* Re: BIOS Guard Security Configuration [not found] <DM6PR11MB3004C8AFBF8D9375909431699E869@DM6PR11MB3004.namprd11.prod.outlook.com> @ 2021-10-28 19:09 ` Tal Lubko 0 siblings, 0 replies; 3+ messages in thread From: Tal Lubko @ 2021-10-28 19:09 UTC (permalink / raw) To: chipsec [-- Attachment #1: Type: text/plain, Size: 798 bytes --] Document #557274 in Intel RDC On Thursday, October 28, 2021, 09:44:53 PM GMT+3, Frinzell, Aaron <aaron.frinzell@intel.com> wrote: Hi Tal, Are you able to share the link to this document or the source? Thanks, Aaron From: Tal Lubko <tallubko@yahoo.com> Sent: Thursday, October 28, 2021 12:42 PM To: chipsec(a)lists.01.org Subject: [chipsec] BIOS Guard Security Configuration Hi I'm looking at "Skylake and Kaby Lake Platform Secure Configuration Specification". It has a section named "BIOS Guard Security Configuration" with several recommendations. For example: Test "BIOS Guard Lock" (this is MSR bit). Why chipsec doesn't verify this bit? Regards, Tal [-- Attachment #2: attachment.htm --] [-- Type: text/html, Size: 3482 bytes --] ^ permalink raw reply [flat|nested] 3+ messages in thread
[parent not found: <DM6PR11MB300452FACA496B4516AF375C9E869@DM6PR11MB3004.namprd11.prod.outlook.com>]
* Re: BIOS Guard Security Configuration [not found] <DM6PR11MB300452FACA496B4516AF375C9E869@DM6PR11MB3004.namprd11.prod.outlook.com> @ 2021-10-28 20:16 ` Tal Lubko 0 siblings, 0 replies; 3+ messages in thread From: Tal Lubko @ 2021-10-28 20:16 UTC (permalink / raw) To: chipsec [-- Attachment #1: Type: text/plain, Size: 2217 bytes --] Yep Sent from Yahoo Mail on Android On Thu, Oct 28, 2021 at 23:03, Frinzell, Aaron<aaron.frinzell@intel.com> wrote: <!--#yiv3014457062 _filtered {} _filtered {} _filtered {}#yiv3014457062 #yiv3014457062 p.yiv3014457062MsoNormal, #yiv3014457062 li.yiv3014457062MsoNormal, #yiv3014457062 div.yiv3014457062MsoNormal {margin:0in;font-size:11.0pt;font-family:"Calibri", sans-serif;}#yiv3014457062 a:link, #yiv3014457062 span.yiv3014457062MsoHyperlink {color:#0563C1;text-decoration:underline;}#yiv3014457062 p.yiv3014457062ydp12457c1yiv1228804852msonormal, #yiv3014457062 li.yiv3014457062ydp12457c1yiv1228804852msonormal, #yiv3014457062 div.yiv3014457062ydp12457c1yiv1228804852msonormal {margin-right:0in;margin-left:0in;font-size:11.0pt;font-family:"Calibri", sans-serif;}#yiv3014457062 span.yiv3014457062EmailStyle20 {font-family:"Calibri", sans-serif;color:windowtext;}#yiv3014457062 .yiv3014457062MsoChpDefault {font-size:10.0pt;} _filtered {}#yiv3014457062 div.yiv3014457062WordSection1 {}--> Hi Tal, This is a document normally shared though NDA. If you are associated with an organization that has access to it? Thanks, Aaron From: Tal Lubko <tallubko@yahoo.com> Sent: Thursday, October 28, 2021 2:10 PM To: chipsec(a)lists.01.org; Frinzell, Aaron <aaron.frinzell@intel.com> Subject: Re: [chipsec] BIOS Guard Security Configuration Document #557274 in Intel RDC On Thursday, October 28, 2021, 09:44:53 PM GMT+3, Frinzell, Aaron <aaron.frinzell@intel.com> wrote: Hi Tal, Are you able to share the link to this document or the source? Thanks, Aaron From: Tal Lubko <tallubko@yahoo.com> Sent: Thursday, October 28, 2021 12:42 PM To: chipsec(a)lists.01.org Subject: [chipsec] BIOS Guard Security Configuration Hi I'm looking at "Skylake and Kaby Lake Platform Secure Configuration Specification". It has a section named "BIOS Guard Security Configuration" with several recommendations. For example: Test "BIOS Guard Lock" (this is MSR bit). Why chipsec doesn't verify this bit? Regards, Tal [-- Attachment #2: attachment.htm --] [-- Type: text/html, Size: 8988 bytes --] ^ permalink raw reply [flat|nested] 3+ messages in thread
[parent not found: <1581434535.1889091.1635442924028.ref@mail.yahoo.com>]
* BIOS Guard Security Configuration [not found] <1581434535.1889091.1635442924028.ref@mail.yahoo.com> @ 2021-10-28 17:42 ` Tal Lubko 0 siblings, 0 replies; 3+ messages in thread From: Tal Lubko @ 2021-10-28 17:42 UTC (permalink / raw) To: chipsec [-- Attachment #1: Type: text/plain, Size: 281 bytes --] Hi I'm looking at "Skylake and Kaby Lake Platform Secure Configuration Specification".It has a section named "BIOS Guard Security Configuration" with several recommendations.For example: Test "BIOS Guard Lock" (this is MSR bit).Why chipsec doesn't verify this bit? Regards,Tal [-- Attachment #2: attachment.htm --] [-- Type: text/html, Size: 894 bytes --] ^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2021-10-28 20:16 UTC | newest] Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed) -- links below jump to the message on this page -- [not found] <DM6PR11MB3004C8AFBF8D9375909431699E869@DM6PR11MB3004.namprd11.prod.outlook.com> 2021-10-28 19:09 ` BIOS Guard Security Configuration Tal Lubko [not found] <DM6PR11MB300452FACA496B4516AF375C9E869@DM6PR11MB3004.namprd11.prod.outlook.com> 2021-10-28 20:16 ` Tal Lubko [not found] <1581434535.1889091.1635442924028.ref@mail.yahoo.com> 2021-10-28 17:42 ` Tal Lubko
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox; as well as URLs for NNTP newsgroup(s).