Rate This Document
Findability
Accuracy
Completeness
Readability

Deploying the HPM Package and Configuring the Server

The Kunpeng SCCM must run on a server that supports the TrustZone feature.

Obtain BoostKit-boostcc-ccos-1.4.RC1.zip as instructed in Table 2. Decompress the ZIP package to obtain the HPM firmware, kunpeng_sec_drv.sec, and sdf-utils*.rpm.

Deploying the HPM Package

  1. Log in to the iBMC WebUI, choose iBMC Settings > Firmware Upgrade, select the HPM file in the preceding package, and click Upgrade.
    Figure 1 Firmware upload and upgrade
    Figure 2 Firmware upgrade in progress
    Figure 3 Firmware upgrade completed
  2. After the upgrade is successful, click the power icon and choose Power Off. Wait for several seconds until the icon turns gray, and then click Power On.

Configuring the Server

For details about the hardware environments, see TrustZone Kit Feature Guide.

The TEE is incompatible with some features and is disabled by default. To enable the TEE, perform the following operations in the BIOS:

  1. Restart the server to access the BIOS screen. For details, see "Accessing the BIOS" in TaiShan Server BIOS Parameter Reference (Kunpeng 920 Processor).
  2. Disable three-channel interleaving.
    1. On the BIOS screen, choose Advanced > Memory Config and press Enter. The Memory Configuration screen is displayed.
    2. On the Memory Configuration screen, set Channel Interleaving 3Way to Disabled.

  3. Enable the TEE.
    1. On the BIOS screen, choose Security > TEE Configuration. The TEE Configuration screen is displayed.
    2. On the TEE Configuration screen, set Support TEE to Enabled.

  4. Save the modification and restart the server.