Skip to main content

syslock command

Use this command to display and configure system lockdown settings.

Syntax:
syslock [-options]
Table 1. syslock options
OptionDescriptionValues
-enEnable or disable system configuration lock function.
Note
Enable with -e option can promote the current inventory as trusted snapshot.
enabled, disabled
-eEnable system configuration lock settings with or without enforcing current inventory into trusted snapshot.
Note
A default value will be set if there is not a -e option.
enabled, disabled
-l [x]List inventory of specific snapshot at index x.The index number, x, is specified as an integer in the command option.
-mTake manual snapshot. 
-dDescription for manual snapshot.String of up to 32 characters.
-cList inventory difference from trusted snapshot. 
-poSet lockdown policy.
Note
The action will prevent server booting if System Guard is in noncompliant status.
none, osboot, pperm
-cpuSet cpu lockdown.on, off
-dimmSet dimm lockdown.on, off
-pciSet pci lockdown.on, off
-driveSet drive lockdown.on, off
-riserSet riser lockdown.on, off
-bpSet bp lockdown.on, off