Latitude 9510 Setup and specifications guide

PDF

Security

Table 1. SecurityThe table describes the security configuration information.
Option Description
Admin Password

Allows you to set, change, or delete the administrator (admin) password (sometimes called setup password).

The entries to set the password are:

  • Enter the old password:
    NOTE:For the first time login, "Enter the old password:" Field is marked to "Not set". Set the password for the first time and later you can change or delete the password.
  • Enter the new password:
  • Confirm new password:

Click OK once you set the password.

Successful changes to the password take effect immediately.
NOTE:If you delete the admin password, the system password, if set, is also deleted. The admin password can also be used to delete the HDD password. For this reason, you cannot set an admin password if a system password or HDD password is already set. The admin password must be set first if an admin password is used with a system password or HDD password or both.
System Password

Allows you to set, change, or delete the System password (previously called the "Primary" password).

The entries to set the password are:

  • Enter the old password:
    NOTE:For the first time login, "Enter the old password:" field is marked to "Not set". Set the password for the first time and later you can change or delete the password.
  • Enter the new password:
  • Confirm new password:

Click OK once you set the password.

Successful changes to the password take effect immediately. The system requires the password to be entered when it is powered on.

Password Configuration

Allows you to control the rules when setting a password. The value of characters cannot be less than 4.

  • Lower Caste Letter
  • Upper Case Letter
  • Digit
  • Special Character

All options are disabled by default.

  • Minimum Characters (Set at 4 by default)
Password Bypass

Allows you to bypass the System (Boot) Password and the Internal HDD password prompts during a system restart.

Click one of the options:

  • Disabled (enabled by default)
  • Reboot bypass (disabled by default)
NOTE:The system always prompts for the System and internal HDD passwords when powered on from the off state (a cold boot). The system always prompts for passwords on any module bay HDDs that may be present.
Password Change

Allows you to change the System and Hard Disk password when the administrator password is set.

The Allow Non-Admin Password Changes option is enabled by default.

UEFI Capsule Firmware Updates

Allows you to update the system BIOS via UEFI capsule update packages.

The Enable UEFI Capsule Firmware Updates option is enabled by default.
NOTE:Disabling this option blocks BIOS updates from services such as Microsoft Windows Update and Linux Vendor Firmware Services (LVFS).
TPM 2.0 Security

Allows you to enable or disable the Trusted Platform Module (TPM) during POST.

  • Disabled (disabled by default)
  • Enabled (enabled by default)

The options are:

  • TPM On (enabled by default)
    NOTE:Disabling this option does not change any settings you have made to the TPM, nor does it delete or change any information or keys you may have stored in the TPM. Changes to this setting take effect immediately.
  • Clear(disabled by default)
  • PPI Bypass for Enable Commands (disabled by default)
  • PPI Bypass for Disbale Commands (disabled by default)
  • PPI Bypass for Clear Command (disabled by default)
  • Attestation Enable (enabled by default)
  • Key Storage Enable (enabled by default)
  • SHA-256 (enabled by default)
Absolute This field lets you Enable, Disable, or Permanently Disable the BIOS module interface of the optional Absolute Persistence Module service from Absolute Software.

The options are:

  • Enabled (enabled by default)
  • Disabled (disabled by default)
  • Permanently disabled (disabled by default)
WARNING:The Permanently Disabled option can only be selected once. When Permanently Disabled is selected, Absolute Persistence cannot be reenabled. No further changes to the Enable or Disable state are allowed.
OROM Keyboard Access

This option determines whether users are able to enter Option ROM Configuration screens via hotkeys during boot. Specifically this setting is capable of preventing access to Intel RAID (Ctrl+I) or Intel Management Engine BIOS Extension (Ctrl+P/F12).

The options are:

  • Enabled (enabled by default)
  • Disabled (disabled by default)
  • One Time Enable (disabled by default)
Admin Setup Lockout

Allows you to prevent users from entering Setup when an admin password is set.

The Enable Admin Setup Lockout option disabled by default.

Master Password Lockout

Allows you to disable master password support.

The Enable Master Password Lockout option is disabled by default.

NOTE:Hard Disk password should be cleared before the settings can be changed.
SMM Security Mitigation

Allows you to enable or disable additional UEFI SMM Security Mitigation protection.

The SMM Security Mitigation option is disabled by default.

HDD Security

This section defines special security features that shall be available for Self-Encrypting Drives (SED) that supports either Opal or Pyrite specification requirements. It is not available for regular storage devices.

The SED Block SID Authentication option is enabled by default.

The PPI Bypass for SED Block SID Command option is disabled by default.


Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\