HP (Hewlett-Packard) 686234S01 Server User Manual


 
Hardware options installation 54
HP Trusted Platform Module option
Use these instructions to install and enable a TPM on a supported server. This procedure includes three
sections:
1. Installing the Trusted Platform Module board (on page 54).
2. Retaining the recovery key/password (on page 56).
3. Enabling the Trusted Platform Module (on page 56).
Enabling the TPM requires accessing RBSU ("HP ROM-Based Setup Utility" on page 72). For more
information about RBSU, see the HP website (http://www.hp.com/go/ilomgmtengine/docs).
TPM installation requires the use of drive encryption technology, such as the Microsoft Windows BitLocker
Drive Encryption feature. For more information on BitLocker, see the Microsoft website
(http://www.microsoft.com).
CAUTION: Always observe the guidelines in this document. Failure to follow these guidelines
can cause hardware damage or halt data access.
When installing or replacing a TPM, observe the following guidelines:
Do not remove an installed TPM. Once installed, the TPM becomes a permanent part of the system
board.
When installing or replacing hardware, HP service providers cannot enable the TPM or the encryption
technology. For security reasons, only the customer can enable these features.
When returning a system board for service replacement, do not remove the TPM from the system board.
When requested, HP Service provides a TPM with the spare system board.
Any attempt to remove an installed TPM from the system board breaks or disfigures the TPM security
rivet. Upon locating a broken or disfigured rivet on an installed TPM, administrators should consider the
system compromised and take appropriate measures to ensure the integrity of the system data.
When using BitLocker, always retain the recovery key/password. The recovery key/password is
required to enter Recovery Mode after BitLocker detects a possible compromise of system integrity.
HP is not liable for blocked data access caused by improper TPM use. For operating instructions, see the
encryption technology feature documentation provided by the operating system.
Installing the Trusted Platform Module board
WARNING: To reduce the risk of personal injury, electric shock, or damage to the equipment,
remove the power cord to remove power from the server. The front panel Power On/Standby
button does not completely shut off system power. Portions of the power supply and some internal
circuitry remain active until AC power is removed.
WARNING: To reduce the risk of personal injury from hot surfaces, allow the drives and the
internal system components to cool before touching them.
To install the component:
1. Power down the server (on page 18).
2. Unlock the tower bezel (on page 19).
3. Remove the access panel (on page 20).