On Tue, 7 Dec 2021 at 07:25, Mike Rapoport <rppt@xxxxxxxxxx> wrote: > Can you please describe the actual check for the memory encryption and how > it would impact the HSI rating? The problem HSI is trying to solve is that customers are buying systems where the CPU supports memory encryption, where the motherboard and dram controller support memory encryption and where the vendor says it's supported. But in some cases it's not working, either because the system firmware is not working properly, or some component requires updating to enable the feature. We're found quite a few cases where people assumed this was all working fine, but on looking closer, finding out that it's not working at all. The higher HSI rating would only be available where most of the system RAM is encrypted, although we've not worked out a heuristic number for "good enough" yet. > I wonder, for example, why did you choose per-node reporting rather than > per-region as described in UEFI spec. I think Dave is better to answer this question. Richard.