RE: USB devices on Dell TB16 dock stop working after resuming

From: Mario.Limonciello
Date: Wed Nov 20 2019 - 12:06:44 EST



> > Yeah it might be useful to enumerate all the BIOS settings that are selected
> > related to Thunderbolt. Some of them are a bit confusing.
>
> BTW, I played a bit with 9380 and it looks like there is no option to
> enable Preboot ACL which means that if you have TBT security enabled
> (user or secure) the Dock PCIe side is not functional during boot, only
> once the OS has booted up. That's fine unless you want to enter BIOS
> menu from the keyboard you have connected to the TB16 dock (probably not
> too common use case anyway).

Eh? On 9380 in front of me:
System Configuration -> Thunderbolt (TM) Adapter Configuration

There is a checkbox for "Enable Thunderbolt (and PCIe behind TBT) Pre-boot
modules". It's not checked by default, but that should turn on pre-boot ACL
stuff. That's the thing that Paul probably needs checked too.

But I mean this is generally an unsafe (but convenient) option, it means that you
throw out security pre-boot, and all someone needs to do is turn off your machine,
plug in a malicious device, turn it on and then they have malicious device all the way
into OS.