HP ML150 HP ProLiant Intel-based 100-series G6 server technology - Page 19

BitLocker Drive Encryption, Server management and deployment, Systems management and monitoring - g6 smartstart

Page 19 highlights

TPM is an option on all ProLiant 100-series G6 servers. For more information about TPM, go to www.hp.com/go/TPM BitLocker Drive Encryption Microsoft BitLocker Drive Encryption (BitLocker) is a data protection feature available in Windows Server 2008. BitLocker uses the enhanced security capabilities of TPM version 1.2 to protect data and to ensure that a server running Windows Server 2008 has not been compromised while the system was offline. Implementing BitLocker requires the following: • The Master Boot Record (MBR), a small, encrypted system partition of approximately 50 MB to contain boot utilities • TPM version 1.2 • Trusted Computing Group (TCG) compliant firmware including support of "Static Root of Trust" • Two NTFS partitions on the boot drive During the boot process, the TPM will not release the encryption key until completing a comparison of operating system configuration information (or hash) with an earlier snapshot of the same data. If any part of the hash is compromised (for example by introduction of malicious code), the TPM ensures that the volume encryption key is never released. Server management and deployment ProLiant ML and DL 100-series G6 server users each have different computing requirements. Consequently, the way in which customers manage, deploy, and control servers can differ. With these requirements in mind, this section examines the following management topics: • Systems management and monitoring • Intelligent Platform Management Interface (IPMI) 2.0 and Data Center Management Interface (DCMI) 1.0 Standards • HP ProLiant Onboard Administrator Powered by Lights-Out 100i remote management and control • Server deployment Some of these technologies are new tools for the ProLiant 100-series G6 servers, while others have been available with previous generations of ProLiant 100-series servers. Users may already be familiar with Agents, SmartStart Scripting Toolkit (SSSTK), and software Smart Components. These tools are now available for ProLiant 100-series G6 servers. The tools let users deploy many servers at once and manage them with HP SIM and Insight Management Agents. Systems management and monitoring Unplanned downtime can be significantly reduced through alerting provided by Insight Management Agents, which are based on Simple Network Management Protocol (SNMP). SNMP is the protocol developed to manage nodes (such as servers, workstations, routers, switches, and hubs) on an IP network. Network management systems learn of problems by receiving traps or change notices from network devices implementing SNMP. Insight Management Agents ProLiant 100-series G6 servers can use the same SNMP-based Insight Management Agents that are supported by other ProLiant servers. This means that administrators can use SIM 5.3 and greater to manage ProLiant 100-series G6 servers. Administrators can also use any other SNMP- based management tool. Support Automation Services are provided on 100-series G6 servers through these 19

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29

TPM is an option on all ProLiant 100-series G6 servers. For more information about TPM, go to
www.hp.com/go/TPM
BitLocker Drive Encryption
Microsoft BitLocker Drive Encryption (BitLocker) is a data protection feature available in Windows
Server 2008. BitLocker uses the enhanced security capabilities of TPM version 1.2 to protect data and
to ensure that a server running Windows Server 2008 has not been compromised while the system
was offline.
Implementing BitLocker requires the following:
The Master Boot Record (MBR), a small, encrypted system partition of approximately 50 MB to
contain boot utilities
TPM version 1.2
Trusted Computing Group (TCG) compliant firmware including support of “Static Root of Trust”
Two NTFS partitions on the boot drive
During the boot process, the TPM will not release the encryption key until completing a comparison of
operating system configuration information (or hash) with an earlier snapshot of the same data. If any
part of the hash is compromised (for example by introduction of malicious code), the TPM ensures that
the volume encryption key is never released.
Server management and deployment
ProLiant ML and DL 100-series G6 server users each have different computing requirements.
Consequently, the way in which customers manage, deploy, and control servers can differ. With
these requirements in mind, this section examines the following management topics:
Systems management and monitoring
Intelligent Platform Management Interface (IPMI) 2.0 and Data Center Management Interface
(DCMI) 1.0 Standards
HP ProLiant Onboard Administrator Powered by Lights-Out 100i remote management and control
Server deployment
Some of these technologies are new tools for the ProLiant 100-series G6 servers, while others have
been available with previous generations of ProLiant 100-series servers. Users may already be
familiar with Agents, SmartStart Scripting Toolkit (SSSTK), and software Smart Components. These
tools are now available for ProLiant 100-series G6 servers. The tools let users deploy many servers at
once and manage them with HP SIM and Insight Management Agents.
Systems management and monitoring
Unplanned downtime can be significantly reduced through alerting provided by Insight Management
Agents, which are based on Simple Network Management Protocol (SNMP). SNMP is the protocol
developed to manage nodes (such as servers, workstations, routers, switches, and hubs) on an IP
network. Network management systems learn of problems by receiving traps or change notices from
network devices implementing SNMP.
Insight Management Agents
ProLiant 100-series G6 servers can use the same SNMP-based Insight Management Agents that are
supported by other ProLiant servers. This means that administrators can use SIM 5.3 and greater to
manage ProLiant 100-series G6 servers. Administrators can also use any other SNMP- based
management tool. Support Automation Services are provided on 100-series G6 servers through these
19