Install the Firmware and RoT Security Module
Follow instructions in this section to install the ThinkSystem V3 Firmware and Root of Trust Security Module (Firmware and RoT Security Module).
About this task
This task must be operated by trained technicians that are certified by Lenovo Service. Do not attempt to remove or install the part without proper training and qualification.
(Lenovo trained technician only) After replacing the Firmware and RoT Security Module, update the UEFI, XCC, and LXPM firmware to the specific version supported by the server. For detailed information on how to update the firmware, see Tip for replacing a Firmware and RoT Security Module (Lenovo service technicians only).
Read Installation Guidelines and Safety inspection checklist to ensure that you work safely.
Power off the server and peripheral devices, disconnect the power cords from the primary chassis, then disconnect the power cords from the secondary chassis. See Power off the server.
Prevent exposure to static electricity, which might lead to system halt and loss of data, by keeping static-sensitive components in their static-protective packages until installation, and handling these devices with an electrostatic-discharge wrist strap or other grounding system.
If the server is installed in a rack, remove the server from the rack. See Remove the server from rails.
Go to Drivers and Software download website for ThinkSystem SR950 V3 to see the latest firmware and driver updates for your server.
Go to Update the firmware for more information on firmware updating tools.
Procedure
After you finish
For primary chassis only, reinstall the system I/O board and interposer assembly. See Install the system I/O board and interposer board.
Reinstall the support bracket. See Install the support bracket.
Reinstall the upper processor board (CPU BD). See Install the upper processor board (CPU BD).
Reinstall the upper processor board (CPU BD) air baffle. See Install the upper processor board (CPU BD) air baffle.
Reinstall the front top cover. See Install the front top cover.
Complete the parts replacement. See Complete the parts replacement.
Update the UEFI, XCC, and LXPM firmware to the specific version supported by the server. See Tip for replacing a Firmware and RoT Security Module (Lenovo service technicians only).
Perform OneCLI commands to restore the UEFI settings. See OneCLI commands that restore configuration settings.
Perform both OneCLI commands and XCC actions to restore the XCC settings. See OneCLI commands that restore configuration settings and Using XCC to restore the BMC configuration.
- If there is a software (SW) key, for example, XCC FoD key, installed in the system, inject the key again to ensure that the key functions properly. See Using Lenovo Features on Demand.NoteIf you need to replace the lower processor board (MB) or upper processor board (CPU BD) together with the
Firmware and RoT Security Module, update the VPD before injecting the key. See Update the Vital Product Data (VPD). - Optionally, do the following if needed:
Hide TPM. See Hide/observe TPM.
Update the TPM firmware. See Update the TPM firmware.
Enable UEFI Secure Boot. See Enable UEFI Secure Boot.
Demo video