Remote management of UEFI BIOS settings and configuration
In an information handling system (IHS), remote management of basic input/output system (BIOS) settings and configuration includes maintaining a BIOS setting/configuration database, providing an application to communicate a BIOS setting/configuration from the database to a BIOS system, determining whether the BIOS setting/configuration communicated from the database to the BIOS system is a special BIOS configuration capsule packet, and validating BIOS setting/configuration.
1. A method for updating basic input/output system (BIOS) settings and configuration on an Information Handling System (IHS), comprising:
maintaining a BIOS setting/configuration database;
providing an IHS coupled to the BIOS setting/configuration database through a network, wherein the IHS includes a BIOS and an operating system (OS) including an OS device driver;
communicating with the OS device driver by an application during a boot process of the OS, wherein the communicating is performed prior to a user logging on to the IHS;
accessing the BIOS setting/configuration database by the application to combine a plurality of currently authorized BIOS setting/configuration data that is based on the IHS into a special BIOS configuration capsule packet;
communicating the special BIOS configuration capsule packet by the application to the OS device driver;
passing the special BIOS configuration capsule packet from the OS device driver to a capsule runtime service driver as a special capsule data packet;
determining, by the capsule runtime service driver, that the special capsule data packet is a special BIOS configuration capsule packet; and
validating the plurality of currently authorized BIOS setting/configuration data that is based on the IHS in the special BIOS configuration capsule packet against a plurality of currently used BIOS setting/configuration data being used by the BIOS.
2. The method of claim 1 , wherein the BIOS is a unified extensible firmware interface (UEFI) BIOS, a legacy BIOS, or an extensible firmware interface (EFI) BIOS.
3. The method of claim 1 , further comprising:
determining that there are differences between the plurality of currently authorized BIOS setting/configuration data and the plurality of currently used BIOS setting/configuration data; and
updating the plurality of currently used BIOS setting configuration data being used by the BIOS to conform with the plurality of currently authorized BIOS setting/configuration data.
4. The method of claim 3 , further comprising:
initiating a restart mechanism subsequent to the updating.
5. The method of claim 4 , wherein the restart mechanism is a special S 3 resume mechanism.
6. The method of claim 1 , further comprising:
determining that there are no differences between the plurality of currently authorized BIOS setting/configuration data and the plurality of currently used BIOS setting/configuration data; and
completing the boot process.
7. A method for updating basic input/output system (BIOS) settings and configuration on an Information Handling System (IHS), comprising:
maintaining a BIOS setting/configuration database;
providing an IHS coupled to the BIOS setting/configuration database through a network, wherein the IHS includes a BIOS and an operating system (OS) including an OS device driver;
communicating with the OS device driver by an application in response to receiving log on information for the IHS associated with a user;
accessing the BIOS setting/configuration database by the application to combine a plurality of currently authorized BIOS setting/configuration data that is based on the IHS and the user into a special BIOS configuration capsule packet;
communicating the special BIOS configuration capsule packet by the application to the OS device driver;
passing the special BIOS configuration capsule packet from the OS device driver to a capsule runtime service driver as a special capsule data packet;
determining, by the capsule runtime service driver, that the special capsule data packet is a special BIOS configuration capsule packet; and
validating the plurality of currently authorized BIOS setting/configuration data that is based on the IHS and the user in the special BIOS configuration capsule packet against a plurality of currently used BIOS setting/configuration data being used by the BIOS.
8. The method of claim 7 , wherein the BIOS is a unified extensible firmware interface (UEFI) BIOS, a legacy BIOS, or an extensible firmware interface (EFI) BIOS.
9. The method of claim 7 , further comprising:
determining that there are differences between the plurality of currently authorized BIOS setting/configuration data and the plurality of currently used BIOS setting/configuration data; and
updating the plurality of currently used BIOS setting configuration data being used by the BIOS to conform with the plurality of currently authorized BIOS setting/configuration data.
10. The method of claim 9 , further comprising:
initiating a restart mechanism subsequent to the updating.
11. The method of claim 10 , wherein the restart mechanism is a special S 3 resume mechanism.
12. The method of claim 7 , further comprising:
determining that there are no differences between the plurality of currently authorized BIOS setting/configuration data and the plurality of currently used BIOS setting/configuration data; and
allowing the user to log on to the IHS.
13. A method for updating basic input/output system (BIOS) settings and configuration on Information Handling Systems (IHSs), comprising:
maintaining a BIOS setting/configuration database;
providing a first IHS coupled to the BIOS setting/configuration database through a network, wherein the first IHS includes a first BIOS and a first operating system (OS) including a first OS device driver;
communicating with the first OS device driver by an application;
accessing the BIOS setting/configuration database by the application to combine a plurality of currently authorized BIOS setting/configuration data into a special BIOS configuration capsule packet;
communicating the special BIOS configuration capsule packet by the application to the first OS device driver;
passing the special BIOS configuration capsule packet from the first OS device driver to a first capsule runtime service driver as a special capsule data packet;
determining, by the first capsule runtime service driver, that the special capsule data packet is a special BIOS configuration capsule packet; and
validating the plurality of currently authorized BIOS setting/configuration data in the special BIOS configuration capsule packet against a plurality of currently used BIOS setting/configuration data being used by the first BIOS.
14. The method of claim 13 , wherein the first BIOS is a unified extensible firmware interface (UEFI) BIOS, a legacy BIOS, or an extensible firmware interface (EFI) BIOS.
15. The method of claim 13 , further comprising:
determining that there are differences between the plurality of currently authorized BIOS setting/configuration data and the plurality of currently used BIOS setting/configuration data; and
updating the plurality of currently used BIOS setting configuration data being used by the first BIOS to conform with the plurality of currently authorized BIOS setting/configuration data.
16. The method of claim 15 , further comprising:
initiating a restart mechanism subsequent to the updating.
17. The method of claim 16 , wherein the restart mechanism is a special S 3 resume mechanism.
18. The method of claim 13 , further comprising:
providing a plurality of second IHSs coupled to the BIOS setting/configuration database through a network, wherein the plurality of second IHSs each include a second BIOS and a second operating system (OS) including a second OS device driver;
communicating with the second OS device drivers by an application;
accessing the BIOS setting/configuration database by the application to combine a plurality of currently authorized BIOS setting/configuration data into a special BIOS configuration capsule packet;
communicating the special BIOS configuration capsule packet by the application to the second OS device drivers;
passing the special BIOS configuration capsule packet from the second OS device drivers to corresponding second capsule runtime service drivers as a special capsule data packet;
determining, by the second capsule runtime service drivers, that the special capsule data packet is a special BIOS configuration capsule packet; and
validating the plurality of currently authorized BIOS setting/configuration data in the special BIOS configuration capsule packet against a plurality of currently used BIOS setting/configuration data being used by the second BIOSs.
19. The method of claim 18 , further comprising:
determining that there are differences between the plurality of currently authorized BIOS setting/configuration data and the plurality of currently used BIOS setting/configuration data; and
updating the plurality of currently used BIOS setting configuration data being used by the second BIOSs to conform with the plurality of currently authorized BIOS setting/configuration data.
20. The method of claim 18 , wherein the application is operable to communicate with the first OS device driver and the second OS device drivers to communicate the special BIOS configuration capsule packet at scheduled times.