
TPM Lifecycle Management | Wave Systems Corp. 2012
ESC 2.9.5 Client Manual
4. TPM Lifecycle Management
A TPM is a hardware chip attached to the motherboard that can make authentication to protected
services or data easier and more secure. ESC can manage the TPM chip to securely store keys and
certificates. Users must provide credentials to unlock certificates. Thus, the TPM provides both user and
device-level authentication.
Additionally, the TPM can be used to detect changes made to the computer’s boot process, making it
possible to detect many types of malware early.
When used with Wave Endpoint Monitor (WEM), the
TPM can be used to detect changes and potential tampering to the boot sequence.
Turn on the TPM
The Trusted Platform Module (TPM) is available on most business class laptops from well-known
manufacturers. To determine if your computer has a TPM, the technical specifications on the
manufacturer’s website are a good place to start.
If you are unsure if your computer has an enabled TPM, go to Control Panel > Device Manager and
search for a Trusted Platform Module under Security Devices. If the TPM has not been enabled, check
the system BIOS to see if it has an option to enable a TPM. System BIOS’ vary, but you can view the
settings for most by pressing the F2 key at system boot. Once the TPM is enabled, it will need a TPM
driver. If a TPM does not display in Device Manager, a TPM driver may need to be installed. Check your
computer manufacturer’s website to find and install the appropriate driver.
Take ownership of the TPM
An owner password must be assigned to the TPM before any of its security functions can be utilized.
Once the prerequisites have been met, ESC will say “TPM Security Chip Status” at the bottom of the
window. There will be a green checkmark by “Enabled”. If it does not appear, verify that the
prerequisites
have been met. If there is a green checkmark by “Owned”, than the TPM has already has
an owner.
In order to take ownership, the TPM must be Enabled and Not Owned
Neither ESC nor a TSS is required to use the TPM for BitLocker management with
Wave EMBASSY Remote Administration Server (ERAS).
Komentáře k této Příručce