuring enables the BIOS to measure the optional PCI or PCIe expansion ROM code and store that measurement in the TPM. On subsequent reboots, operating systems or validation software that utilize the measurements stored in the TPM can use this data to detect modifications to PCI or PCIe expansion ROM versions. TPM Clear The TPM Clear option allows the user to reset the TPM to factory settings, clearing any assigned passwords, keys, or ownership. Clearing the TPM may prevent the server from booting to a TPM-aware operating system. Network Server Mode The Network Server Mode option is a toggle setting that sets the server to operate in network server mode. This feature works in conjunction with the power-on password. When set to Disabled, the server operates normally. When it is set to Enabled, the following actions occur: • The local keyboard remains locked until the power-on password is entered. • The power-on password prompt is bypassed. • When a diskette is in the diskette drive, the server does not start unless the power-on password is entered locally. IMPORTANT: Network server mode cannot be enabled until the power-on password has been established. QuickLock The QuickLock option is a toggle setting that either enables or disables the QuickLock feature. When set to Enabled, the keyboard is locked by pressing the Ctrl+Alt+L keys. The keyboard remains locked until the power-on password is typed. NOTE: If the power-on password is disabled at the power-on key prompt, the QuickLock feature remains inactive until the password is changed in RBSU. 160 RBSU menu-driven interface (G6 and earlier servers)

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204

TPM Functionality
Enabling TPM Functionality enables the TPM and BIOS secure startup. The TPM is fully functional
in this mode.
CAUTION:
When a TPM is installed and enabled on the server, data access is locked if you fail
to follow the proper procedures for updating the system or option firmware, replacing the system
board, replacing a hard drive, or modifying OS application TPM settings.
For information on installing and enabling the TPM module option, see the
HP Trusted Platform
Module Option Installation Instructions
that ships with the option.
Disabling TPM Functionality disables the BIOS secure startup but still allows the TPM to be visible
to the operating system. The TPM can respond to most commands in this mode.
Selecting Disabled may prevent the server from booting to a TPM-aware operating system.
TPM Visibility
The TPM Visibility option provides the ability to hide the TPM from the operating system. When
the TPM is hidden, BIOS secure startup is disabled, and the TPM does not respond to any commands
from any software.
Hiding the TPM may prevent the server from booting to a TPM-aware operating system.
TPM Expansion ROM Measuring
TPM Expansion ROM Measuring enables the BIOS to measure the optional PCI or PCIe expansion
ROM code and store that measurement in the TPM. On subsequent reboots, operating systems or
validation software that utilize the measurements stored in the TPM can use this data to detect
modifications to PCI or PCIe expansion ROM versions.
TPM Clear
The TPM Clear option allows the user to reset the TPM to factory settings, clearing any assigned
passwords, keys, or ownership.
Clearing the TPM may prevent the server from booting to a TPM-aware operating system.
Network Server Mode
The Network Server Mode option is a toggle setting that sets the server to operate in network server
mode. This feature works in conjunction with the power-on password. When set to Disabled, the
server operates normally. When it is set to Enabled, the following actions occur:
The local keyboard remains locked until the power-on password is entered.
The power-on password prompt is bypassed.
When a diskette is in the diskette drive, the server does not start unless the power-on password
is entered locally.
IMPORTANT:
Network server mode cannot be enabled until the power-on password has
been established.
QuickLock
The QuickLock option is a toggle setting that either enables or disables the QuickLock feature.
When set to Enabled, the keyboard is locked by pressing the
Ctrl+Alt+L
keys. The keyboard remains
locked until the power-on password is typed.
NOTE:
If the power-on password is disabled at the power-on key prompt, the QuickLock feature
remains inactive until the password is changed in RBSU.
160
RBSU menu-driven interface (G6 and earlier servers)