Intel® Xeon® Processor and Server Products
Intel® Xeon® Processors, Data Center Products including boards, integrated systems, and RAID Storage
5168 ディスカッション

Intel Xeon Silver 4410Y - SGX compatibility

e_discoveryinfra_cdo
ビギナー
2,137件の閲覧回数

Hello,

I open this post after trying unsuccessfully to configure SGX modules on a server with the following specs:

 

It appears also on the list of processors supporting SGX: https://www.intel.com/content/www/us/en/architecture-and-technology/software-guard-extensions-processors.html

 

 

Regarding the product specs, the processor has SGX compatibility. 

e_discoveryinfra_cdo_0-1754643529466.png

 

On the server BIOS configuration, SGX is enabled as well:

e_discoveryinfra_cdo_1-1754643569871.png

 

Regarding Intel SGX documentation, drivers on the kernel (mod name: intel_sgx) must be present by default, but they aren't:

modprobe intel_sgx
# Output
modprobe: FATAL: Module intel_sgx not found in directory /lib/modules/5.15.0-151-generic

Checked system messages for sgx:

dmesg | grep sgx
# Output
[    5.000387] intel_sgx: CPU does not support the SGX1 instructions

Can anyone confirm if the Hardware supports SGX to check if is a misconfiguration issue?

 

Thanks you in advance,

any additional information, please let me know

0 件の賞賛
6 返答(返信)
Vik3
従業員
2,101件の閲覧回数

Hello e_discoveryinfra_cdo,

Thank you for trusting Intel with your business. As with all good things, your product has reached the end of its interactive technical support life. However, you can find Intel® Xeon® Silver 4410Y Processor recommendations at Intel Community forums and additional information at the Discontinued Products website. It is our pleasure to continue to serve you with the next generation of Intel innovation at Intel.com.

Additionally , The processor Intel® Xeon® Silver 4410Y does support Intel® SGX. The Dell Server PowerEdge R660 also Supports SGX with the condition that Processor must support it (which it does) and BIOS settings and hardware requirements are met. Please refer to this Dell Support Manual for PowerEdge R660 which includes the details of the BIOS settings and memory requirements as well.

 

In addition to that, to check whether it supports SGX, we recommend to you follow this Intel Article to check if SGX supported by your processor.

 

We would like to inform you that the command in this intel article checks for SGX Capability at hardware layer whereas the commands which you used check for SGX at OS Kernel level.

 

Also, from the Intel® Software Guard Extensions Github link for linux, it seems that Ubuntu 22.04 LTS and the provided kernel versions should be capable of supporting SGX as per  Intel article

 

Hence we would recommend you to refer to the Dell Manual, ensure all the BIOS settings mentioned are as per the recommendation including the memory requirements. Also please confirm if the Processor is purchased Separately and integrated to your PowerEdge Server. If yes, please help share an image of the processor. If not, then we would recommend you to check with Dell Support team as they would be best equipped to advise you further.

 

Regards,

Vikas

Intel Customer Support Technician

 

 

 

e_discoveryinfra_cdo
ビギナー
1,894件の閲覧回数

Hello Vikas,

Thanks you for your response.

 

Regarding the server (Dell PowerEdge R660XS), we've checked that the requirements are fulfilled in order to enable SGX and install the drivers (Dell PowerEdge R660xs Installation and Service Manual | Dell España

- BIOS support for SGX and enable on Security Settings

e_discoveryinfra_cdo_0-1754983916002.png

- Memory requirements (Optimizer, encryption, node interleaving)

e_discoveryinfra_cdo_1-1754984395650.png

e_discoveryinfra_cdo_2-1754984435755.png

 

About the article (Which Platforms Support Intel® Software Guard Extensions (Intel® SGX)...),it seems this CPU model (Intel Xeon Silver 4410Y) not to appear on that lists of supported processors.

The output for the "cpuid" command confirms that architecture doesn't support neither SGX1 nor SGX2 instructions:

cpuid | grep -i sgx

e_discoveryinfra_cdo_3-1754984771008.png

 

I suppose that this is a limitation at Hardware level that impedes us to utilize libraries such as Gramine

 

Greetings, 

Sergio

Vik3
従業員
1,862件の閲覧回数

Hello e_discoveryinfra_cdo,


Thanks you for your update.

Kindly confirm if the Processor is purchased Separately and integrated to your PowerEdge Server. If yes, please help share an image of the processor


Regards,

Vikas


Vik3
従業員
1,664件の閲覧回数

Hello e_discoveryinfra_cdo,


Greetings for the day!


We are following up to check if you were able to find the information we requested. Kindly confirm at your earliest convenience, so that we can continue assisting you in resolving this matter.


Regards,

Vikas

Intel Customer Support Technician


Vik3
従業員
1,502件の閲覧回数

Hello e_discoveryinfra_cdo,


Thank you for contacting Intel.

This is the follow-up regarding the reported issue. We're eager to ensure a swift resolution and would appreciate any updates or additional information you can provide.


Please feel free to respond to this email at your earliest convenience.


Regards,

Vikas

Intel Customer Support Technician


Vik3
従業員
1,359件の閲覧回数

Hello e_discoveryinfra_cdo,


Greetings for the day!


We would like to inform you that we are closing this request due to no response being received for our previous follow-ups. Please don’t hesitate to reach out with any further questions in the future. Feel free to start a new conversation, as this thread will no longer be monitored.


Regards,

Vikas

Intel Customer Support Technician


返信