oe-chipsec.lists.linux.dev archive mirror
 help / color / mirror / Atom feed
* Re: BIOS Guard Security Configuration
       [not found] <DM6PR11MB300452FACA496B4516AF375C9E869@DM6PR11MB3004.namprd11.prod.outlook.com>
@ 2021-10-28 20:16 ` Tal Lubko
  0 siblings, 0 replies; 3+ messages in thread
From: Tal Lubko @ 2021-10-28 20:16 UTC (permalink / raw)
  To: chipsec

[-- Attachment #1: Type: text/plain, Size: 2217 bytes --]

Yep

Sent from Yahoo Mail on Android 
 
  On Thu, Oct 28, 2021 at 23:03, Frinzell, Aaron<aaron.frinzell@intel.com> wrote:   <!--#yiv3014457062 _filtered {} _filtered {} _filtered {}#yiv3014457062 #yiv3014457062 p.yiv3014457062MsoNormal, #yiv3014457062 li.yiv3014457062MsoNormal, #yiv3014457062 div.yiv3014457062MsoNormal {margin:0in;font-size:11.0pt;font-family:"Calibri", sans-serif;}#yiv3014457062 a:link, #yiv3014457062 span.yiv3014457062MsoHyperlink {color:#0563C1;text-decoration:underline;}#yiv3014457062 p.yiv3014457062ydp12457c1yiv1228804852msonormal, #yiv3014457062 li.yiv3014457062ydp12457c1yiv1228804852msonormal, #yiv3014457062 div.yiv3014457062ydp12457c1yiv1228804852msonormal {margin-right:0in;margin-left:0in;font-size:11.0pt;font-family:"Calibri", sans-serif;}#yiv3014457062 span.yiv3014457062EmailStyle20 {font-family:"Calibri", sans-serif;color:windowtext;}#yiv3014457062 .yiv3014457062MsoChpDefault {font-size:10.0pt;} _filtered {}#yiv3014457062 div.yiv3014457062WordSection1 {}-->
Hi Tal,
 
  
 
This is a document normally shared though NDA.  If you are associated with an organization that has access to it?
 
  
 
Thanks,
 
  
 
Aaron
 
  
 
From: Tal Lubko <tallubko@yahoo.com> 
Sent: Thursday, October 28, 2021 2:10 PM
To: chipsec(a)lists.01.org; Frinzell, Aaron <aaron.frinzell@intel.com>
Subject: Re: [chipsec] BIOS Guard Security Configuration
 
  
 
Document #557274 in Intel RDC
 
  
 
On Thursday, October 28, 2021, 09:44:53 PM GMT+3, Frinzell, Aaron <aaron.frinzell@intel.com> wrote:
 
  
 
  
 
 
 
Hi Tal,
 
 
 
Are you able to share the link to this document or the source?
 
 
 
Thanks,
 
 
 
Aaron
 
 
 
From: Tal Lubko <tallubko@yahoo.com>
Sent: Thursday, October 28, 2021 12:42 PM
To: chipsec(a)lists.01.org
Subject: [chipsec] BIOS Guard Security Configuration
 
 
 
Hi
 
 
 
I'm looking at "Skylake and Kaby Lake Platform Secure Configuration Specification".
 
It has a section named "BIOS Guard Security Configuration" with several recommendations.
 
For example: Test "BIOS Guard Lock" (this is MSR bit).
 
Why chipsec doesn't verify this bit?
 
 
 
Regards,
 
Tal
 
 
   

[-- Attachment #2: attachment.htm --]
[-- Type: text/html, Size: 8988 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: BIOS Guard Security Configuration
       [not found] <DM6PR11MB3004C8AFBF8D9375909431699E869@DM6PR11MB3004.namprd11.prod.outlook.com>
@ 2021-10-28 19:09 ` Tal Lubko
  0 siblings, 0 replies; 3+ messages in thread
From: Tal Lubko @ 2021-10-28 19:09 UTC (permalink / raw)
  To: chipsec

[-- Attachment #1: Type: text/plain, Size: 798 bytes --]

 Document #557274 in Intel RDC
    On Thursday, October 28, 2021, 09:44:53 PM GMT+3, Frinzell, Aaron <aaron.frinzell@intel.com> wrote:  
 
  
  
 
Hi Tal,
 
  
 
Are you able to share the link to this document or the source?
 
  
 
Thanks,
 
  
 
Aaron
 
  
 
From: Tal Lubko <tallubko@yahoo.com> 
Sent: Thursday, October 28, 2021 12:42 PM
To: chipsec(a)lists.01.org
Subject: [chipsec] BIOS Guard Security Configuration
 
  
 
Hi
 
  
 
I'm looking at "Skylake and Kaby Lake Platform Secure Configuration Specification".
 
It has a section named "BIOS Guard Security Configuration" with several recommendations.
 
For example: Test "BIOS Guard Lock" (this is MSR bit).
 
Why chipsec doesn't verify this bit?
 
  
 
Regards,
 
Tal
 
  
   

[-- Attachment #2: attachment.htm --]
[-- Type: text/html, Size: 3482 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

* BIOS Guard Security Configuration
       [not found] <1581434535.1889091.1635442924028.ref@mail.yahoo.com>
@ 2021-10-28 17:42 ` Tal Lubko
  0 siblings, 0 replies; 3+ messages in thread
From: Tal Lubko @ 2021-10-28 17:42 UTC (permalink / raw)
  To: chipsec

[-- Attachment #1: Type: text/plain, Size: 281 bytes --]

Hi
I'm looking at "Skylake and Kaby Lake Platform Secure Configuration Specification".It has a section named "BIOS Guard Security Configuration" with several recommendations.For example: Test "BIOS Guard Lock" (this is MSR bit).Why chipsec doesn't verify this bit?
Regards,Tal

[-- Attachment #2: attachment.htm --]
[-- Type: text/html, Size: 894 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2021-10-28 20:16 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <DM6PR11MB300452FACA496B4516AF375C9E869@DM6PR11MB3004.namprd11.prod.outlook.com>
2021-10-28 20:16 ` BIOS Guard Security Configuration Tal Lubko
     [not found] <DM6PR11MB3004C8AFBF8D9375909431699E869@DM6PR11MB3004.namprd11.prod.outlook.com>
2021-10-28 19:09 ` Tal Lubko
     [not found] <1581434535.1889091.1635442924028.ref@mail.yahoo.com>
2021-10-28 17:42 ` Tal Lubko

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).