Table 11. System setup options—Security menu
Security
TPM 2.0 Security On Select whether or not the Trusted Platform Model (TPM) is visible to the OS.
Default: ON
Attestation Enable Enables to control whether the TPM Endorsement Hierarchy is available to the
OS. Disabling this setting restricts the ability to use the TPM for signature
operations.
Default: ON
Key Storage Enable Enables to control whether the TPM Endorsement Hierarchy is available to the
OS. Disabling this setting restricts the ability to use the TPM for storing owner
data.
Default: ON
SHA-256 Enables or disables the BIOS and the TPM to use the SHA-256 hash algorithm
to extend measurements into the TPM PCRs during BIOS boot.
Default: ON
Clear Enables or disables the computer to clear the PTT owner information, and
returns the PTT to the default state.
Default: OFF
PPI Bypass for Clear Commands Enables or disables the operating system to skip BIOS Physical Presence
Interface (PPI) user prompts when issuing the Clear command.
Default: OFF
PPI Bypass for Enable Commands Enables or disables the OS to skip BIOS Physical Presence Interface (PPI) user
prompts when issuing TPM PPI enabled and activate commands.
Default: OFF
PPI Bypass for Disable Commands Enables or disables The OS to skip BIOS PPI user prompts when issuing TPM
PPI Disable and Deactivate commands.
Default: OFF
Intel Total Memory Encryption
Multi-Key Total Memory Encryption (Up
to 16 keys)
Enable or disable the protection of memory from physical attacks including
freeze spray, probing DDR to read the cycles, and others. When enabled, the
system memory is encrypted bu the Total Memory Encryption (TME) block
attached to the memory controller.
Default: OFF
Chassis intrusion
Chassis intrusion Controls the chassis intrusion feature.
Default: Disabled
NOTE: This feature detects when the base cover has been removed from
the computer.
Block Boot Until Cleared Enables or disables the "Block Boot Until Cleared" setting.
Default: ON
NOTE: When this feature is turned on, the computer will not boot up until
the chassis intrusion is cleared. If the Administrator password is set, Setup
has to be unlocked before the warning can be cleared.
TPM State Enables or disables the TPM. This is the normal operating state for the TPM
when you want to use its complete array of capabilities.
System setup 53