Intel Firmware Descriptor: Add Lock ME Kconfig question

Add the Kconfig question to allow the user to lock the ME section
using ifdtool.

Change-Id: I46018c3bc9df3e309aa3083d693cbebf00e18062
Signed-off-by: Martin Roth <gaumless@gmail.com>
Reviewed-on: http://review.coreboot.org/10648
Tested-by: build bot (Jenkins)
Reviewed-by: Stefan Reinauer <stefan.reinauer@coreboot.org>
This commit is contained in:
Martin Roth 2015-06-23 21:47:19 -06:00 committed by Stefan Reinauer
parent c407cb97bc
commit 775d50828e
1 changed files with 14 additions and 0 deletions

View File

@ -92,4 +92,18 @@ config IFD_PLATFORM_SECTION
string
default ""
config LOCK_MANAGEMENT_ENGINE
bool "Lock ME/TXE section"
depends on HAVE_ME_BIN
default n
help
The Intel Firmware Descriptor supports preventing write accesses
from the host to the ME or TXE section in the firmware
descriptor. If the section is locked, it can only be overwritten
with an external SPI flash programmer. You will want this if you
want to increase security of your ROM image once you are sure
that the ME/TXE firmware is no longer going to change.
If unsure, say N.
endif #INTEL_FIRMWARE