The Trusted Platform Module (TPM) is a security chip that complies with the TPM standards established by the Trusted Computing Group (TCG). It effectively protects a server from unauthorized access.
The Trusted Cryptography Module (TCM) is a security chip embedded with China's home-grown cryptographic algorithms and engines.
On the Security screen, you can set the TPM function and administrator password. Figure 6-90 and Figure 6-91 show the Security screen. Table 6-69 describes the parameters.
Figure 6-90 Security screen 1![]()
Figure 6-91 Security screen 2![]()
Table 6-69 Parameters on the Security screenParameter
|
Description
|
Default Value
|
TPM Device
|
Sets the TPM device type.
Not Detected indicates that the server has no TPM devices.
- If it is "TPM x.x", the TPM, TPM Active PCR Hash Algorithm, TPM Hardware Supported Hash, TPM Availability, and TPM Operation Clear TPMS parameters are available.
- If it is TCM, the Trusted Platform Support parameter is available.
|
-
|
TPM State
|
Displays the TPM status. The TPM effectively prevents unauthorized access to the server.
|
-
|
TPM Active PCR Hash Algorithm
|
Displays the Platform Configuration Register (PCR) hash algorithms enabled for the TPM.
|
-
|
TPM Hardware Supported Hash Algorithm
|
Displays the Hash algorithms supported by the TPM hardware.
|
-
|
TPM Availability
|
Displays the current status of the TPM.
|
Available
|
TPM Operation
|
Sets the TPM operation menu.
- No Operation
- Enable
- Disable
- DisableEndorsementEnableStorageHierarchy
- SetPCRBanks(Algorithm)
- LogAllDigests
- SetPPRequiredForClear_True
- SetPPRequiredForClear_False
- SetPPRequiredForTurnOn_False
- SetPPRequiredForTurnOn_True
- SetPPRequiredForTurnOff_False
- SetPPRequiredForTurnOff_True
- SetPPRequiredForChangePCRs_False
- SetPPRequiredForChangePCRs_True
- ChangeEPS
|
-
|
Clear TPM
|
Clears the TPM private key.
|
-
|
Supervisor Password
|
Displays the BIOS password status.
- Not Installed: The administrator password is not set. Users can access the BIOS screen without a password.
- Installed: The administrator password is set. This password is required when a user attempts to access the BIOS screen.
|
-
|
User Password
|
Displays the status of the common user password.
- Not Installed: The user password is not set.
- Installed: The user password is set.
|
-
|
Manage Supervisor Password
|
Sets the BIOS password. This password is required when a user attempts to access the BIOS screen.
NOTE: - The password must be a string of 8 to 16 characters and contain special characters (including spaces) and at least two of the following types: uppercase letters, lowercase letters, and digits.
- The new password must be different from the latest five passwords.
- The current password of the system administrator is required before you set or change the password. The system will be locked if an incorrect password is entered for three consecutive times. You can restart the server to unlock it.
- The default password is Admin@9000. For security purposes, change the password upon your first login. To restore the default password, see How Do I Restore the Default BIOS Password?
|
Admin@9000
|
Delete Supervisor Password
|
Delete the administrator password. This parameter is available after the administrator password is set. After the administrator password is deleted, you can access the BIOS screen without a password.
NOTICE: - Deleting the administrator password will reduce system security. Exercise caution when performing this operation.
- Before clearing the password, enter the current administrator password. The system will be locked if an incorrect password is entered for three consecutive times. You can restart the server to unlock it.
|
-
|
Power-On Password
|
Enables or disables the power-on password. If it is set to Enabled, a password is required during the POST of the server.
The options are as follows:
- Enabled: A password is required. Enter the password of the system administrator.
- Disabled: No password is required.
|
Disabled
|
Simple Password
|
Enables and disables the simple password function.
The options are as follows:
- Enabled
- Disabled
NOTICE: - If this parameter is set to Enabled, password complexity check will not be performed. However, the password length must be 8 to 16 characters.
- Enabling the simple password function reduces system security. Exercise caution when you use this parameter.
|
Disabled
|
Set User Password
|
Sets the user password.
NOTE: - The user password can be set only after the administrator password is set.
- The password contains 8 to 16 characters.
- The password must contain special characters and at least two types of the following characters: uppercase letters, lowercase letters, and digits.
- The password cannot be the same as the previous five passwords.
|
-
|
Clear User Password
|
Clears a user password.
NOTE: This parameter is available only when the user password is set.
|
-
|