Difference between revisions of "IC-OS Installation - UEFI Configuration - Gen2 Gigabyte"

From Internet Computer Wiki
Jump to: navigation, search
(Add correct images)
Line 2: Line 2:
  
 
# Reboot or power on the server.
 
# Reboot or power on the server.
# Watch for the screen with the Gigabyte logo and boot options underneath it. Press DEL (delete) a couple of times, once the options are listed.
+
# Watch for the screen with the Gigabyte logo and boot options underneath it. Press DEL (delete) a couple of times, once the options are listed to enter setup.
#: [[File:Gigabyte loading screen.jpg|580px]]
+
#:[[File:Gigabyte loading screen.jpg|580px]]
  
== 2. UEFI - Check Version ==
+
==2. UEFI - Check Version==
  
# Check the version number at the bottom of the screen. Ensure the UEFI/BIOS version is '''2.21.1280''' or higher. This version was tested and found to support features required for IC-OS.
+
#Check the version number at the bottom of the screen. Ensure the UEFI/BIOS version is '''2.21.1280''' or higher. This version was tested and found to support features required for IC-OS.
#* Is your version lower than '''2.21.1280'''? Download the latest version and follow the included instructions at the [https://www.supermicro.com/en/support/resources/downloadcenter/swdownload Supermicro support site]
+
#*Is your version lower than '''2.21.1280'''? Download the latest version and follow the included instructions at the [https://www.gigabyte.com/Support Gigabyte support site]
* TOO FIX WITH GIGABYTE SUPPORT
+
==3. UEFI - Advanced Settings==
  
== 3. UEFI - Advanced Settings ==
+
#Change to the '''Advanced''' menu. Then select '''PCI Subsystem Settings''' and press '''enter'''
 +
#:[[File:Gigabyte bios 15.jpg|580px]]
 +
#Set '''SR-IOV Support''' to Enabled (scroll to bottom of page to find setting); then press '''escape''' to return to the '''Advanced''' main menu.
 +
#:[[File:Gigabyte bios 16.jpg|580px]]
 +
#Select '''Trusted Computing'''
 +
#:[[File:Gigabyte bios 17.jpg|580px]]
 +
#Set '''Security Device Support''' to '''Enabled'''
 +
#Set '''SHA256 PCR Bank''' to '''Enabled'''
 +
#Set '''Platform Hierarchy''' to '''Enabled'''
 +
#Set '''Storage Hierarchy''' to '''Enabled'''
 +
#Set '''Endorsement Hierarchy''' to '''Enabled'''
 +
#:[[File:Gigabyte bios 18.jpg|580px]]
 +
#Press '''escape''' to return to the '''Advanced''' main menu.
  
# Change to the '''Advanced''' menu. Then select '''PCI Subsystem Settings''' and press enter
+
== 4. UEFI - AMD CBS==
[[File:Gigabyte bios 15.jpg|580px]]
 
# Set '''SR-IOV Support''' to Enabled (scroll to bottom of page)
 
#: [[File:Gigabyte bios 16.jpg|580px]]
 
# Select '''Trusted Computing'''
 
#: [[File:Gigabyte bios 17.jpg|580px]]
 
# Set '''Security Device Support''' to '''Enabled'''
 
# Set '''SHA256 PCR Bank''' to '''Enabled'''
 
# Set '''Platform Hierarchy''' to '''Enabled'''
 
# Set '''Storage Hierarchy''' to '''Enabled'''
 
# Set '''Endorsement Hierarchy''' to '''Enabled'''
 
#: [[File:Gigabyte bios 18.jpg|580px]]
 
  
== 4. UEFI - AMD CBS ==
+
# Change to the '''AMD CBS''' menu. Then select '''CPU Common Options''' and press '''enter'''
 
+
#:[[File:Gigabyte bios CPU common options.jpg|580px]]
# Change to the '''AMD CBS''' menu. Then select '''CPU Common Options''' and press enter
 
#: [[File:Gigabyte bios CPU common options.jpg|580px]]
 
# Set '''SMEE''' to '''Enabled'''
 
 
# Set '''SEV-ES ASID Space Limit Control''' to '''Manual'''
 
# Set '''SEV-ES ASID Space Limit Control''' to '''Manual'''
# Set '''SEV-ES ASID Space Limit''' to '''100'''
+
#Set '''SEV-ES ASID Space Limit''' to '''100'''
# Set '''SNP Memory (RMP Table) Coverage''' to '''Enabled'''
+
#Set '''SNP Memory (RMP Table) Coverage''' to '''Enabled'''
#: [[File:Gigabyte bios 12.jpg|580px]]
+
#Set '''SMEE''' to '''Enabled'''
# Press ESC (escape) to return to previous menu
+
#:[[File:Gigabyte bios 12.jpg|580px]]
# Select '''NBIO Common Options''' and press enter
+
#Press '''escape''' to return to the '''AMD CBS''' main menu.
#: [[File:Gigabyte bios 13.jpg|580px]]
+
#Select '''NBIO Common Options''' and press '''enter'''
 +
#:[[File:Gigabyte bios 13.jpg|580px]]
 
# Set '''SEV-SNP Support''' to '''Enabled'''
 
# Set '''SEV-SNP Support''' to '''Enabled'''
#: [[File:Gigabyte bios 14.jpg|580px]]
+
#:[[File:Gigabyte bios 14.jpg|580px]]
 +
#Press '''escape''' to return to the '''AMD CBS''' main menu.
  
== 5. UEFI - Boot Menu ==
+
== 5. UEFI - Boot Menu==
  
# Change to the '''Boot''' menu; Set '''Boot Mode Select''' to '''UEFI'''
+
#Change to the '''Boot''' menu. Then set '''Boot Mode Select''' to '''UEFI'''
#: [[File:Gigabyte bios 19.jpg|580px]]
+
#:[[File:Gigabyte bios 19.jpg|580px]]
# Change to '''Save Changes and Exit'', then select '''Yes''' at the prompt and press enter.
+
#Select '''Save Changes and Exit'', then select '''''<nowiki/>''Yes''<nowiki/>''<nowiki/>'<nowiki/>'' at''<nowiki/>'' the prompt and press '''enter'''.
#: [[File:Gigabyte bios 21.jpg|580px]]
+
#:[[File:Gigabyte bios 21.jpg|580px]]
 
The system will now reboot. Please do not unplug the IC-OS USB stick at this point.
 
The system will now reboot. Please do not unplug the IC-OS USB stick at this point.
  
== 6. Boot the IC-OS USB image ==
+
==6. Boot the IC-OS USB image==
# Watch for the screen with the Gigabyte logo and boot options underneath it. Press F10 a couple of times, once the options are listed.
+
#Watch for the screen with the Gigabyte logo and boot options underneath it. Press F10 a couple of times, once the options are listed.
#: [[File:Gigabyte loading screen.jpg|580px]]
+
#:[[File:Gigabyte loading screen.jpg|580px]]
# In the boot menu, select the ''first partition on the USB device'' and press enter, e.g.:
+
#In the boot menu, select the ''first partition on the USB device'' and press '''enter''', e.g.:
#: [[File:Gigabyte bios 22.jpg|580px]]
+
#:[[File:Gigabyte bios 22.jpg|580px]]
 
<br>
 
<br>
  
== Return to the Installation Runbook ==
+
==Return to the Installation Runbook==
  
* If using the '''non-HSM''' onboarding procedure, return to the [[IC-OS Installation Runbook#8. UEFI Setup and Boot Menu|IC-OS Installation Runbook]].
+
*If using the '''non-HSM''' onboarding procedure, return to the [[IC-OS Installation Runbook#8. UEFI Setup and Boot Menu|IC-OS Installation Runbook]].
  
* If using the '''legacy, HSM''' onboarding procedure, return to the [[NitroKey HSM installation runbook#8. UEFI Setup and Boot Menu|NitroKey HSM installation runbook]]
+
*If using the '''legacy, HSM''' onboarding procedure, return to the [[NitroKey HSM installation runbook#8. UEFI Setup and Boot Menu|NitroKey HSM installation runbook]]

Revision as of 20:12, 27 July 2023

1. UEFI - Enter Setup

  1. Reboot or power on the server.
  2. Watch for the screen with the Gigabyte logo and boot options underneath it. Press DEL (delete) a couple of times, once the options are listed to enter setup.
    Gigabyte loading screen.jpg

2. UEFI - Check Version

  1. Check the version number at the bottom of the screen. Ensure the UEFI/BIOS version is 2.21.1280 or higher. This version was tested and found to support features required for IC-OS.
    • Is your version lower than 2.21.1280? Download the latest version and follow the included instructions at the Gigabyte support site

3. UEFI - Advanced Settings

  1. Change to the Advanced menu. Then select PCI Subsystem Settings and press enter
    Gigabyte bios 15.jpg
  2. Set SR-IOV Support to Enabled (scroll to bottom of page to find setting); then press escape to return to the Advanced main menu.
    Gigabyte bios 16.jpg
  3. Select Trusted Computing
    Gigabyte bios 17.jpg
  4. Set Security Device Support to Enabled
  5. Set SHA256 PCR Bank to Enabled
  6. Set Platform Hierarchy to Enabled
  7. Set Storage Hierarchy to Enabled
  8. Set Endorsement Hierarchy to Enabled
    Gigabyte bios 18.jpg
  9. Press escape to return to the Advanced main menu.

4. UEFI - AMD CBS

  1. Change to the AMD CBS menu. Then select CPU Common Options and press enter
    Gigabyte bios CPU common options.jpg
  2. Set SEV-ES ASID Space Limit Control to Manual
  3. Set SEV-ES ASID Space Limit to 100
  4. Set SNP Memory (RMP Table) Coverage to Enabled
  5. Set SMEE to Enabled
    Gigabyte bios 12.jpg
  6. Press escape to return to the AMD CBS main menu.
  7. Select NBIO Common Options and press enter
    Gigabyte bios 13.jpg
  8. Set SEV-SNP Support to Enabled
    Gigabyte bios 14.jpg
  9. Press escape to return to the AMD CBS main menu.

5. UEFI - Boot Menu

  1. Change to the Boot menu. Then set Boot Mode Select to UEFI
    Gigabyte bios 19.jpg
  2. Select Save Changes and Exit, then select Yes' at the prompt and press enter.
    Gigabyte bios 21.jpg

The system will now reboot. Please do not unplug the IC-OS USB stick at this point.

6. Boot the IC-OS USB image

  1. Watch for the screen with the Gigabyte logo and boot options underneath it. Press F10 a couple of times, once the options are listed.
    Gigabyte loading screen.jpg
  2. In the boot menu, select the first partition on the USB device and press enter, e.g.:
    Gigabyte bios 22.jpg


Return to the Installation Runbook