Intel Firmware Descriptor: Add Lock ME Kconfig question
Add the Kconfig question to allow the user to lock the ME section using ifdtool. Change-Id: I46018c3bc9df3e309aa3083d693cbebf00e18062 Signed-off-by: Martin Roth <gaumless@gmail.com> Reviewed-on: http://review.coreboot.org/10648 Tested-by: build bot (Jenkins) Reviewed-by: Stefan Reinauer <stefan.reinauer@coreboot.org>
This commit is contained in:
parent
c407cb97bc
commit
775d50828e
|
@ -92,4 +92,18 @@ config IFD_PLATFORM_SECTION
|
|||
string
|
||||
default ""
|
||||
|
||||
config LOCK_MANAGEMENT_ENGINE
|
||||
bool "Lock ME/TXE section"
|
||||
depends on HAVE_ME_BIN
|
||||
default n
|
||||
help
|
||||
The Intel Firmware Descriptor supports preventing write accesses
|
||||
from the host to the ME or TXE section in the firmware
|
||||
descriptor. If the section is locked, it can only be overwritten
|
||||
with an external SPI flash programmer. You will want this if you
|
||||
want to increase security of your ROM image once you are sure
|
||||
that the ME/TXE firmware is no longer going to change.
|
||||
|
||||
If unsure, say N.
|
||||
|
||||
endif #INTEL_FIRMWARE
|
||||
|
|
Loading…
Reference in New Issue