Do you have a question about the Supermicro X12 and is the answer not in the manual?
Provides information on Secure Boot configuration in the UEFI BIOS Setup utility for Supermicro's X12 Series motherboards.
Provides detailed instructions on configuring Secure Boot settings in the UEFI BIOS for X12 motherboards based on 3rd Gen Intel® Xeon® Scalable Processors.
Highlights important symbols for proper BIOS configuration and prevention of accidental damage to system components.
Provides address, telephone, fax, email, and website for Super Micro Computer, Inc. headquarters.
Provides contact details for Super Micro Computer B.V. in Europe, including address, phone, fax, and email.
Provides contact details for Super Micro Computer, Inc. in the Asia-Pacific region, including address, phone, fax, and email.
Explains how to set the system's boot mode to UEFI, a prerequisite for enabling Secure Boot features.
Details enabling Secure Boot, setting mode to Custom, and disabling CSM support for optimal configuration.
Guides users on setting Secure Boot Mode to Standard and installing manufacturer default keys.
Covers managing Secure Boot keys, available when Secure Boot Mode is set to Custom.
This document outlines the secure boot configuration instructions for Supermicro X12 motherboards, designed for system integrators, IT technicians, and knowledgeable end-users. It focuses on enabling and managing the Secure Boot feature within the Unified Extensible Firmware Interface (UEFI) BIOS.
Secure Boot is a critical security feature integrated into the UEFI BIOS. Its primary function is to enhance system security by preventing unauthorized drivers and operating system loaders from booting. This is achieved by ensuring that all boot loaders are digitally signed and validated before the system starts. If a boot loader lacks an acceptable digital signature or if the signature is invalid, Secure Boot will prevent it from loading, thereby protecting the system from malicious software, rootkits, and other unauthorized code that might attempt to compromise the boot process. The X12 motherboards, based on 3rd Gen Intel® Xeon® Scalable Processors, leverage this feature to provide a more secure computing environment. Proper configuration of Secure Boot settings is essential for the secure operation of the machine.
The configuration process for Secure Boot involves several key steps within the UEFI BIOS Setup utility.
Setting Boot Mode to UEFI: Secure Boot is a UEFI-specific feature, so the first step is to ensure that the system's boot mode is set to UEFI. This is done by accessing the BIOS Setup utility (typically by pressing <Del> during system boot), navigating to the "Boot" tab, and selecting "UEFI" from the "Boot Mode Select" options. After making this change, the settings must be saved, and the system rebooted for the changes to take effect.
Enabling Secure Boot and CSM Support: After setting the boot mode to UEFI, the next step is to enable the Secure Boot feature itself. Within the BIOS Setup utility, under the "Security" tab, users will find the "Secure Boot" menu. Here, "Secure Boot" needs to be set to "Enabled." Concurrently, "CSM Support" (Compatibility Support Module) must be disabled. Disabling CSM ensures that the system operates exclusively in UEFI mode, which is a prerequisite for Secure Boot. Once these settings are adjusted, saving and exiting the BIOS Setup utility will apply the changes. It's important to note that once Secure Boot is enabled, CSM Support will become disabled automatically, and the legacy platform will no longer be supported. Only authorized UEFI applications, such as UEFI OS, AOC UEFI FW, and UEFI PXE server, will be allowed to run on the platform.
Secure Boot Mode Configuration: Within the "Secure Boot" menu, users can set the "Secure Boot Mode" to either "Standard" or "Custom."
Key Management Settings (Custom Mode Only): The "Key Management" menu is accessible only when "Secure Boot Mode" is set to "Custom." This menu allows for the installation, export, update, append, and deletion of various Secure Boot keys and signatures. The key hierarchy in Secure Boot includes:
The Secure Boot configuration includes several features that aid in maintaining the integrity and security of the boot process:
Restore Factory Keys: This option, available under "Key Management," allows users to restore the manufacturer's default Secure Boot keys. Selecting "Yes" will install these keys and reset the system to User mode, ensuring a known secure state. This is useful if custom keys become corrupted or if the user wishes to revert to the default security configuration.
Reset To Setup Mode: When the system is in User mode, this feature allows users to clear all Secure Boot values and reset the system to Setup mode. This is a more drastic reset than restoring factory keys and can be used to completely reconfigure Secure Boot from scratch.
Export Secure Boot Variables: This feature enables users to export the current Secure Boot values (PK, KEK, DB, DBX, DBT, DBR) to files in a root folder on a file system device, typically a FAT-formatted USB flash drive. This is crucial for backup purposes, allowing users to restore their specific Secure Boot configurations if needed.
Enroll EFI Image: This feature allows users to enroll SHA256 hash binary data into the Authorized Signature Database (DB). This enables specific PE images (e.g., custom boot loaders or drivers) to run in Secure Boot mode, providing flexibility for specialized system configurations while maintaining security.
Device Guard Ready Options:
These features collectively provide comprehensive control over the Secure Boot environment, allowing for both simplified default configurations and advanced, customized security management. The emphasis on digital signatures and key management ensures that the X12 motherboards maintain a robust defense against unauthorized boot processes, contributing to overall system integrity and reliability.
| Memory Slots | 4 |
|---|---|
| Maximum Memory Supported | 128GB |
| Form Factor | ATX |
| CPU Socket | LGA 1200 |
| Chipset | Intel C256 |
| Memory Type | DDR4 |
| PCIe 4.0 x16 Slots | 1 |
| RAID Support | 0, 1, 5, 10 |











