Server Products
Data Center Products including boards, integrated systems, Intel® Xeon® Processors, RAID Storage, and Intel® Xeon® Processors
4761 Discussions

TPM Measurement

MGerl
Beginner
1,788 Views

For TPM enabled Intel Server Boards is there any document that describes what is being measured and stored in PCRs? I have looked at the Technical Product Specifications for a number of boards found http://www.intel.com/p/en_US/support/server here but they only state "The server board implements TPM as per TPM PC Client specifications revision 1.2". The problem is https://www.trustedcomputinggroup.org/files/resource_files/CB0B2BFA-1A4B-B294-D0C3B9075B5AFF17/TCG_PCClientImplementation_1-21_1_00.pdf TPM client specification is huge and has both required and optional requirements and if I don't know what went into the measurements how can they supply me with any level of trust?

This question started when I was experimenting on server (Xeon based but not an Intel Board) and I was trying to see if changing BIOS settings would change the value of PCR1 which according to my research should have been the case. As it turned out none of the BIOS configuration changes (boot order, disabling devices, changing the BIOS password, ...) where effecting the PCR value. Eventually I confirmed with the vendor that they had not implemented any of these measurements which was disappointing. I am looking to avoid a trial and error approach and understand what is actually being measured so I can select a board that meets my needs. So far my inquires to Intel and other manufacturers have been met with generic "We Support TPM" responses. Is there anywhere to get more information?

0 Kudos
3 Replies
Daniel_O_Intel
Employee
463 Views

I don't see any level of detail like that, in any of the public documentation. Are you looking for a board that specifically changes the value of PCR1 when something like the BIOS boot order changes?

0 Kudos
MGerl
Beginner
463 Views

I am looking for a board that measures BIOS settings (like boot order) and extends PCR1 with the measurement. Also I was hoping to be able to understand which settings are being measured.

0 Kudos
Daniel_O_Intel
Employee
463 Views

For Intel boards, it would all depend on the functionality of the AXXTPME5 module. But the hardware guide for that, just points to the same TPM client specification you mention above, which only tells us what MUST, MUST NOT, and MAY be included.

I'll see if I can find anything further on the module in http://www.intel.com/support/motherboards/server/sb/CS-034490.htm Server Products — Intel® Trusted Platform Module AXXTPME3/AXXTPME5 Hardware User's Guide .

0 Kudos
Reply