Dear Maintainer,
Gnome-Control-Center > Privacy > Device Security
Security Events:
Intel Management Engine Version
The Intel Management Engine controls device components and needs to have a
recent version to avoid security issues.
I booted into the BIOS and found that IME was already disabled and has been
since before the original Linux Install on this device.
SUGGESTION:
Can IME state be detected?
If so, is this still an issue?
If it is not an issue, then it should not be reported or it should be reported
differently and not treated as a Security Event Failure.
Disabling IME reports as LOCKED (see below). Which is why a valid IME version
is not being reported back.
So, if both IME Mode and IME Override report back Pass(Locked) and IME Version
reports back (Not Valid) then IME is Disabled, right?
Device Security Report
======================
Report details
Date generated: 2023-11-01 08:28:16
fwupd version: 1.9.6
System details
Hardware model: Dell Inc. Latitude 7210
2-in-1
Processor: Intel(R) Core(TM) i7-10610U
CPU @ 1.80GHz
OS: Debian GNU/Linux trixie/sid
Security level: HSI:0! (v1.9.6)
HSI-1 Tests
Firmware BIOS Region: Pass (Locked)
UEFI Platform Key: Pass (Valid)
UEFI Bootservice Variables: Pass (Locked)
MEI Key Manifest: Pass (Valid)
TPM v2.0: ! Fail (Not Found)
Firmware Write Protection Lock: Pass (Enabled)
Platform Debugging: Pass (Not Enabled)
Intel Management Engine Manufacturing Mode: Pass (Locked)
UEFI Secure Boot: Pass (Enabled)
BIOS Firmware updates: Pass (Enabled)
Firmware Write Protection: Pass (Not Enabled)
Intel Management Engine Override: Pass (Locked)
Intel Management Engine Version: ! Fail (Not Valid)
HSI-2 Tests
Platform Debugging: Pass (Locked)
Intel BootGuard ACM Protected: Pass (Valid)
IOMMU Protection: Pass (Enabled)
Intel BootGuard Fuse: Pass (Valid)
Intel GDS Mitigation: Pass (Enabled)
BIOS Rollback Protection: ! Fail (Not Enabled)
Intel BootGuard Verified Boot: Pass (Valid)
Intel BootGuard: Pass (Enabled)
HSI-3 Tests
Intel CET: ! Fail (Not Supported)
Intel BootGuard Error Policy: Pass (Valid)
Pre-boot DMA Protection: Pass (Enabled)
Suspend To RAM: Pass (Not Enabled)
Suspend To Idle: Pass (Enabled)
HSI-4 Tests
Encrypted RAM: ! Fail (Not Supported)
Intel SMAP: Pass (Enabled)
Runtime Tests
Firmware Updater Verification: Pass (Not Tainted)
Linux Swap: ! Fail (Not Encrypted)
Linux Kernel Lockdown: Pass (Enabled)
Linux Kernel Verification: Pass (Not Tainted)
Host security events
2022-07-05 18:46:50 Intel Management Engine Versi! Fail (Valid → Not Valid)
For information on the contents of this report, see
https://fwupd.github.io/hsi.html