HP Scanjet 5000 User Guide - Page 96

Retaining the recovery key/password, Enabling the Trusted Platform Module, HP Trusted Platform Module

Page 96 highlights

Retaining the recovery key/password The recovery key/password is generated during BitLocker setup, and can be saved and printed after BitLocker is enabled. When using BitLocker, always retain the recovery key/password. The recovery key/ password is required to enter Recovery Mode after BitLocker detects a possible compromise of system integrity. To help ensure maximum security, observe the following guidelines when retaining the recovery key/ password: ● Always store the recovery key/password in multiple locations. ● Always store copies of the recovery key/password away from the server. ● Do not save the recovery key/password on the encrypted hard drive. Enabling the Trusted Platform Module 1. During the server start-up sequence, press the F9 key to access System Utilities. 2. From the System Utilities screen, select System Configuration > BIOS/Platform Configuration (RBSU) > Server Security. 3. Select Trusted Platform Module Options and press the Enterkey. 4. Select Enabled to enable the TPM and BIOS secure startup. The TPM is fully functional in this mode. 5. Press the F10 key to save your selection. 6. When prompted to save the change in System Utilities, press the Ykey. 7. Press the ESC key to exit System Utilities. Then, press the Enter key when prompted to reboot the server. The server then reboots a second time without user input. During this reboot, the TPM setting becomes effective. You can now enable TPM functionality in the OS, such as Microsoft Window BitLocker or measured boot. CAUTION: When a TPM is installed and enabled on the server, data access is locked if you fail to follow the proper procedures for updating the system or option firmware, replacing the system board, replacing a hard drive, or modifying OS application TPM settings. For more information on firmware updates and hardware procedures, go to the HP Trusted Platform Module Best Practices White Paper on the HP website http://www.hp.com/support. For more information on adjusting TPM usage in BitLocker, go to the Microsoft website http://technet.microsoft.com/en-us/library/cc732774.aspx. 88 Chapter 5 Hardware options installation

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133

Retaining the recovery key/password
The recovery key/password is generated during BitLocker setup, and can be saved and printed after
BitLocker is enabled. When using BitLocker, always retain the recovery key/password. The recovery key/
password is required to enter Recovery Mode after BitLocker detects a possible compromise of system
integrity.
To help ensure maximum security, observe the following guidelines when retaining the recovery key/
password:
Always store the recovery key/password in multiple locations.
Always store copies of the recovery key/password away from the server.
Do not save the recovery key/password on the encrypted hard drive.
Enabling the Trusted Platform Module
1.
During the server start-up sequence, press the
F9
key to access System Utilities.
2.
From the System Utilities screen, select
System Configuration
>
BIOS/Platform Configuration (RBSU)
>
Server Security
.
3.
Select
Trusted Platform Module Options
and press the
Enter
key.
4.
Select
Enabled
to enable the TPM and BIOS secure startup. The TPM is fully functional in this mode.
5.
Press the
F10
key to save your selection.
6.
When prompted to save the change in System Utilities, press the
Y
key.
7.
Press the
ESC
key to exit System Utilities. Then, press the
Enter
key when prompted to reboot the
server.
The server then reboots a second time without user input. During this reboot, the TPM setting becomes
effective.
You can now enable TPM functionality in the OS, such as Microsoft Window BitLocker or measured boot.
CAUTION:
When a TPM is installed and enabled on the server, data access is locked if you fail to follow the
proper procedures for updating the system or option firmware, replacing the system board, replacing a hard
drive, or modifying OS application TPM settings.
For more information on firmware updates and hardware procedures, go to the
HP Trusted Platform Module
Best Practices White Paper
on the HP website
support
.
For more information on adjusting TPM usage in BitLocker, go to the Microsoft website
en-us/library/cc732774.aspx
.
88
Chapter 5
Hardware options installation