Using TPM to Protect Confidential Information in the Machine
Document number: A0YC-1U4
By enabling TPM, you can encrypt and securely manage confidential information such as passwords and keys and certificates saved on the machine. When TPM is enabled, be sure to back up the TPM key to a USB memory device. If the TPM chip malfunctions, you can restore the backed up TPM key to recover the system.
* The machine may take some time to start up after TPM has been enabled.
TPM does not guarantee complete protection of data and hardware.
Canon is not responsible for failure or damage resulting from the use of TPM.
When Using the Administrator with the "Administrator" User Name
Before you enable TPM, change the default password for the "Administrator" user name so that only specific administrators know the new password. Administrator Privileges and Password
* If you leave the password at its default setting, there is a risk that a third party could back up the TPM key and steal the backup data. The TPM key can only be backed up one time, so if a third party steals the backup data, you will not be able to restore the TPM key.
When Initializing All Settings and Data on the Machine
Use the control panel to configure the settings. You cannot configure the settings using Remote UI from a computer. Administrator privileges are required. The machine must be restarted to apply the settings.
Required Preparations
When you use the administrator with the "Administrator" user name, check that the password has been changed from the default setting. Administrator Privileges and Password
After enabling TPM, immediately back up the TPM key. The TPM key is required to recover confidential information if the TPM chip should malfunction. Use a commercial USB memory device for the backup of the TPM key.
* The TPM key is encrypted when backed up. The backup data cannot be managed or viewed on a computer.
Use the control panel to back up the TPM key. You cannot back up the TPM key using Remote UI from a computer. Administrator privileges are required.
Required Preparations
Provide a USB memory device that satisfies the following conditions. Do not connect anything other than the USB memory device that you are using.
When the setting to use the MEAP driver for the USB storage device is enabled, the USB memory device may not be recognized even if connected correctly. [Use MEAP Driver for USB Input Device]
Restoring the TPM Key
If the TPM chip malfunctions, use the backup data of the TPM key to restore the TPM key on a new TPM chip. You can recover encrypted confidential information by restoring the TPM key.
* For details on troubleshooting or replacing the TPM chip, contact your dealer or service representative.
Use the control panel to restore the TPM key. You cannot restore the TPM key using Remote UI from a computer. Administrator privileges are required. The machine must be restarted to apply the restoration.
Required Preparations
Prepare the USB memory device with the backed up TPM key. Do not connect anything other than the USB memory device that you are using.
IMPORTANT
Restoring the TPM Key Does Not Recover the Memory Area Itself.
The TPM key restore function recovers access to the storage and SRAM resulting from the TPM chip malfunction. It does not recover the memory area itself.
Precautions When Restoring the TPM Key
You cannot use the machine when restoring the TPM key.
Do not remove the USB memory device or subject it to shock or vibration during restoration. Do not turn OFF the machine during restoration.
* Removing the USB memory device when restoring the TPM key can cause the machine to malfunction.
When the setting to use the MEAP driver for the USB storage device is enabled, the USB memory device may not be recognized even if connected correctly. [Use MEAP Driver for USB Input Device]
This site uses cookies to provide its contents and functions and improve their qualities etc. You can find out more about our use of the cookies here. If you select "Reject", only cookies necessary to provide the contents and functions of the site are recorded and stored.