TDX disabled in bios
matti opened this issue · 7 comments
Okay so in here by an Intel employee Kai Huang kai.huang@intel.com https://patchwork.kernel.org/project/kvm/patch/062075b36150b119bf2d0a1262de973b0a2b11a7.1654025431.git.kai.huang@intel.com/
It says that
To enable TDX, BIOS needs to configure SEAMRR (core-scope) and TDX
private KeyIDs (package-scope) consistently for all packages. TDX
doesn't trust BIOS. TDX ensures all BIOS configurations are correct,
and if not, refuses to enable SEAMRR on any core. This means detecting
SEAMRR alone on BSP is enough to check whether TDX has been enabled by
BIOS.
So it's not clear if BIOS even needs to be enabled. Meanwhile I've updated to the latest BIOS and firmware.
For the general requirement on HW and BIOS, you can refer to the chapter 2 at https://www.intel.com/content/www/us/en/content-details/780133/whitepaper-linux-stacks-for-intel-trust-domain-extension-1-0.html
But it may various on different vendor's hardware and BIOS. So you may need contact sales or vendor for TDX support status.
This link does not give any concrete information.
I have contacted Asus on this.
This link does not give any concrete information.
I have contacted Asus on this.
Thanks!
@matti did you have any luck with the support? I am in the same situation. Thanks in advnce for your time!
@rezabfil-sec not yet, the case is still open. what hardware do you have?
feel free to email me at matti.paksula@iki.fi