Lenovo ThinkPad X1 Carbon (English) User Guide - Page 89

UEFI BIOS Update Option, Security Chip option

Page 89 highlights

Table 6. Security menu items (continued) Menu item Submenu item Security Chip Security Chip Selection • Active • Inactive • Disabled Security Reporting Options Clear Security Chip • Enter Intel TXT Feature Physical Presence for Provisioning • Disabled • Enabled • Disabled • Enabled Physical Presence for Clear • Disabled • Enabled UEFI BIOS Update Option Flash BIOS Updating by End-Users • Disabled • Enabled Secure RollBack Prevention • Disabled • Enabled Comments re-enabled in the fingerprint software. If you select Active, the security chip is functional. If you select Inactive, the Security Chip option is displayed, but is not functional. If you select Disable the security chip is hidden and is not functional. Enable or disable the following Security Reporting Options; • BIOS ROM String Reporting: BIOS text string • CMOS Reporting: CMOS data • NVRAM Reporting: Security data stored in the Asset ID • SMBIOS Reporting: SMBIOS data Clear the encryption key. Note: Only if you select Active for the security chip, this item will be displayed. Enable or disable Intel Trusted Execution Technology. This option enables or disables the confirmation message when you change the settings of the security chip. This option enable or disables the confirmation message when you clear the security chip. If you select Enabled, all users can update the UEFI BIOS. If you select Disabled, only the person who knows the supervisor password can update the UEFI BIOS. If you select Enabled, you can choose to flash to the previous version of the UEFI BIOS Chapter 6. Advanced configuration 75

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

Table 6. Security menu items (continued)
Menu item
Submenu item
Selection
Comments
re-enabled in the fingerprint
software.
Security Chip
Active
Inactive
Disabled
If you select
Active
, the
security chip is functional.
If you select
Inactive
,
the
Security Chip option
is displayed, but is not
functional. If you select
Disable
the security chip is
hidden and is not functional.
Security Reporting Options
Enable or disable the
following Security
Reporting Options;
BIOS ROM String
Reporting
: BIOS text
string
CMOS Reporting
:
CMOS data
NVRAM Reporting
:
Security data stored in
the Asset ID
SMBIOS Reporting
:
SMBIOS data
Clear Security Chip
Enter
Clear the encryption key.
Note:
Only if you select
Active
for the security chip,
this item will be displayed.
Intel TXT Feature
Disabled
Enabled
Enable or disable Intel
Trusted Execution
Technology.
Physical Presence for
Provisioning
Disabled
Enabled
This option enables or
disables the confirmation
message when you change
the settings of the security
chip.
Security Chip
Physical Presence for Clear
Disabled
Enabled
This option enable or
disables the confirmation
message when you clear
the security chip.
Flash BIOS Updating by
End-Users
Disabled
Enabled
If you select
Enabled
,
all users can update the
UEFI BIOS. If you select
Disabled
, only the person
who knows the supervisor
password can update the
UEFI BIOS.
UEFI BIOS Update Option
Secure RollBack Prevention
Disabled
Enabled
If you select
Enabled
, you
can choose to flash to the
previous version of the
UEFI BIOS
Chapter 6
.
Advanced configuration
75