Server Products
Data Center Products including boards, integrated systems, Intel® Xeon® Processors, RAID Storage, and Intel® Xeon® Processors
4958 Discussions

Intel S2400GP-BIOS - "The capsule file failed in the security compliance check"

JSchr11
Beginner
3,862 Views

I have an Intel S2400GP with a fairly old BIOS. Since I wanted to upgrade it I downloaded the newest official BIOS from Intel, followed the instructions and started the flashing process. It seems to work until the error "The capsule file failed in the security compliance check" is shown. First, I tried older official version but all are the same.

Then, after restoring all settings I found out, that during the booting process the logo of the company Tarox is shown; so I figured I have a branded motherboard. Am i right? And regardless "if"; is there any way I can install the newest BIOS by bypassing the security compliance check?

 

By the way, the CPUID-Update-jumper is set to update enable. I found an very old Tarox BIOS update for this board but I want the newest patches Intel provides...for obvious reasons.

 

Thanks!

0 Kudos
11 Replies
Jeremias_A_Intel
Employee
2,957 Views
Hello Julian, Thank you for contacting Intel Technical Support. I understand that you are getting an error when trying to update the BIOS on the Intel S2400GP. I will go ahead and investigate this issue and get back to you as soon as possible with new information. If you have any question, please let me know. Your patience is highly appreciated. Best regards, Jeremiah A. Intel Technical Support
0 Kudos
Jeremias_A_Intel
Employee
2,957 Views
In an effort to better assist you, can you please provide the Server Board Part number?
0 Kudos
JSchr11
Beginner
2,958 Views

Hi Jeremiah,

 

thanks for the fast reply! According to AIDA64:

 

Product: S2400GP (should be GP2)

Version: G31611-205

Motherboard-ID: 63-0100-000001-00101111-082009-Chipset$RML06_BIOS DATE: 08/20/09 10:33:39 VER: 08.00.10

0 Kudos
Jeremias_A_Intel
Employee
2,958 Views
Thank you for your update. I will get back to you as soon as possible with new information. Regards,
0 Kudos
Jeremias_A_Intel
Employee
2,958 Views
Hello Julian, Be aware that, when having an old BIOS, the update must be done starting from the old one to the new one but without jumping any version in between to avoid corrupted BIOS to avoid corrupted BIOS. Since are the BIOS got corrupted you can try clearing the CMOS. There two ways to clear CMOS: Using a CMOS jumper or a dedicated jumper on the motherboard, generally near the battery. The jumper position, time to wait, and location of the jumper are completely dependent on the motherboard. Removing the battery. Steps to clear CMOS using the jumper method: - Power off the system. - Open up the system so you can see the motherboard. - Locate the CMOS jumper by referring to the motherboard manual and how to clear the CMOS. In general, the CMOS jumper is three pins located near the battery. - In general, CMOS jumper has positions 1–2 and 2–3. Move the jumper from the default position 1–2 to position 2–3 to clear CMOS. Wait 1–5 minutes then move it back to the default position. - Power on the system. In some systems, you might need to enter BIOS to reset to the factory defaults. Steps to clear CMOS using the battery method: - Turn off all peripheral devices connected to the computer. - Disconnect the power cord from the AC power source. - Remove the computer cover. - Find the battery on the board. The battery may be in a horizontal or vertical battery holder, or connected to an onboard header with a wire. Remove the battery: - If the battery is in a holder, note the orientation of the + and – on the battery. Gently pry the battery free from its connector. - If the battery is connected to an onboard header with a wire, disconnect the wire from the onboard header. Wait 1–5 minutes, then reconnect the battery. - Put the computer cover back on. - Plug the computer and all devices back in. Please try these steps and if you have any question please let me know. Regards, Jeremiah A. Intel Technical Support
0 Kudos
Jeremias_A_Intel
Employee
2,958 Views
In case this action plan does not work, you might need to contact the brand (Tarox) to have them provide you with the correct file to update the BIOS.
0 Kudos
JSchr11
Beginner
2,958 Views

Thanks for your replies, I tried the jumper- and the battery-option. I also made contact with TAROX and they basically told me that there is no issue with updating Intel-BIOS on their OEM-systems. Additionally I made a picture of the error message. Although the ME-Update seems to work it will be recovered in the end. Hence, only BMC is updated.

 

IMG_20190226_145700_794.jpg

0 Kudos
Jeremias_A_Intel
Employee
2,958 Views
Hello Julian, Thank you for your update. Since this is an OEM system, we cannot determine how the behavior of the board will be using our BIOS. You can try flashing the BIOS using previous versions, like System BIOS - 01.06.0002, and so on until you reach to the latest version. If that doesn't work, you nay want try using Tarox BIOS file. Please let me know your comments. Best regards, Jeremiah A, Intel Technical Support.
0 Kudos
JSchr11
Beginner
2,958 Views

I contacted Tarox and they say that it should be no problem using official genuine Intel BIOS files. Could you provide me with the manual for the Intel S2400GP-series, I struggle to find them online. Maybe, I am missing something.

0 Kudos
JSchr11
Beginner
2,958 Views

I fixed the problem; I will post my solution tomorrow!

0 Kudos
JSchr11
Beginner
2,958 Views

First of all; I do not know if the following steps helps anybody except me.

 

TL;DR:

Set the BIOS recovery jumper, use the exact same BIOS recovery file, place only needed files on the flash drive, Do not use Startup.nsh

 

Problem:

I had an Intel S2400GP2 motherboard with 2x Intel Xeon E5 2470v1 and 96GB RAM that was stuck with an old OEM (TAROX) BIOS (SE5C600.86B.01.06.0001). The Intel ME and BMC version were also (very) outdated.

What I did:

I downloaded the newest BIOS-package (R02.06.E006) from the Intel website. There is a newer light package available that only contains the BIOS R02.06.E007. The version R02.06.E006 needs to be flashed first. I copied all files onto a USB flash drive (FAT32) and booted to the EFI shell and let the automatically executing Startup.nsh do its work.

What happened:

The BMC was updated correctly but the BIOS update failed with the error “The capsule file failed in the security compliance check” and hence the Intel ME update fails, too. I tried several other BIOS versions, even older ones than the installed one.

What I did wrong and what fixed the problem:

I failed to set the ME FRC UPD Jumper from the default (pins 1 and 2) operating position to the Force Update position (pins 2 and 3) like listed in the manual, which I did not had at this point. So I done the same steps than before: EFI & Startup.nsh. But again, the flash procedure failed. I thought it might be caused by the failing BIOS flash. Hence instead of letting the Startup.nsh run I cancelled it, moved to “fs0:” manually and run the UpdateME.nsh from the R02.06.E006 package. This script only flashes the Intel ME and worked for me. After the successful flash I powered off the system and put the jumper back to the default (pins 1 and 2).

After that I though it might be the same issue with the BIOS, but it wasn’t that; but first steps first. It is mentioned that you only can use the BIOS Recovery when you want to recover the current BIOS version. Thankfully (!), the OEM TAROX provided me these old files. The process need the special recovery version R01.06.0002Rec.cap. When I moved the BIOS Recovery Jumper to the recovery state and tried to boot the screen went black. Besides some beeps from the motherboard nothing happened; the system won’t show me a boot screen. After another look the ReleaseNotes I found and I quote:

 

“The recovery media must contain the following files under the root directory:

a)      RML.ROM

b)     UEFI iFlash32 11.0 Build 8 or higher (including ipmi.efi )

c)      *Rec.CAP

d)     BIOS.nsh (update accordingly to use proper *Rec.CAP file).”

 

This BIOS.nsh had different names over the last years. So I deleted all files on the flash drive and only (!) placed the above mentioned files on it. Plugged it in and powered the system back on. After the systems was done with the BIOS beeping the flash procedure started; no black screen.

After the update I powered off the systems, put the BIOS Recovery Jumper back to the default pins and powered the system back on. Everything went fine.

It is mentioned that you shall flash every BIOS version to get to the newest one. I did not and moved directly to the R02.06.E006 package. I copied all files (again) on the flash drive, booted to the EFI shell and let the Startup.nsh do its work: the BIOS update went through! After that I even flashed the R02.06.E007 BIOS.

 

 

 

 

0 Kudos
Reply