10 Replies Latest reply on Nov 10, 2018 12:21 PM by scan80269

    NUC5i5MYBE TPM version 5.0 Update

    Hanno

      The release notes says that customers with TPM version 5.0 should contact Intel support to get help...

       

      Download Trusted Platform Module (TPM) Firmware Update for Intel® NUC Kits NUC5i5MYHE

       

      We have many SA# H47796-207

       

      Kind Regards

       

      Jesper Hanno

        • 1. Re: NUC5i5MYBE TPM version 5.0 Update
          Intel Corporation
          This message was posted on behalf of Intel Corporation

          Hello Hanno
          Thank you for contacting us.
          I understand that you are having issues with our Trusted Platform Module (TPM) and your Intel® NUC Board NUC5i5MYBE.
          Can you provide us with a longer/more detailed description of your issue?
          We are here to serve.
           
          I hope to hear from you soon.
          Best regards.
          Diego S.
           

          • 2. Re: NUC5i5MYBE TPM version 5.0 Update
            Intel Corporation
            This message was posted on behalf of Intel Corporation

            Hello Hanno
            We just wanted to double check if you still need further assistance.
            Please do not hesitate on contacting us back.
            Best Regards,
            Diego S.
             

            • 3. Re: NUC5i5MYBE TPM version 5.0 Update
              AnybodyM2

              I think I have the same problem. While I cannot see the release notes (where are they?), I also do have FW version 5.0 of the TPM chip.

              According to the installation guide of the TPM update, anyone with TPM 5.4 or earlier needs to update.

               

              According to tpm.msc in Windows, I have an IFX TPM, Version 5.0.1089.2

               

              However, when I try to flash it using F7 and NUC5i5MY-TPM-Firmware-Update.bio I get the following error:

              "Current TPM FW version is 5.00, skip FW update. System will reboot in 20 seconds."

               

              How do I update my NUC5i5MYHE NUCs (I have three of them) to TPM Firmware 5.62 ?

              On one of the NUCs Windows 10 security center even complains about the TPM firmware and tells me to update it!

              • 4. Re: NUC5i5MYBE TPM version 5.0 Update
                Intel Corporation
                This message was posted on behalf of Intel Corporation

                Hello AnybodyM2,
                 
                 Thank you for joining this community; it will be more than a pleasure to assist you.
                 
                In this case, please let me ask, where did you download the TPM Firmware?
                Can you provide us the link?
                The reason that I am asking is because the actual firmware is a .ZIP file that can be found here:
                https://downloadcenter.intel.com/download/27513/NUCs-Trusted-Platform-Module-TPM-Firmware-Update-for-Intel-NUC-Kit-NUC5i5MYHE?product=84861
                Based on your post, you mentioned that you downloaded a NUC5i5MY-TPM-Firmware-Update.bio, so we want to gather more information about that.
                 
                I hope to hear from you soon.
                 
                 
                Regards,
                Diego S.
                 

                • 5. Re: NUC5i5MYBE TPM version 5.0 Update
                  AnybodyM2

                  I got the download link from the official download page for the NUC5i5MYHE NUC on downloadcenter.intel.com

                   

                  The download item is "Trusted Platform Module (TPM) Firmware Update for Intel® NUC Kit NUC5i5MYHE Instructions, BIOS and Firmware necessary to update the TPM on Intel® NUC Kits NUC5i5MYHE and Intel® NUC Boards NUC5i5MYBE." and is dated 4/3/2018 and it links to the 11.96MB ZIP File which hanno linked to in the first post here.

                   

                  This ZIP file contains a .bio file and a .pdf file, which tells me to flash the .bio file using F7.

                  It also tells me that I need to upgrade if I have TPM Firmware 5.4 or lower and according to the tpm.msc utility by microsoft (which the PDF tells me to use) I have 5.0.x firmware.

                  Yet the firmware flashing using an USB Stick and the "F7" method aborts with: "Current TPM FW version is 5.00, skip FW update. System will reboot in 20 seconds"

                  • 6. Re: NUC5i5MYBE TPM version 5.0 Update
                    Intel Corporation
                    This message was posted on behalf of Intel Corporation

                    Hello AnybodyM2
                    Thank you for your response.
                    In this case, we are currently trying to replicate your situation in order to find a suitable answer.
                    This may delay our answers; however I will reach you back as soon as possible.
                    I hope this helps.
                    Regards,
                    Diego S.
                     

                    • 7. Re: NUC5i5MYBE TPM version 5.0 Update
                      Intel Corporation
                      This message was posted on behalf of Intel Corporation

                      Hello Hanno and AnybodyM2,
                      Thank you for your response.
                      To Hanno:  The link to the article on the download page is missing, we just added it.
                      Please go ahead and take a look to it:
                      https://www.intel.com/content/www/us/en/support/articles/000026516/mini-pcs.html
                      In this case you can update the Firmware on your NUCs based on the link.
                      If you have the version 5.0, however you should have the version 5.4.
                      Please perform the update and let us know the outcome.
                      To AnybodyM2: I have sent a private message to your inbox, please go ahead and check it, I am awaiting for your response.
                       
                       
                      I hope this helps.
                      Regards,
                       
                      Diego S.
                       

                      • 8. Re: NUC5i5MYBE TPM version 5.0 Update
                        Intel Corporation
                        This message was posted on behalf of Intel Corporation

                        Hello Hanno,
                        We just wanted to double check if you still need further assistance.
                        Please do not hesitate on contacting us back.
                        Best Regards,
                        Diego S.
                         

                        • 9. Re: NUC5i5MYBE TPM version 5.0 Update
                          AnybodyM2

                          Just to summarize this for anyone who also has the TPM version 5.0 update problem and who will stumble upon this thread:

                           

                          If you have this version, there is no software update. You need to exchange the NUC via Intel Support which they might even do for free outside the warranty period (?).

                          I opted not to do so, since it would have been a major hassle to not have the unit for some time and the likelihood that somebody will attack my TPM is pretty minimal (the NUC is not used in an industry which is especially prone to attacks).

                          • 10. Re: NUC5i5MYBE TPM version 5.0 Update
                            scan80269

                            It is possible to update Infineon TPM 2.0 firmware for NUC5i5MYBE from 5.0.1089.2 to 5.62.3126.2 to address the security vulnerability.

                             

                            The procedure is more involved than flashing a special BIOS for NUC5i5MYBE.  It requires clearing the TPM, booting system to UEFI shell, then launching a TPM FW update utility (called TPMFactoryUpd.efi) to execute the TPM FW update.  The required FW binary file is TPM20_5.0.1089.2_to_TPM20_5.62.3126.2.BIN.

                             

                            I was able to use this process to update all three of my NUC5i5MYBE with H47796-202 revision that came with 5.0.1089.2 FW for the TPM, which saved the need to exchange the NUCs via Intel Support.