HP Scanjet 5000 User Guide - Page 113

Secure Boot configuration, Embedded UEFI shell, Embedded UEFI diagnostics

Page 113 highlights

You can also configure default settings as necessary, and then save the configuration as the custom default configuration. When the system loads the default settings, it uses the custom default settings instead of the factory defaults. Secure Boot configuration Secure Boot is integrated in the UEFI specification on which the HP implementation of UEFI is based. Secure Boot is completely implemented in the BIOS and does not require special hardware. It ensures that each component launched during the boot process is digitally signed and that the signature is validated against a set of trusted certificates embedded in the UEFI BIOS. Secure Boot validates the software identity of the following components in the boot process: ● UEFI drivers loaded from PCIe cards ● UEFI drivers loaded from mass storage devices ● Pre-boot UEFI shell applications ● OS UEFI boot loaders Once enabled, only firmware components and operating systems with boot loaders that have an appropriate digital signature can execute during the boot process. Only operating systems that support Secure Boot and have an EFI boot loader signed with one of the authorized keys can boot when Secure Boot is enabled. For more information about supported operating systems, go to the HP UEFI System Utilities and Shell Release Notes on the HP website http://www.hp.com/go/ProLiantUEFI/docs. A physically present user can customize the certificates embedded in the UEFI BIOS by adding/removing their own certificates. Embedded UEFI shell The system BIOS in all HP ProLiant Gen9 servers includes an embedded UEFI Shell in the ROM. The UEFI Shell environment provides an API, a command line prompt, and a set of CLIs that allow scripting, file manipulation, and system information. These features enhance the capabilities of the UEFI System Utilities. For more information, see the following documents: ● HP UEFI Shell User Guide for HP ProLiant Gen9 Servers on the HP website http://www.hp.com/go/ ProLiantUEFI/docs ● UEFI Shell Specification on the UEFI website http://www.uefi.org/specifications Embedded UEFI diagnostics The system BIOS in all HP ProLiant Gen9 servers includes an embedded UEFI diagnostics tool in the ROM. The embedded UEFI diagnostics tool can run comprehensive diagnostics of the server hardware, including processors, memory, drives, and other server components. For more information on the embedded UEFI diagnostics tool, go to the HP UEFI System Utilities User Guide for HP ProLiant Gen9 Servers on the HP website http://www.hp.com/go/ProLiantUEFI/docs. HP RESTful API support for UEFI HP ProLiant Gen9 servers include support for a UEFI compliant System BIOS, along with UEFI System Utilities and Embedded UEFI Shell pre-boot environments. HP ProLiant Gen9 servers also support configuring the UEFI BIOS settings using the HP RESTful API, a management interface that server management tools can use to perform configuration, inventory, and monitoring of an HP ProLiant server. A REST client uses HTTPS operations to configure supported server settings, such as UEFI BIOS settings. HP UEFI System Utilities 105

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133

You can also configure default settings as necessary, and then save the configuration as the custom default
configuration. When the system loads the default settings, it uses the custom default settings instead of the
factory defaults.
Secure Boot configuration
Secure Boot is integrated in the UEFI specification on which the HP implementation of UEFI is based. Secure
Boot is completely implemented in the BIOS and does not require special hardware. It ensures that each
component launched during the boot process is digitally signed and that the signature is validated against a
set of trusted certificates embedded in the UEFI BIOS. Secure Boot validates the software identity of the
following components in the boot process:
UEFI drivers loaded from PCIe cards
UEFI drivers loaded from mass storage devices
Pre-boot UEFI shell applications
OS UEFI boot loaders
Once enabled, only firmware components and operating systems with boot loaders that have an appropriate
digital signature can execute during the boot process. Only operating systems that support Secure Boot and
have an EFI boot loader signed with one of the authorized keys can boot when Secure Boot is enabled. For
more information about supported operating systems, go to the
HP UEFI System Utilities and Shell Release
Notes
on the HP website
go/ProLiantUEFI/docs
.
A physically present user can customize the certificates embedded in the UEFI BIOS by adding/removing their
own certificates.
Embedded UEFI shell
The system BIOS in all HP ProLiant Gen9 servers includes an embedded UEFI Shell in the ROM. The UEFI Shell
environment provides an API, a command line prompt, and a set of CLIs that allow scripting, file
manipulation, and system information. These features enhance the capabilities of the UEFI System Utilities.
For more information, see the following documents:
HP UEFI Shell User Guide for HP ProLiant Gen9 Servers
on the HP website
go/
ProLiantUEFI/docs
UEFI Shell Specification
on the UEFI website
specifications
Embedded UEFI diagnostics
The system BIOS in all HP ProLiant Gen9 servers includes an embedded UEFI diagnostics tool in the ROM. The
embedded UEFI diagnostics tool can run comprehensive diagnostics of the server hardware, including
processors, memory, drives, and other server components.
For more information on the embedded UEFI diagnostics tool, go to the
HP UEFI System Utilities User Guide
for HP ProLiant Gen9 Servers
on the HP website
go/ProLiantUEFI/docs
.
HP RESTful API support for UEFI
HP ProLiant Gen9 servers include support for a UEFI compliant System BIOS, along with UEFI System Utilities
and Embedded UEFI Shell pre-boot environments. HP ProLiant Gen9 servers also support configuring the
UEFI BIOS settings using the HP RESTful API, a management interface that server management tools can use
to perform configuration, inventory, and monitoring of an HP ProLiant server. A REST client uses HTTPS
operations to configure supported server settings, such as UEFI BIOS settings.
HP UEFI System Utilities
105