Successfully Added TPM 2.0 to X99 Motherboard (extra, fairly complicated Infineon firmware update to 5.63.3353 was needed)

aldamon

Supreme [H]ardness
Joined
May 24, 2000
Messages
6,675
Hi all,

I recently upgraded my X99/5820K HTPC to Windows 11 using Rufus, but wanted to circle back and see if I could get a TPM 2.0 module working in case of future issues. I was successful, but it took some extra research and steps to get it working.

The X99 I have is the ASRock X99 Extreme43.1. It's a late-stage X99, so it came with extra goodies like USB 3.1, NVME support, and a TPM slot. In this case, it's an 18-1 slot and it supports TPM 2.0. I thought with the 2.0 slot there I was a made man and this was going to be an easy process. Wrong.

I went to Ebay and found this guy:

https://www.ebay.com/itm/225942548106

TPM TPM2.0 Module ASRock TPM 18-1 Pin Security Module Board Win11 for Infineon​


Ordered, it arrived fairly quickly, popped it in, and enabled secure boot. Everything seemed fine until I checked Attestation status. Result was Not Ready and Firmware update is needed for your security processor. WTF?

After a deep dive, I found out security flaws have been found in TPM modules over the years. Usually, these flaws are patched by mobo manufacturers in BIOS updates, but obviously this doesn't help with stand-alone cards. Firmware on my card out of the box was 5.63.3144.0, which seemed to be fully patched from my research, because it was after a well-publicized 2018 security flaw. Turns out, forum threads from 2018 are no longer accurate. For Win11, there's yet another firmware update available that takes Infineon cards to 5.63.3353. With no stand-alone patcher from Infineon to use (WTF), and my mobo long past EoL, the fine folks at Prema Mod provided a firmware updater that runs on a USB stick and takes numerous cards to the newer version. Here is a good forum thread about it with the download:

https://winraid.level1techs.com/t/w...are-for-asus-tpm-m-r2-0-module-13-pin/99877/3

If you're interested, follow ALL of the directions in the README file. On my mobo, disabling the TPM slot entirely was necessary for the firmware to update, which because of a quirk of the board, meant I had to clear CMOS after the patch to get the TPM slot back. Just disabling all of the options on the card was not enough and the updater failed. The card had to be disabled fully. YMMV. Some mobos might be able to just disable the card itself.

Anyway, success:

1716040226803.png


There we go. Good attestation and firmware 5.63.3353.0 on an X99. Obviously, I still have a 5820K, but if that becomes an issue in the future, I'll address it then. I hope this post helps someone. Good luck!
 
Last edited:
As an eBay Associate, HardForum may earn from qualifying purchases.
Back
Top