All the laptops contain a TPM 2.0 chip. Enable the measured boot security feature by default. Link: https://doc.coreboot.org/security/vboot/measured_boot.html Signed-off-by: Tim Crawford <tcrawford@system76.com>
22 lines
639 B
Plaintext
22 lines
639 B
Plaintext
CONFIG_VENDOR_SYSTEM76=y
|
|
CONFIG_BOARD_SYSTEM76_ADDW2=y
|
|
CONFIG_CCACHE=y
|
|
CONFIG_CONSOLE_SERIAL=n
|
|
CONFIG_CPU_MICROCODE_CBFS_DEFAULT_BINS=y
|
|
CONFIG_HAVE_IFD_BIN=y
|
|
CONFIG_HAVE_ME_BIN=y
|
|
CONFIG_IFD_BIN_PATH="$(FIRMWARE_OPEN_MODEL_DIR)/fd.rom"
|
|
CONFIG_ME_BIN_PATH="$(FIRMWARE_OPEN_MODEL_DIR)/me.rom"
|
|
CONFIG_PAYLOAD_ELF=y
|
|
CONFIG_PAYLOAD_FILE="$(FIRMWARE_OPEN_UEFIPAYLOAD)"
|
|
CONFIG_PCIEXP_HOTPLUG_MEM=0x2000000
|
|
CONFIG_PCIEXP_HOTPLUG_PREFETCH_MEM=0x20000000
|
|
CONFIG_POST_IO=n
|
|
CONFIG_RUN_FSP_GOP=y
|
|
CONFIG_SMMSTORE=y
|
|
CONFIG_SMMSTORE_V2=y
|
|
CONFIG_TPM_MEASURED_BOOT=y
|
|
CONFIG_USE_OPTION_TABLE=y
|
|
CONFIG_VALIDATE_INTEL_DESCRIPTOR=y
|
|
#CONFIG_CONSOLE_SYSTEM76_EC=y
|