diff options
-rw-r--r-- | src/southbridge/intel/common/firmware/Kconfig | 14 |
1 files changed, 14 insertions, 0 deletions
diff --git a/src/southbridge/intel/common/firmware/Kconfig b/src/southbridge/intel/common/firmware/Kconfig index 8ad1fede41..2767c0e316 100644 --- a/src/southbridge/intel/common/firmware/Kconfig +++ b/src/southbridge/intel/common/firmware/Kconfig @@ -92,4 +92,18 @@ config IFD_PLATFORM_SECTION string default "" +config LOCK_MANAGEMENT_ENGINE + bool "Lock ME/TXE section" + depends on HAVE_ME_BIN + default n + help + The Intel Firmware Descriptor supports preventing write accesses + from the host to the ME or TXE section in the firmware + descriptor. If the section is locked, it can only be overwritten + with an external SPI flash programmer. You will want this if you + want to increase security of your ROM image once you are sure + that the ME/TXE firmware is no longer going to change. + + If unsure, say N. + endif #INTEL_FIRMWARE |