<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re:Pre-boot DMA Protection problem on M50CYP in Intel® Xeon® Processor and Server Products</title>
    <link>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1483196#M22833</link>
    <description>&lt;P&gt;Hello, alpha_,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you again for waiting. I tried once more, and this time I was able to replicate the issue in a lab. I searched for any information that might explain why it happens, and I have confirmed that currently the VROC driver does not support enabling pre-boot DMA.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I cannot confirm when and if it will be supported, but at the moment you can only use the VROC driver by disabling pre-boot DMA.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Allan&lt;/P&gt;&lt;BR /&gt;</description>
    <pubDate>Thu, 04 May 2023 20:09:16 GMT</pubDate>
    <dc:creator>Allan_A_Intel</dc:creator>
    <dc:date>2023-05-04T20:09:16Z</dc:date>
    <item>
      <title>Pre-boot DMA Protection problem on M50CYP</title>
      <link>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1477927#M22797</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I installed Windows Server 2022 on M50CYP. Everything works fine and Secure Boot is enabled.&lt;/P&gt;
&lt;P&gt;Now, if I enable "Pre-boot DMA Protection" in BIOS (v01.01.0007) the OS cannot boot anymore. It goes directly to the network boot options.&lt;/P&gt;
&lt;P&gt;Is this a known issue and is there any solution?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Anguel&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 12:56:12 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1477927#M22797</guid>
      <dc:creator>alpha_</dc:creator>
      <dc:date>2023-04-18T12:56:12Z</dc:date>
    </item>
    <item>
      <title>Re:Pre-boot DMA Protection problem on M50CYP</title>
      <link>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1478368#M22803</link>
      <description>&lt;P&gt;Hello, alpha_,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you for reaching Intel Communities. I will gladly help you.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I couldn't confirm right away any issue related to DMA and the Intel® Server Board M50CYP with the latest BIOS, and I see that Windows* Server 2022 should support it as well.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Please allow me some time to research and try to find out the cause of the issue.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Allan&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 19 Apr 2023 15:29:37 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1478368#M22803</guid>
      <dc:creator>Allan_A_Intel</dc:creator>
      <dc:date>2023-04-19T15:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Pre-boot DMA Protection problem on M50CYP</title>
      <link>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1478600#M22806</link>
      <description>&lt;P&gt;Hi Allan,&lt;/P&gt;
&lt;P&gt;in &lt;STRONG&gt;ReleaseNotes_BIOS_R01.01.0007.txt&lt;/STRONG&gt; there is some DMA issue listed, however I do not understand if it may apply to my problem:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;13.[Hsd-ES]:[2103654290] Error is prompted when create RAID volume if enable pre-boot DMA protection option&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Indeed I am using a RAID1 VROC with two internal M.2 NVMEs for the Win Server 2022 OS (boot) volume. I created the volume &lt;STRONG&gt;without&lt;/STRONG&gt; having pre-boot DMA protection enabled.&lt;/P&gt;
&lt;P&gt;Also, although the M50CYP is certified for Server 2022 Secured Core and this was one of the main reasons we decided to buy this server, I did not find any official Intel document stating the BIOS settings required to enable all Secured Core features, and they are everything but trivial. Fortunately, with a lot of searching I could find some information from Lenovo that allowed me to enable secured core on the M50CYP:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Make sure the following UEFI settings are enabled in order to enable secured-core features:&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;System Settings -&amp;gt; Security -&amp;gt; Secure Boot Configurations -&amp;gt; Secure Boot Settings&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;System Settings -&amp;gt; Security -&amp;gt; Secure Boot Configurations -&amp;gt; Trusted Platform Module -&amp;gt; TPM 2.0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;System Information -&amp;gt; Socket Configuration -&amp;gt; Processor Configuration -&amp;gt; Enable Intel TXT&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;System Setting -&amp;gt; Devices and I/O Ports -&amp;gt; Intel VT for Directed I/O (VT-d)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;System Setting -&amp;gt; Devices and I/O Ports -&amp;gt; DMA Control Opt-In Flag&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Can Intel please confirm that this also applies to M50CYP?&lt;/P&gt;
&lt;P&gt;But again, as soon as I turn on&amp;nbsp;&lt;STRONG&gt;"Pre-boot DMA protection"&amp;nbsp;&lt;/STRONG&gt;in BIOS, the server does not boot to Windows anymore.&lt;/P&gt;
&lt;P&gt;Any help is welcome.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Anguel&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 06:46:12 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1478600#M22806</guid>
      <dc:creator>alpha_</dc:creator>
      <dc:date>2023-04-20T06:46:12Z</dc:date>
    </item>
    <item>
      <title>Re:Pre-boot DMA Protection problem on M50CYP</title>
      <link>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1479649#M22809</link>
      <description>&lt;P&gt;Hello, alpha_,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you for your patience. I tried this scenario in a lab with the same board and operating system, and I wasn't able to replicate the issue. The operating system booted even after enabling the pre-boot DMA protection.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Just to be sure, please verify the boot order, and test the system by disabling the pre-boot DMA protection and see if it is possible to boot the oeprating system again.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Allan&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 24 Apr 2023 17:16:22 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1479649#M22809</guid>
      <dc:creator>Allan_A_Intel</dc:creator>
      <dc:date>2023-04-24T17:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Pre-boot DMA Protection problem on M50CYP</title>
      <link>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1479958#M22811</link>
      <description>&lt;P&gt;Hi Allan,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tested again, also put "Windows Boot Manager" on top of boot order - same problem.&lt;/P&gt;
&lt;P&gt;Have you really tested with two internal M.2 NVMEs in VROC RAID1 configuration? See my details above.&lt;/P&gt;
&lt;P&gt;I think this might be causing the problem:&lt;/P&gt;
&lt;P&gt;If "Pre-boot DMA Protection" is OFF, everything is fine and in BIOS the VROC volume status is "Normal", Bootable: "Yes".&lt;/P&gt;
&lt;P&gt;But as soon as I turn "Pre-boot DMA Protection" ON, the system fails to boot and BIOS also shows the VROC volume status as "Failed", Bootable: "No".&lt;/P&gt;
&lt;P&gt;See attached screenshots.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Anguel&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 07:20:29 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1479958#M22811</guid>
      <dc:creator>alpha_</dc:creator>
      <dc:date>2023-04-25T07:20:29Z</dc:date>
    </item>
    <item>
      <title>Re:Pre-boot DMA Protection problem on M50CYP</title>
      <link>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1480028#M22812</link>
      <description>&lt;P&gt;Hello, alpha_,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you for the screenshots. Allow me to double check. I will contact you again soon.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 25 Apr 2023 14:34:22 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1480028#M22812</guid>
      <dc:creator>Allan_A_Intel</dc:creator>
      <dc:date>2023-04-25T14:34:22Z</dc:date>
    </item>
    <item>
      <title>Re:Pre-boot DMA Protection problem on M50CYP</title>
      <link>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1483196#M22833</link>
      <description>&lt;P&gt;Hello, alpha_,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you again for waiting. I tried once more, and this time I was able to replicate the issue in a lab. I searched for any information that might explain why it happens, and I have confirmed that currently the VROC driver does not support enabling pre-boot DMA.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I cannot confirm when and if it will be supported, but at the moment you can only use the VROC driver by disabling pre-boot DMA.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Allan&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 04 May 2023 20:09:16 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1483196#M22833</guid>
      <dc:creator>Allan_A_Intel</dc:creator>
      <dc:date>2023-05-04T20:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Pre-boot DMA Protection problem on M50CYP</title>
      <link>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1483415#M22836</link>
      <description>&lt;P&gt;Hi Allan,&lt;/P&gt;
&lt;P&gt;Thank you for the confirmation. This is really disappointing. We actually decided to buy Intel secured-core certified servers to make sure that they support all the latest security technologies.&lt;/P&gt;
&lt;P&gt;Regarding "Secured Core Server" I still cannot find any Intel document describing the BIOS settings required to enable this feature in Windows Server 2022. How is it possible to get certification but not even say a thing about the required settings?&lt;/P&gt;
&lt;P&gt;Any information regarding the settings is welcome. Thanks.&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Anguel&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 11:20:19 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1483415#M22836</guid>
      <dc:creator>alpha_</dc:creator>
      <dc:date>2023-05-05T11:20:19Z</dc:date>
    </item>
    <item>
      <title>Re:Pre-boot DMA Protection problem on M50CYP</title>
      <link>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1484304#M22838</link>
      <description>&lt;P&gt;Hello, alpha_,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The security is enabled by enabling pre-boot DMA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;It is the VROC driver that does not support enabling pre-boot DMA. If Windows is installed in a non-RAID environment, pre-boot DMA can be enabled.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Allan&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 08 May 2023 21:41:32 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/Pre-boot-DMA-Protection-problem-on-M50CYP/m-p/1484304#M22838</guid>
      <dc:creator>Allan_A_Intel</dc:creator>
      <dc:date>2023-05-08T21:41:32Z</dc:date>
    </item>
  </channel>
</rss>

