summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--src/southbridge/intel/common/firmware/Kconfig14
1 files changed, 14 insertions, 0 deletions
diff --git a/src/southbridge/intel/common/firmware/Kconfig b/src/southbridge/intel/common/firmware/Kconfig
index 8ad1fede41..2767c0e316 100644
--- a/src/southbridge/intel/common/firmware/Kconfig
+++ b/src/southbridge/intel/common/firmware/Kconfig
@@ -92,4 +92,18 @@ config IFD_PLATFORM_SECTION
string
default ""
+config LOCK_MANAGEMENT_ENGINE
+ bool "Lock ME/TXE section"
+ depends on HAVE_ME_BIN
+ default n
+ help
+ The Intel Firmware Descriptor supports preventing write accesses
+ from the host to the ME or TXE section in the firmware
+ descriptor. If the section is locked, it can only be overwritten
+ with an external SPI flash programmer. You will want this if you
+ want to increase security of your ROM image once you are sure
+ that the ME/TXE firmware is no longer going to change.
+
+ If unsure, say N.
+
endif #INTEL_FIRMWARE