HP Dc7800 vPro Setup and Configuration for the dc7800p Business PC with Intel - Page 22

Transport Layer Security TLS connection to the AMT system using a TLS Pre-Shared-Key PSK cipher

Page 22 highlights

26. Plug the system into a power source and connect the network. Use the integrated Intel 82566DM NIC. Intel AMT does not work with any other NIC solution. When power is reapplied to the system, the system immediately looks for a Setup and Configuration Server. If the system finds this server, the AMT system will send a "Hello" message to the server. DHCP and DNS must be available for the Setup and Configuration Server search to automatically succeed. If DHCP and DNS are not available, then the Setup and Configuration Server's IP address must be manually entered into the AMT system's MEBx. The "Hello" message contains the following information: • PID • UUID (Universally Unique Identifier) • IP address • ROM and firmware version numbers The "Hello" message is transparent to the end-user. There is no feedback mechanism to tell the user the system is broadcasting the message. The Setup and Configuration Server uses the information in the "Hello" message to initiate a Transport Layer Security (TLS) connection to the AMT system using a TLS Pre-Shared-Key (PSK) cipher suite if TLS is supported. The Setup and Configuration server uses the PID to lookup PPS in provisioning server database and uses the PPS and PID to generate TLS Pre-Master Secret. TLS is optional. For secure and encrypted transactions, use TLS if the infrastructure is available. If you do not use TLS, then HTTP Digest will be used for mutual authentication. HTTP Digest is not as secure as TLS. Setup and Configuration Server logs into AMT system with the user name and password and provisions all required data items: • New PPS and PID (for future Setup and Configuration) • TLS certificates • Private keys • Current date and time • HTTP Digest credentials • HTTP Negotiate credentials You can set other options depending on S&CS implementation. The system goes from In-Setup phase to Operational phase, and AMT is fully operational. Once in the Operational phase, you can remotely manage the system and you can provide the system to endusers for regular use. 22

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34

22
26.
Plug the system into a power source and connect the network. Use the integrated Intel 82566DM
NIC. Intel AMT does not work with any other NIC solution.
When power is reapplied to the system, the system immediately looks for a Setup and Configuration
Server. If the system finds this server, the AMT system will send a “Hello” message to the server.
DHCP and DNS must be available for the Setup and Configuration Server search to automatically
succeed. If DHCP and DNS are not available, then the Setup and Configuration Server’s IP address
must be manually entered into the AMT system’s MEBx.
The “Hello” message contains the following information:
PID
UUID (Universally Unique Identifier)
IP address
ROM and firmware version numbers
The “Hello” message is transparent to the end-user. There is no feedback mechanism to tell the user
the system is broadcasting the message.
The Setup and Configuration Server uses the information in the “Hello” message to initiate a
Transport Layer Security (TLS) connection to the AMT system using a TLS Pre-Shared-Key (PSK) cipher
suite if TLS is supported.
The Setup and Configuration server uses the PID to lookup PPS in provisioning server database and
uses the PPS and PID to generate TLS Pre-Master Secret. TLS is optional. For secure and encrypted
transactions, use TLS if the infrastructure is available. If you do not use TLS, then HTTP Digest will be
used for mutual authentication. HTTP Digest is not as secure as TLS.
Setup and Configuration Server logs into AMT system with the user name and password and
provisions all required data items:
New PPS and PID (for future Setup and Configuration)
TLS certificates
Private keys
Current date and time
HTTP Digest credentials
HTTP Negotiate credentials
You can set other options depending on S&CS implementation.
The system goes from In-Setup phase to Operational phase, and AMT is fully operational. Once in the
Operational phase, you can remotely manage the system and you can provide the system to end-
users for regular use.