Skip to content
This repository has been archived by the owner on Mar 27, 2024. It is now read-only.

TDX disabled in bios #348

Closed
matti opened this issue Jun 21, 2023 · 7 comments
Closed

TDX disabled in bios #348

matti opened this issue Jun 21, 2023 · 7 comments
Labels
question Further information is requested

Comments

@matti
Copy link
Contributor

matti commented Jun 21, 2023

I know this is not directly related to tdx-tools, but what could be missing? I can not enable TDX it's not selectable and looks disabled.

The CPU is w3-2423, motherboard is Asus Pro WS W790E-SAGE SE

image

@matti
Copy link
Contributor Author

matti commented Jun 21, 2023

Okay so in here by an Intel employee Kai Huang kai.huang@intel.com https://patchwork.kernel.org/project/kvm/patch/062075b36150b119bf2d0a1262de973b0a2b11a7.1654025431.git.kai.huang@intel.com/

It says that

To enable TDX, BIOS needs to configure SEAMRR (core-scope) and TDX
private KeyIDs (package-scope) consistently for all packages. TDX
doesn't trust BIOS. TDX ensures all BIOS configurations are correct,
and if not, refuses to enable SEAMRR on any core. This means detecting
SEAMRR alone on BSP is enough to check whether TDX has been enabled by
BIOS.

So it's not clear if BIOS even needs to be enabled. Meanwhile I've updated to the latest BIOS and firmware.

@kenplusplus
Copy link
Contributor

For the general requirement on HW and BIOS, you can refer to the chapter 2 at https://www.intel.com/content/www/us/en/content-details/780133/whitepaper-linux-stacks-for-intel-trust-domain-extension-1-0.html

But it may various on different vendor's hardware and BIOS. So you may need contact sales or vendor for TDX support status.

@matti
Copy link
Contributor Author

matti commented Jun 22, 2023

This link does not give any concrete information.

I have contacted Asus on this.

@kenplusplus
Copy link
Contributor

This link does not give any concrete information.

I have contacted Asus on this.

Thanks!

@kenplusplus kenplusplus added the question Further information is requested label Jun 22, 2023
@rezabfil-sec
Copy link

@matti did you have any luck with the support? I am in the same situation. Thanks in advnce for your time!

@matti
Copy link
Contributor Author

matti commented Jun 27, 2023

@rezabfil-sec not yet, the case is still open. what hardware do you have?

feel free to email me at matti.paksula@iki.fi

@matti
Copy link
Contributor Author

matti commented Jul 5, 2023

Basically no Sapphire Rapids supports TDX - Emerald Rapids will, see #399

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

3 participants