Intel Firmware Descriptor: Add Lock ME Kconfig question
Add the Kconfig question to allow the user to lock the ME section using ifdtool. Change-Id: I46018c3bc9df3e309aa3083d693cbebf00e18062 Signed-off-by: Martin Roth <gaumless@gmail.com> Reviewed-on: http://review.coreboot.org/10648 Tested-by: build bot (Jenkins) Reviewed-by: Stefan Reinauer <stefan.reinauer@coreboot.org>
This commit is contained in:
parent
c407cb97bc
commit
775d50828e
|
@ -92,4 +92,18 @@ config IFD_PLATFORM_SECTION
|
||||||
string
|
string
|
||||||
default ""
|
default ""
|
||||||
|
|
||||||
|
config LOCK_MANAGEMENT_ENGINE
|
||||||
|
bool "Lock ME/TXE section"
|
||||||
|
depends on HAVE_ME_BIN
|
||||||
|
default n
|
||||||
|
help
|
||||||
|
The Intel Firmware Descriptor supports preventing write accesses
|
||||||
|
from the host to the ME or TXE section in the firmware
|
||||||
|
descriptor. If the section is locked, it can only be overwritten
|
||||||
|
with an external SPI flash programmer. You will want this if you
|
||||||
|
want to increase security of your ROM image once you are sure
|
||||||
|
that the ME/TXE firmware is no longer going to change.
|
||||||
|
|
||||||
|
If unsure, say N.
|
||||||
|
|
||||||
endif #INTEL_FIRMWARE
|
endif #INTEL_FIRMWARE
|
||||||
|
|
Loading…
Reference in New Issue