HP ProLiant BL660c HP ProLiant and Integrity Firmware Management Best Practice - Page 23

File encoding, Error reporting, HP SUM special considerations

Page 23 highlights

[END] ◦ Credentials: The TARGETS section allows the targets to be grouped according to the credentials needed for logging in remotely. Each TARGETS section must have a set of login credentials, which applies to all targets in that section. - To use the current host's login credentials to log in to one or more remote targets, you can do so by setting the variable USECURRENTCREDENTIAL to YES. You can supply login credentials for one or more hosts by using the variables UID and PWD. - To provide the variables at the beginning of a TARGETS section, use both of them. - To provide the variables in the middle of a TARGETS section, use one or the other to override the selected variable and continue using the active value for the remaining variable. ◦ Remote target: You can specify a remote target by using the variable HOST. Possible values are a DNS name or an IP address. File encoding To allow for the inclusion of double-byte characters, the input file is in UTF-8 format. Error reporting If errors occur in the input file, HP SUM exits with a return value of -2 (bad parameter). The details of the location and nature of the error are recorded in hpsum_execution_log__.raw. HP SUM special considerations Disabling BitLocker to permit firmware updates The TPM, when used with BitLocker, measures a system state and, upon detection of a changed ROM image, restricts access to the Windows file system if the user cannot provide the recovery key. HP SUM detects if a TPM is enabled in your system. If a TPM is detected in your system or with any remote server selected as a target, for some newer models of ProLiant servers, HP SUM utilities for HP iLO, Smart Array, NIC, and BIOS warn users prior to a flash. If the user does not temporarily disable BitLocker and does not cancel the flash, the BitLocker recovery key is needed to access the user data upon reboot. A recovery event is triggered if: • You do not temporarily disable BitLocker before flashing the system BIOS when using the Microsoft BitLocker Drive Encryption. • You have optionally selected to measure HP iLO, Smart Array, and NIC firmware. If HP SUM detects a TPM, a warning message appears. To enable firmware updates without the need to type in the TPM password on each server, the BitLocker Drive Encryption must be temporarily disabled. Disabling the BitLocker Drive Encryption Using HP SUM 23

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57

[END]
Credentials: The
TARGETS
section allows the targets to be grouped according to the
credentials needed for logging in remotely. Each
TARGETS
section must have a set of
login credentials, which applies to all targets in that section.
To use the current host's login credentials to log in to one or more remote targets,
you can do so by setting the variable
USECURRENTCREDENTIAL
to
YES
. You can
supply login credentials for one or more hosts by using the variables
UID
and
PWD
.
To provide the variables at the beginning of a
TARGETS
section, use both of them.
To provide the variables in the middle of a
TARGETS
section, use one or the other
to override the selected variable and continue using the active value for the remaining
variable.
Remote target: You can specify a remote target by using the variable
HOST
. Possible
values are a DNS name or an IP address.
File encoding
To allow for the inclusion of double-byte characters, the input file is in UTF-8 format.
Error reporting
If errors occur in the input file, HP SUM exits with a return value of -2 (bad parameter). The details
of the location and nature of the error are recorded in
hpsum_execution_log_<date>_<time>.raw
.
HP SUM special considerations
Disabling BitLocker to permit firmware updates
The TPM, when used with BitLocker, measures a system state and, upon detection of a changed
ROM image, restricts access to the Windows file system if the user cannot provide the recovery
key. HP SUM detects if a TPM is enabled in your system. If a TPM is detected in your system or
with any remote server selected as a target, for some newer models of ProLiant servers, HP SUM
utilities for HP iLO, Smart Array, NIC, and BIOS warn users prior to a flash. If the user does not
temporarily disable BitLocker and does not cancel the flash, the BitLocker recovery key is needed
to access the user data upon reboot.
A recovery event is triggered if:
You do not temporarily disable BitLocker before flashing the system BIOS when using the
Microsoft BitLocker Drive Encryption.
You have optionally selected to measure HP iLO, Smart Array, and NIC firmware.
If HP SUM detects a TPM, a warning message appears.
To enable firmware updates without the need to type in the TPM password on each server, the
BitLocker Drive Encryption must be temporarily disabled. Disabling the BitLocker Drive Encryption
Using HP SUM
23