Intel® Software Guard Extensions (Intel® SGX)
Discussion board focused on hardware-based isolation and memory encryption to provide extended code protection in solutions.

Get GROUP_OUT_OF_DATE from IAS with the latest bios ?

muye
Novice
525 Views

Hello,  I have the same problem with the issue here :   https://community.intel.com/t5/Intel-Software-Guard-Extensions/CPU-has-latest-microcode-but-Attestation-Service-claims-an/m-p/1232267

and get the solution as follows:

Follow these steps to mitigate SGX issues:

  1. Refer to your OEM to get the latest BIOS and inquire if it has the latest microcode with the required fixes implemented.
  2. Install the early load microcode that comes with the latest BIOS from the OEM.

I know there is five microcode-update points from microcode-update-guidance .So I think the words Install the early load microcode  means   just   FIT Microcode Update    or   Early BIOS Microcode Update ,is this right ?  I have in touch with OEM, since the experts from OEM says they don't know the solution  what could i do then?

 

 

0 Kudos
1 Solution
JesusG_Intel
Moderator
517 Views

Hello muye,


You are correct. Either FIT or Early Microcode Update is what you need. The latest BIOS update from an OEM may not contain all of the latest mitigations for a particular TCB. Hence the advice to: "Refer to your OEM to get the latest BIOS and inquire if it has the latest microcode with the required fixes implemented."


Sincerely,

Jesus G.

Intel Customer Support


View solution in original post

0 Kudos
2 Replies
JesusG_Intel
Moderator
518 Views

Hello muye,


You are correct. Either FIT or Early Microcode Update is what you need. The latest BIOS update from an OEM may not contain all of the latest mitigations for a particular TCB. Hence the advice to: "Refer to your OEM to get the latest BIOS and inquire if it has the latest microcode with the required fixes implemented."


Sincerely,

Jesus G.

Intel Customer Support


0 Kudos
JesusG_Intel
Moderator
501 Views

This thread has been marked as answered and Intel will no longer monitor this thread. If you want a response from Intel in a follow-up question, please open a new thread.


0 Kudos
Reply