§ Wiki · Wiki entry
IC-OS UEFI Configuration — Gen-2 Dell
BIOS and UEFI settings for Gen-2 Dell node machines — processor, boot mode, integrated devices, system security, and miscellaneous settings required by IC-OS.
This runbook configures the BIOS/UEFI on a Gen-2 Dell server so that IC-OS can install and run correctly. It is the BIOS-side step of the Node Deployment Guide (Gen-2) — at section 9, "UEFI setup and boot menu", you should branch here, complete the steps below, then return to the deployment guide and continue to step 10.
[!WARNING] Do not enable the RAID BIOS setting. RAID will break IC-OS installation.
1. UEFI — Enter System Setup
- Reboot or power on the server.
- Watch for the blue screen with boot options in the top-left corner.
- Press F2 a couple of times once the options are listed.
- If the keypress is recognized, the screen highlights Entering System Setup.
2. UEFI — Check version
- From System Setup, select System BIOS and press Enter.
- From System BIOS, select System Information and press Enter.
- Verify the System BIOS Version is at least 2.8.4.
[!WARNING] If the BIOS version is below 2.8.4, abort this configuration and update the BIOS first.
- Select Back to return to System BIOS.
3. UEFI — Processor Settings
- From System BIOS, select Processor Settings and press Enter.
- Set Logical Processor to Enabled.
- Set Virtualization Technology to Enabled.
- Set NUMA Nodes Per Socket to 0.
- Set Secure Memory Encryption to Enabled.
- Set Minimum SEV non-ES ASID to 253.
- Set Secure Nested Paging to Enabled.
- Set SNP Memory Coverage to Enabled.
- Set Transparent Secure Memory Encryption to Disabled.
- Select Back to return to System BIOS.
4. UEFI — Boot Settings
- From System BIOS, select Boot Settings and press Enter.
- Set Boot Mode to UEFI.
- Select Back to return to System BIOS.
5. UEFI — Integrated Devices
- From System BIOS, select Integrated Devices.
- Set SR-IOV Global Enable to Enabled.
- Select Back to return to System BIOS.
6. UEFI — System Security
- From System BIOS, select System Security.
- Set TPM Security to On.
- Set TPM Hierarchy to Enabled.
- Select TPM Advanced settings.
- Set TPM2 Algorithm Selection to SHA256.
7. UEFI — Miscellaneous Settings
- From System BIOS, select Miscellaneous Settings.
- Set F1/F2 Prompt on Error to Disabled.
- Select Back to return to System BIOS.
- Select Finish and press Enter.
- Select Yes to save the changes and press Enter.
- Select OK and press Enter.
- Confirm the exit and press Enter. The system will reboot.
[!WARNING] Do not unplug the IC-OS USB stick during this reboot.
8. Boot Manager — Enter Boot Manager
- Watch for the blue screen with boot options in the top-left corner. Press F11 a couple of times once the options are listed.
- If recognized, the screen highlights Entering Boot Manager.
- From the Boot Manager, select One-shot UEFI Boot Menu and press Enter.
- From the Boot Menu, select your USB device and press Enter.
Return to the deployment runbook
- If you are following the non-HSM path, return to Node Deployment Guide (Gen-2) at section 9, "UEFI setup and boot menu", and continue to step 10.
- If you are following the legacy HSM path, return to Node Deployment Guide (Gen-1, with HSM) at section 9 and continue to step 10.
Related
- Node Deployment Guide (Gen-2) — the full deployment runbook this configuration is part of.
- Node Provider Machine Hardware Guide — hardware specifications by generation.
- Troubleshooting Node Deployment Errors — what to do if installation fails after BIOS configuration.
- IC-OS UEFI Configuration — Gen-2 Supermicro — sibling configuration for Supermicro hardware.