# HoneyComb LX2 TPM2 Module

**URL:** <https://community.solid-run.com/t/honeycomb-lx2-tpm2-module/425>\
**Category:** NXP LX2160\
**Tags:** NXP-LX2160\
**Created:** [August 12, 2022, 7:46am UTC](https://community.solid-run.com/t/honeycomb-lx2-tpm2-module/425 "2022-08-12T07:46:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![preisschild](https://dub1.discourse-cdn.com/flex005/user_avatar/community.solid-run.com/preisschild/32/137_2.png) [@preisschild](https://community.solid-run.com/u/preisschild)\
**Post date:** [August 12, 2022, 7:46am UTC](https://community.solid-run.com/t/honeycomb-lx2-tpm2-module/425/1 "2022-08-12T07:46:28Z")

</div>

Hi

I want to use the LX2 as a storage server in my homelab because it looks like a really cool low power, high connectivity board, but I still have a question regarding full disk encryption with a TPM/HSM module to save the LUKS key:

I read in the developer documentation block diagram that there is a GPIO header. Does this header also include SPI and/or I2C interfaces?

Most TPM modules that are specific to the raspberry pi use either i2c and generic GPIO Pins (e.g. Zymkey 4) or SPI Pins (e.g. LetsTrust TPM).

Zymbit Zymkey 4: [ZYMBIT - ZYMKEY4, Essential Security for Raspberry Pi](https://www.zymbit.com/zymkey/)  
LetsTrust TPM: [https://buyzero.de/en/products/letstrust-hardware-tpm-trusted-platform-module](https://buyzero.de/en/products/letstrust-hardware-tpm-trusted-platform-module)

I couldn’t find anything in the developer documentation or here, so If anyone else already has a TPM module running it would be very helpful.

---

<div class="post-metadata">

**Author:** ![jnettlet](https://dub1.discourse-cdn.com/flex005/user_avatar/community.solid-run.com/jnettlet/32/62_2.png) [@jnettlet](https://community.solid-run.com/u/jnettlet)\
**Post date:** [August 15, 2022, 8:23am UTC](https://community.solid-run.com/t/honeycomb-lx2-tpm2-module/425/2 "2022-08-15T08:23:17Z")

</div>

We currently don’t have much testing or support for a hardware based TPM solution. There are unpopulated I2C headers on the CEX7 module that could be used to add a hardware based TPM solution. We have worked with NXP on supporting TPM2.0 via optee-os and a software based TPM solution. This was work originally started by Microsoft for the iMX lineup of SOCs.

---

<div class="post-metadata">

**Author:** ![preisschild](https://dub1.discourse-cdn.com/flex005/user_avatar/community.solid-run.com/preisschild/32/137_2.png) [@preisschild](https://community.solid-run.com/u/preisschild)\
**Post date:** [August 15, 2022, 9:25am UTC](https://community.solid-run.com/t/honeycomb-lx2-tpm2-module/425/3 "2022-08-15T09:25:24Z")

</div>

Thanks for the reply.

With “CEX7 module” you mean the LX2160A daughter board, right?

I2C headers would be enough for me to buy one and give it a try 🙂

---

<div class="post-metadata">

**Author:** ![jnettlet](https://dub1.discourse-cdn.com/flex005/user_avatar/community.solid-run.com/jnettlet/32/62_2.png) [@jnettlet](https://community.solid-run.com/u/jnettlet)\
**Post date:** [August 15, 2022, 9:31am UTC](https://community.solid-run.com/t/honeycomb-lx2-tpm2-module/425/4 "2022-08-15T09:31:24Z")

</div>

In general I would recommend you user the J2 header. This is the I2C bus that can be restricted to only be accessible from Secure World. This has the RTC and eeprom for UEFI secure variable storage on it already.
