Looking to pass HSI-1 tests, anyone with an z890 mobo

Ubuntu noob here thinking I may need to log a ticket with Asrock. I have flashed the BIOS and is currently running the latest version.

One of the issues I have:

Intel Management Engine Manufacturing Mode: ! Fail (Not Locked)

Spent hours trying to find this in the BIOS, then a search found this:

For ASRock Z890 motherboards on Ubuntu, the Intel MEI (Management Engine Interface) is typically unlocked or hidden by default in standard BIOS images, as many ASRock boards do not expose the MEBx (Management Engine BIOS Extension) configuration utility in the UEFI setup.

Do you have Ubuntu installed?

Which version?

Yes, running Ubuntu 26.04.1

Given that you have identified a possible UEFI (BIOS) issue, do you experience any tangible problem after booting into Ubuntu 26.04.1?

1 Like

You are completely right about opening a ticket with ASRock :))

This ā€œManufacturing Modeā€ is left open in the factory to write MAC addresses and Intel ME settings. Before sending the board to stores, the factory script must lock it, but ASRock often forgets to lock it in their BIOS.

You will not find any button for this in BIOS settings because it is not a user option. fwupd fails HSI-1 test because unlocked ME is a real security risk. Only ASRock support can fix this by releasing a new BIOS or ME tool with the lock enabled…

Nope… Everything works really well. Using Unity3d (with vs code), Epic games and steam games.

Looks like I am going to be ā€˜that guy’ Asrock are tired of hearing from… This is going to be fun.

1 Like

Someone has to be ā€œthat guyā€ to keep motherboard vendors on their toes :-))

2 Likes

Logged a ticket with Asrock. Maybe this will help someone, here is thier reply:

Dear customer,

Thank you for contacting us.

This is expected on consumer-level motherboards across manufacturers.

However, we lock ME Descriptor GPIO at the hardware level on the boards, so the ME region cannot be modified without unlocking it.

Therefore, this configuration does not pose any security risks or vulnerabilities.

We believe you can use the board with no concern.

Many Thanks,

ASRock TSD

3 Likes

Ok… they strap the Flash Descriptor GPIO at hardware level on this board…
Good to know :slight_smile:

Thanks for following up and sharing ASRock’s answer! :wink:

2 Likes