diff --git a/src/southbridge/intel/common/firmware/Kconfig b/src/southbridge/intel/common/firmware/Kconfig index 8ad1fede41..2767c0e316 100644 --- a/src/southbridge/intel/common/firmware/Kconfig +++ b/src/southbridge/intel/common/firmware/Kconfig @@ -92,4 +92,18 @@ config IFD_PLATFORM_SECTION string default "" +config LOCK_MANAGEMENT_ENGINE + bool "Lock ME/TXE section" + depends on HAVE_ME_BIN + default n + help + The Intel Firmware Descriptor supports preventing write accesses + from the host to the ME or TXE section in the firmware + descriptor. If the section is locked, it can only be overwritten + with an external SPI flash programmer. You will want this if you + want to increase security of your ROM image once you are sure + that the ME/TXE firmware is no longer going to change. + + If unsure, say N. + endif #INTEL_FIRMWARE