QuestionQ2

Manage Customer Intent Documentation (CID) process to ensure the installation of the solution achieves the customer requirements

A customer must replace its ESXi servers, and you propose HPE ProLiant DL servers. The customer requires TPM attestation.

What should you recommend?

  • A Using the OneView for vCenter plug-in to deploy the ESXi OS images to the servers
  • B Replacing the servers’ default TPM certificates with a certificate signed by a private CA
  • C Purchasing servers with the trusted supply chain option
  • D Using the servers’ UEFI Secure Boot mode
Explanation

TPM attestation relies on a factory-provisioned System Initial Attestation Key (IAK) certificate whose corresponding private key is stored in the TPM. HPE’s trusted supply-chain capability provides the required factory trust and attestation identity; Secure Boot only protects the boot chain, and ESXi deployment tooling does not establish TPM attestation.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!