Difference between revisions of "IC-OS Installation - UEFI Configuration - Gen2 Gigabyte"

From Internet Computer Wiki
Jump to: navigation, search
m
Line 11: Line 11:
 
==3. UEFI - Advanced Settings==
 
==3. UEFI - Advanced Settings==
  
#Change to the '''Advanced''' menu. Then select '''PCI Subsystem Settings''' and press '''enter'''
+
#Change to the '''Advanced''' menu.
#:[[File:Gigabyte bios 15.jpg|580px]]
 
#Set '''SR-IOV Support''' to Enabled (scroll to bottom of page to find setting); then press '''escape''' to return to the '''Advanced''' main menu.
 
#:[[File:Gigabyte bios 16.jpg|580px]]
 
 
#Select '''Trusted Computing'''
 
#Select '''Trusted Computing'''
 
#:[[File:Gigabyte bios 17.jpg|580px]]
 
#:[[File:Gigabyte bios 17.jpg|580px]]
Line 20: Line 17:
 
#Set '''SHA256 PCR Bank''' to '''Enabled'''
 
#Set '''SHA256 PCR Bank''' to '''Enabled'''
 
#Set '''Platform Hierarchy''' to '''Enabled'''
 
#Set '''Platform Hierarchy''' to '''Enabled'''
#Set '''Storage Hierarchy''' to '''Enabled'''
+
# Set '''Storage Hierarchy''' to '''Enabled'''
 
#Set '''Endorsement Hierarchy''' to '''Enabled'''
 
#Set '''Endorsement Hierarchy''' to '''Enabled'''
 
#:[[File:Gigabyte bios 2.jpg|580px]]
 
#:[[File:Gigabyte bios 2.jpg|580px]]
 +
#Press '''escape''' to return to the '''Advanced''' main menu.
 +
#Select '''CPU Configuration''' and press '''enter'''
 +
#:[[File:Giga bios CPU configuration.png|580px]]
 +
#Set '''SVM Mode''' to '''Enabled'''
 +
#:[[File:Giga bios SVM.png|580px]]
 +
#Select '''PCI Subsystem Settings''' and press '''enter'''
 +
#:[[File:Gigabyte bios 15.jpg|580px]]
 +
#Set '''SR-IOV Support''' to '''Enabled''' (scroll to bottom of page to find setting)
 +
#:[[File:Gigabyte bios 16.jpg|580px]]
 
#Press '''escape''' to return to the '''Advanced''' main menu.
 
#Press '''escape''' to return to the '''Advanced''' main menu.
  
 
== 4. UEFI - AMD CBS==
 
== 4. UEFI - AMD CBS==
  
# Change to the '''AMD CBS''' menu. Then select '''CPU Common Options''' and press '''enter'''
+
#Change to the '''AMD CBS''' menu. Then select '''CPU Common Options''' and press '''enter'''
 
#:[[File:Gigabyte bios CPU common options.jpg|580px]]
 
#:[[File:Gigabyte bios CPU common options.jpg|580px]]
# Set '''SEV-ES ASID Space Limit Control''' to '''Manual'''
+
#Set '''SEV-ES ASID Space Limit Control''' to '''Manual'''
#Set '''SEV-ES ASID Space Limit''' to '''100'''
+
# Set '''SEV-ES ASID Space Limit''' to '''100'''
 
#Set '''SNP Memory (RMP Table) Coverage''' to '''Enabled'''
 
#Set '''SNP Memory (RMP Table) Coverage''' to '''Enabled'''
 
#Set '''SMEE''' to '''Enabled'''
 
#Set '''SMEE''' to '''Enabled'''
Line 54: Line 60:
 
==5. UEFI - Boot Menu==
 
==5. UEFI - Boot Menu==
  
# Change to the '''Boot''' menu. Then set '''Boot Mode Select''' to '''UEFI'''
+
#Change to the '''Boot''' menu. Then set '''Boot Mode Select''' to '''UEFI'''
 
#:[[File:Gigabyte bios 19.jpg|580px]]
 
#:[[File:Gigabyte bios 19.jpg|580px]]
 
#Select '''Save Changes and Exit'', then select '''''<nowiki/>''Yes''<nowiki/>''<nowiki/>'<nowiki/>'' at''<nowiki/>'' the prompt and press '''enter'''.
 
#Select '''Save Changes and Exit'', then select '''''<nowiki/>''Yes''<nowiki/>''<nowiki/>'<nowiki/>'' at''<nowiki/>'' the prompt and press '''enter'''.
Line 60: Line 66:
 
The system will now reboot. Please do not unplug the IC-OS USB stick at this point.
 
The system will now reboot. Please do not unplug the IC-OS USB stick at this point.
  
==6. Boot the IC-OS USB image==
+
== 6. Boot the IC-OS USB image==
 
#Watch for the screen with the Gigabyte logo and boot options underneath it. Press F10 a couple of times, once the options are listed.
 
#Watch for the screen with the Gigabyte logo and boot options underneath it. Press F10 a couple of times, once the options are listed.
 
#:[[File:Gigabyte loading screen.jpg|580px]]
 
#:[[File:Gigabyte loading screen.jpg|580px]]
Line 70: Line 76:
 
==Return to the Installation Runbook==
 
==Return to the Installation Runbook==
  
* If using the '''non-HSM''' onboarding procedure, return to the [[IC-OS Installation Runbook#8. UEFI Setup and Boot Menu|IC-OS Installation Runbook]].
+
*If using the '''non-HSM''' onboarding procedure, return to the [[IC-OS Installation Runbook#8. UEFI Setup and Boot Menu|IC-OS Installation Runbook]].
  
* If using the '''legacy, HSM''' onboarding procedure, return to the [[NitroKey HSM installation runbook#8. UEFI Setup and Boot Menu|NitroKey HSM installation runbook]]
+
*If using the '''legacy, HSM''' onboarding procedure, return to the [[NitroKey HSM installation runbook#8. UEFI Setup and Boot Menu|NitroKey HSM installation runbook]]

Revision as of 16:11, 1 August 2023

1. UEFI - Enter Setup

  1. Reboot or power on the server.
  2. Watch for the screen with the Gigabyte logo and boot options underneath it. Press DEL (delete) a couple of times, once the options are listed to enter setup.
    Gigabyte loading screen.jpg

2. UEFI - Check Version

  1. Check the version number at the bottom of the screen. Ensure the UEFI/BIOS version is 2.21.1280 or higher. This version was tested and found to support features required for IC-OS.
    • Is your version lower than 2.21.1280? Download the latest version and follow the included instructions at the Gigabyte support site

3. UEFI - Advanced Settings

  1. Change to the Advanced menu.
  2. Select Trusted Computing
    Gigabyte bios 17.jpg
  3. Set Security Device Support to Enabled
  4. Set SHA256 PCR Bank to Enabled
  5. Set Platform Hierarchy to Enabled
  6. Set Storage Hierarchy to Enabled
  7. Set Endorsement Hierarchy to Enabled
    Gigabyte bios 2.jpg
  8. Press escape to return to the Advanced main menu.
  9. Select CPU Configuration and press enter
    Giga bios CPU configuration.png
  10. Set SVM Mode to Enabled
    Giga bios SVM.png
  11. Select PCI Subsystem Settings and press enter
    Gigabyte bios 15.jpg
  12. Set SR-IOV Support to Enabled (scroll to bottom of page to find setting)
    Gigabyte bios 16.jpg
  13. Press escape to return to the Advanced main menu.

4. UEFI - AMD CBS

  1. Change to the AMD CBS menu. Then select CPU Common Options and press enter
    Gigabyte bios CPU common options.jpg
  2. Set SEV-ES ASID Space Limit Control to Manual
  3. Set SEV-ES ASID Space Limit to 100
  4. Set SNP Memory (RMP Table) Coverage to Enabled
  5. Set SMEE to Enabled
    Gigabyte bios 1.jpg
  6. Select Performance
    Giga bios performance.png
  7. Set SMT Control to Enabled
    Giga bios SMT.jpg
  8. Press escape twice to return to the AMD CBS main menu.
  9. Select DF Common Options and press enter
    Giga bios DF.png
  10. Select Memory Addressing and press enter
    Giga bios memory addressing.png
  11. Set NUMA nodes per socket to NPS0
    Giga bios NUMA.jpg
  12. Press escape twice to return to the AMD CBS main menu.
  13. Select NBIO Common Options and press enter
    Gigabyte bios 13.jpg
  14. Set SEV-SNP Support to Enabled
    Gigabyte bios 14.jpg
  15. Press escape to return to the AMD CBS main menu.

5. UEFI - Boot Menu

  1. Change to the Boot menu. Then set Boot Mode Select to UEFI
    Gigabyte bios 19.jpg
  2. Select Save Changes and Exit, then select Yes' at the prompt and press enter.
    Gigabyte bios 21.jpg

The system will now reboot. Please do not unplug the IC-OS USB stick at this point.

6. Boot the IC-OS USB image

  1. Watch for the screen with the Gigabyte logo and boot options underneath it. Press F10 a couple of times, once the options are listed.
    Gigabyte loading screen.jpg
  2. In the boot menu, select the first partition on the USB device and press enter, e.g.:
    SM-35.png


Return to the Installation Runbook