Intel Trusted Execution Technology Server Platforms Availability Matrix

Intel Trusted Execution Technology Server Platforms Availability Matrix
February 17, 2015 - Published by Intel DCSG Technology Marketing
Intel® Trusted Execution Technology (Intel® TXT) is a powerful component of enterprise data protection strategies. It provides a hardware root of trust and
measured launch environment that provide new levels of protections for server platforms—helping to assure that “known good” configurations of
controlling software (firmware, BIOS, Hypervisors, etc) are running on the platform.
For more information on how Intel TXT is used as part of cloud security solutions, please visit the Intel Cloud Builder reference architectures site:
http://software.intel.com/en-us/articles/intel-cloud-builders-reference-architecture-library/#enhance_security
More detail around Cloud Usage Models: http://www.intelcloudbuilders.com/cloud-usage-models/index.html
For more and general information: http://www.intel.com/txt
Most, but not all servers support Intel TXT. Intel TXT requires multiple hardware and software components, including:

Intel TXT enabled Intel Processor

Intel Chipset

Trusted Platform Module (TPM) 1.2 or 2.0 (as available)

Intel TXT Enabled BIOS and Enabled Hypervisor or Operating system

Customer and partner software solutions that can extend your Intel TXT architecture can be reference here:
http://www.intel.com/content/www/us/en/architecture-and-technology/trusted-execution-technology/where-to-buy-isv-txt.html
Note: as of this publication, some vendors have added support for TPM 2.0
TCG has released the TPM 2.0 library specification that provides updates to the previous published TPM main specifications.
The changes and enhancements compared to the existing TPM 1.2 include:





Support for additional cryptographic algorithms
Enhancements to the availability of the TPM to applications
Enhanced authorization mechanisms
Simplified TPM management
Additional capabilities to enhance the security of platform services
More information about the TCG TPM 2.0 Spec can be found here: http://www.trustedcomputinggroup.org/resources/tpm_library_specification
The matrix below is intended to provide an easy reference for the IT administrator to determine which platforms and operating environments support Intel
TXT. This list will be updated as vendors complete testing and release products that support Intel TXT.
The following server platform components have announced support and platform availability for Intel® Trusted Execution Technology
Updated February 2015 *NEW since last update
System Level Products
Vendor*
System/component*
Notes
SB302-CP2
SB401-CP2
Intel® Xeon® E5 V3 Series systems
AIC
SB402-CP2
CBox (Cloud in a Box)
Intel® Xeon® E5 Series systems
3U8G-C612
3U8G-C602
ASRock
Intel® Xeon® E5 V3 Series systems with ASROCK TPM #GZZR01
2U12L6SC-2TS6
2U12L6SW-2TS6
B200 M4
B260 M4
B420 M3
B460 M4
Intel® Xeon® E5 V3 Series systems. Requires TPM Module Kit option #UCSX-TPM1-001
C220 M4
C240 M4
C420 M3
Cisco
C460 M4
UCS B200 M3
UCS B22 M3
UCS B420 M3
UCS C220 M3
Intel® Xeon® E5 and E5 V2 Series systems. Requires TPM Module Kit option #UCSX-TPM1-001
UCS C240 M3
UCS C22 M3
UCS C24 M3
Dell
Hitachi
HP
Huawei
PowerEdge R430
PowerEdge R530
PowerEdge M630
PowerEdge R630
PowerEdge T630
PowerEdge R730
PowerEdge R730xd
PowerEdge R320
PowerEdge T320
PowerEdge R420
PowerEdge T420
PowerEdge R520
PowerEdge R620
PowerEdge T620
PowerEdge R720
PowerEdge M620
PowerEdge M820
PowerEdge M420
PowerEdge M520
PowerEdge R720xd
PowerEdge R820
PowerEdge R410
PowerEdge T410
PowerEdge R510
PowerEdge R610
PowerEdge M610
PowerEdge T610
PowerEdge M610x
PowerEdge R710
PowerEdge T710
PowerEdge M710
PowerEdge M710HD
PowerEdge R810
PowerEdge R910
PowerEdge M910
Compute Blade 520H A1
Compute Blade 520H B1
BladeSymphony 520H A1
BladeSymphony 520H B1
Hitachi HA8000 RS220-h
HM1/KM1/LM1
Hitachi HA8000 RS210-h
HM1/KM1/LM1
Hitachi Compute Rack 220H
Hitachi Compute Rack 210H
ProLiant BL420c Gen8
ProLiant BL460c Gen8
ProLiant WS460c Gen8
Workstation Series
ProLiant BL660c Gen8
ProLiant SL230s Gen8
ProLiant SL250s Gen8
ProLiant ML350p Gen8
ProLiant ML350e Gen8
ProLiant DL160 Gen8
ProLiant DL360p Gen8
ProLiant DL360e Gen8
ProLiant DL380p Gen8
ProLiant DL380e Gen8
ProLiant DL560 Gen8
CH121
Intel® Xeon® E5 V3 Series systems
Intel® Xeon® E5 and E5 V2 Series systems
Intel® Xeon® 5600 Series systems
Intel® Xeon® E7 series systems
Intel® Xeon® E5 Series systems. Requires TPM Activate License Option
Intel® Xeon® E5 Series systems.
Intel® Xeon® E5 Series systems. Requires TPM board option
Intel® Xeon® E5 Series systems, requires TPM Module Kit option, download AC module
IBM
Inspur
CH220
RH1288
RH2288
System X3100 M5
System X3250 M5
System X3500 M5
System X3550 M5
System X3650 M5
System X240 M5
System NX360 M5
System X3850 X6
Flex System x220 Compute Node
Flex System x240 Compute Node
System x3750 M4
System x3650 M4
System x3550 M4
System x3530 M4
System x3500 M4
System x3300 M4
System xiDataPlex dx360 M4
BladeCenter HS23
BladeCenter HS23E
System x3250 M4
System x3100 M4
System x3850 X6
NF5280M
NF5270M
Intel® Xeon® E5 V3 Series systems with TPM1.2 Module (ST19NP18-TPM) or TPM 2.0 Module
(Nationz Z32H320TC)
Intel® Xeon® E5 V3 Series systems with TPM1.2 Module Nuvoton NPCT421(P)
Intel® Xeon® E5 V3 Series systems with TPM1.2 Module Nuvoton NPCT650(P)
Intel® Xeon® E5 V3 Series systems with TPM1.2 Module Nuvoton NPCT421(P)
Intel® Xeon® E5 V2 Series systems
Intel® Xeon® E3 Series systems
Intel® Xeon® E7 v2 Series systems
Intel® Xeon® E5 V3 Series systems with TPM 2.0 Module (Nationz Z32H320TC)
ThinkServer TD350
Lenovo
ThinkServer RD550
ThinkServer RD650
ThinkServer RD350
ThinkServer RD450
ThinkServer RD630
ThinkServer RD530
ThinkServer RD430
ThinkServer RD330
ThinkServer TS430
ThinkServer TD330
ThinkServer TS130
Express5800/B120e
Express5800/B120e-h
Express5800/B120f
Express5800/E110d-1
NEC
Express5800/E120b-1
Express5800/GT110d
Express5800/GT110d-S
Express5800/GT110g
Express5800/GT110g-S
Express5800/GT120b
Express5800/R110d-1E
Express5800/R110e-1E
Express5800/R110e-1M
Express5800/R110g-1E
Express5800/R120b-1
Express5800/R120b-2
Express5800/R120e-1E
Express5800/R120e-2E
Intel® Xeon® E5 V3 Series systems with TPM 1.2 Module Nuvoton NPCT421LA1WX
Intel® Xeon® E5 V3 Series systems with TPM 2.0 Module (Nationz Z32H320TC)
Intel® Xeon® E5 Series systems. BIOS Version 1.00 Wave I or later
Intel® Xeon® E5 Series systems. BIOS Version 1.10 Wave II or later
Intel® Xeon® E3 Series systems. BIOS Version 2.10 or later
Intel® Xeon® E5 Series systems. BIOS Version 0.44 or later
Intel® Xeon® E3 Series systems
Order N8415-002 Trusted Platform Module Kit to
support Intel® TXT
Order N8415-002 Trusted Platform Module Kit to support Intel® TXT
Order N8415-008 Trusted Platform Module Kit to support Intel® TXT
Supported in the following models: N8100-1776Y/1861Y
Supported in the following models: N81001682Y/1685Y/1627Y/1689Y/1746Y/1682F/1685F/1627F/1689F/1746F
Supported in the following models: N8100-1768Y/1850Y
Supported in the following models: N8100-1770Y/1772Y/1851Y/1825Y
Order N8115-15 Trusted Platform Module Kit to support Intel® TXT
Order N8115-15 Trusted Platform Module Kit to support Intel® TXT
Supported in the following models: N8100-1736Y
Supported in the following models: N8100-1761/1762/1764/1765/1863/1864/1865/1866
Supported in the following models: N8100-1927Y/1928Y/1930Y/1931Y/1942Y/1943Y
Order N8115-15 Trusted Platform Module Kit to support Intel® TXT
Order N8115-15 Trusted Platform Module Kit to support Intel® TXT
Supported in the following models: N81001717/1718/1719/1720/1721/1722/1723/1724/1725/1726
Supported in the following models: N81001707/1708/1759/1709/1711/1712/1713/1714/1715/1716
Order N8115-20 Trusted Platform Module Kit to support Intel® TXT
Order N8115-20 Trusted Platform Module Kit to support Intel® TXT
Express5800/R120f-1M
Express5800/R120f-2M
Express5800/T110e-M
Express5800/T110g-E
Express5800/T110g-S
Express5800/T120b-E
Express5800/T120b-M
Express5800/T120e
iStorage NS/NS500Rb
iStorage NS300Re
iStorage NS500Re
QuantaPlex T41S-2U (4 Node)
QuantaGrid D51B-1U
QuantaGrid D51B-2U
Quanta
Sugon
ZTE
S100-L11D
S100-X1S1N
S51G-1UL
S910-X31B
S910-X31E
S900- X31A
S210-X12MS
S210-X12RS
S210-X22RQ
i610
i620-G20
HX20G2
Order N8115-21 Trusted Platform Module Kit to support Intel® TXT
Order N8115-21 Trusted Platform Module Kit to support Intel® TXT
Order N8115-20 Trusted Platform Module Kit to support Intel® TXT
Order N8115-15 Trusted Platform Module Kit to support Intel® TXT
Order N8115-15 Trusted Platform Module Kit to support Intel® TXT
Supported in the following models: N8100-1731/1732/1733/1734
Supported in the following models: N8100-1727/1728/1729/1730
Order N8115-20 Trusted Platform Module Kit to support Intel® TXT
Supported in the following models: NF8100-193/194
Supported in the following models: NF8100-220Y
Order N8115-15 Trusted Platform Module Kit to support Intel® TXT
Order N8115-20 Trusted Platform Module Kit to support Intel® TXT
TPM 1.2: INFINEON TECHNOLOGIES ASIA PACIFIC, SLB9635TT1.2 FW 3.19
TPM 2.0: INFINEON TECHNOLOGIES ASIA PACIFIC, SLB9665TT2.0 FW 5.00
TPM 1.2: INFINEON TECHNOLOGIES ASIA PACIFIC, SLB9635TT1.2 FW 3.19
TPM 2.0: INFINEON TECHNOLOGIES ASIA PACIFIC, SLB9665TT2.0 FW 5.00
TPM 1.2: INFINEON TECHNOLOGIES ASIA PACIFIC, SLB9635TT1.2 FW 3.19
TPM 2.0: INFINEON TECHNOLOGIES ASIA PACIFIC, SLB9665TT2.0 FW 5.00
Intel® Xeon® E5 V3 Series systems
Intel® Xeon® E5 and Intel® Xeon® E5 V2 Series systems, requires TPM Module kit option
Intel® Xeon® E5 V3 Series systems
Intel® Xeon® E5 V3 Series systems with TPM 2.0 Module (Nationz Z32H320TC)
Board Level Products
Vendor*
AIC
Gigabyte
Intel
System/component*
Tolimon Motherboard
Hadar Motherboard
Libra Motherboard
Phoenix Motherboard
MD30-RS0
MD50-LS0
MD60-SC0
MD70-HB0
MD80-TM0
MD90-FS0
MG50-G20
MH70-HD0
MU70-SU0
MW50-SV0
Intel® Server Board S2600CW
Family
Intel® Server Board S2600WT
Family
Intel® Server Board S1200V3RP
family
Intel® Compute Module
HNS2600WP
Intel® Compute Module
HNS2600WPF
Intel® Compute Module
HNS2600WPQ
Intel® Server Board H2000LP
Intel® Server Board P4000CP
Intel® Server Board P4000CR
Notes
Intel® Xeon® E5 V2 Series systems
Intel® Xeon® E5 Series systems
Intel® Xeon® E5 V3 Series systems
Intel® Xeon® E5 V3 Series systems
Intel® Xeon® E5 V3 Series systems with Infineon TPM SLB9635TT1.2 and FW3.19
Intel® Xeon® E5 V3 Series systems, requires TPM Module option AXXTPME5
Intel® Xeon® E3 V3 Series systems, requires TPM Module option AXXTPME3
Intel® Xeon® Processor E5 Product Family and
Intel® Xeon® Processor E5 v2 Product Family
Requires TPM Module option AXXTPME5
MSI
Supermicro
Intel® Server Board P4000GP
Intel® Server Board P4000IP
Intel® Server Board P4000SC
Intel® Server Board R1000EP
Intel® Server Board R1000GL
Intel® Server Board R1000GZ
Intel® Server Board R2000GL
Intel® Server Board R2000GZ
Intel® Server Board R2000IP
Intel® Server Board S1400FP
Family
Intel® Server Board S1400SP
Family
Intel® Server Board S1600JP
Family
Intel® Server Board S2400BB4
Intel® Server Board S2400EP
Intel® Server Board S2400EP
Family
Intel® Server Board S2400GP
Intel® Server Board S2400LP
Intel® Server Board S2400SC
Family
Intel® Server Board S2600CO
Family
Intel® Server Board S2600CP
Family
Intel® Server Board S2600GL
Intel® Server Board S2600GZ
Intel® Server Board S2600IP
Family
Intel® Server Board S2600WPQ
Intel® Workstation Board
W2600CR Family
Intel® Server Board S1200BTLR
Intel® Server Board S1200BTLRM
Intel® Server Board S1200BTSR
Intel® Server Board S1200BTL
Intel® Server Board S1200BTS
Intel® Server Board
P4304BTLSFCN
Intel® Server Board
P4304BTLSHCN
Intel® Server Board
P4304BTSSFCN
Intel® Server Board
R1304BTLSHBN
Intel® Server Board
R1304BTSSFAN
Intel® Server Board
R1304BTLSFAN
Intel® Server Board S4600LH2
Intel® Server Board S4600LT2
Intel® Server Board S5520HC
Intel® Server Board S5520UR
MS-S0081 server board
MS-S0131 server board
all X10* server boards
X9DR7-LN4F
X9DR7-JLN4F
X9DRE-LN4F
X9DR3-LN4F+
Intel® Xeon® E3 V2 Series systems. Requires TPM Module option AXXTPME3
Intel® Xeon® E3 Series systems. Requires TPM Module option AXXTPME3
Intel® Xeon® E5-4600 Series systems, requires TPM Module option AXXTPME5
Intel® Xeon® 5600 Series systems, available through reseller channels
Intel® Xeon® E5 Series systems, requires TPM Module Kit option
Intel® Xeon® E5 V3 Series systems and/or Intel® Xeon® E3 V3 Series Systems
Requires TPM Module Option AOM-TPM-9655V (vertical) or AOM-TPM-9655H (horizontal)
Intel® Xeon® E5 Series systems
Requires TPM Module Option AOM-TPM-9655V (vertical) or
AOM-TPM-9655H (horizontal)
X9DRi-LN4F+
X9DR3-F
X9DRi-F
X9DA7
X9DAi
X9DRL-3F
X9DRL-iF
X9DRT-F
X9DRT-IBQF
X9DRT-IBFF
X9DRT-HF
X9DRT-HF+
X9DRT-HIBQF
X9DRT-HIBFF
X9DRW-3LN4F+
X9DRW-3TF+
X9DRW-3F
X9DRW-iF
X9DRH-7F
X9DRH-7TF
X9DRH-iF
X9DRH-iTF
X9DRG-QF
X9DRG-HTF
X9DRG-HF
X9DRD-7LN4F
X9DRD-7JLN4F
X9DRD-EF
X9DRD-iF
X9DRX+-F
X9DBU-3F
X9DBU-iF
X9DBL-3
X9DBL-i
X9DBL-3F
X9DBL-iF
X9DAL-3
X9DAL-i
Software and cloud services
Vendor*
Canonical
Product or service*
Canonical Ubuntu Server
Canonical
Canonical OpenStack
Fedora
HyTrust
M2Mi
Fedora
HyTrust Appliance
SDN platform
Version
11.1 and later
Folsom or later with integration of Open
Attestation (See notes)
13 x86_64 and later + tboot
3.6
Notes
http://www.ubuntu.com/server
https://github.com/OpenAttestation/OpenAtt
estation
http://sourceforge.net/projects/tboot/
http://www.hytrust.com/
http://www.m2mi.com/
McAfee
McAfee Server Security Suite
Essentials
McAfee Server Security Suite
Advanced
McAfee Server Security Suites 3.0 and later. For
use with McAfee ePolicy Orchestrator 4.6.0, 5.0.0
Software
McAfee Boot Attestation Service, feature that
is part of the McAfee Server Security Suites,
utilizes Intel TXT to determine trust
worthiness of VMware ESXi hypervisor boot
with display of trust status in McAfee ePO and
ability to create policies based on the status
that can be used for compliance and
regulatory controls. Please reference the
product guide for more detailed information
about McAfee Boot Attestation Service.
http://www.mcafee.com/us/products/datacenter-security/index.aspx
Open Source
Open Source
Red Hat
SuSe
Trapezoid, Inc.
Xen
Linux/KVM
Red Hat Enterprise Linux
SUSE Linux Enterprise Server
Trust Visibility Engine
4.1.2 and later + tboot
2.6.32 and later + tboot
6.2 and later + tboot
11, sp2 and later + tboot
Version 1.0
http://sourceforge.net/projects/tboot/
http://sourceforge.net/projects/tboot/
http://www.redhat.com/en
https://www.suse.com/
Trapezoid’s integrates your physical and
logical infrastructure into one coherent view,
providing Visibility, Analytics and
Remediation, helping manage security and
compliance across all your environments in a
coordinated fashion.
http://www.trapezoid.com/
Trapezoid’s unique Marker technology
integrates your physical and logical
infrastructure into one coherent view, so that
you can manage your security and compliance
across all your environments in a coordinated
fashion.
UOL
Online Hosting and Online
services with credibility
http://www.uolhost.com.br/
Intel® TXT available on select servers:
SoftLayer
Virtustream
VMware
Bare Metal Server Provisioning as
Trusted Sever Solutions provider
for Cloud Hosting
Intel® Xeon® E3-1230
Intel® Xeon® E3-1270
Intel® Xeon® E3-1270
Intel® Xeon® E5-2620
Intel® Xeon® E5-2620
Intel® Xeon® E5-2640
Intel® Xeon® E5-2650
Intel® Xeon® E5-2650
Intel® Xeon® E5-2670
Intel® Xeon® E5-2690
Intel® Xeon® E5-2690
Intel® Xeon® E5-4620
Intel® Xeon® E5-4650
http://www.softlayer.com/intel-txt
xStream Cloud Management
1.5
http://www.virtustream.com
vSphere Hypervisor (ESXi)
vSphere 5.1 and later
Search VMware HCL for updated Intel TXT support
(see notes)
http://www.vmware.com/resources/compati
bility/search.php
Integration services
Vendor*
Trapezoid, Inc.
Notes
Trapezoid provides professional services that help you integrate Intel® TXT at scale in
your environment, including customizable automated TXT enablement across
compatible equipment.
http://www.trapezoid.com/