HP ProLiant WS460c HP Smart Update Manager 6.0.0 User Guide - Page 14

Launching and logging into HP SUM, Launching HP SUM

Page 14 highlights

the BitLocker Drive Encryption can be re-enabled. Once the BitLocker Drive Encryption has been re-enabled, the plain text key is removed and BitLocker secures the drive again. CAUTION: Temporarily disabling BitLocker Drive Encryption can compromise drive security and should only be attempted in a secure environment. If you are unable to provide a secure environment, HP recommends providing the boot password and leaving BitLocker Drive Encryption enabled throughout the firmware update process. This requires setting the /tpmbypass parameter for HP SUM or the firmware update is blocked. To temporarily disable BitLocker support to allow firmware updates: 1. Click Start, and then search for gpedit.msc in the Search Text box. 2. When the Local Group Policy Editor starts, click Local Computer Policy. 3. Click Computer Configuration→Administrative Templates→Windows Components→BitLocker Drive Encryption. 4. When the BitLocker settings are displayed, double-click Control Panel Setup: Enable Advanced startup options. 5. When the dialog box appears, click Disable. 6. Close all windows, and then start the firmware update. To enable advanced startup options: 1. Enter cscript manage-bde.wsf -protectors -disable c: 2. When the firmware update process is completed, the BitLocker Drive Encryption support can be re-enabled by following steps 1 through 4 but clicking Enabled in step 5 instead. The following command can be used to re-enable BitLocker Drive Encryption after firmware deployment has completed. 3. Enter cscript manage-bde.wsf -protectors -enable c: The following table describes TPM detection scenarios that you might encounter. Scenario Result If TPM is detected and enabled, the installation is not silent, A warning message appears. Select OK to continue. The and a system ROM must be updated. installation is not canceled. If TPM is detected and enabled, the installation is silent, the /tpmbypass switch is not given, and any firmware updated must be applied to the server. No warning appears. A new log file is generated (%systemdrive%\cpqsystem\log\cpqstub.log). Because the installation is silent, the installation is terminated and cannot continue. If TPM is detected and enabled with Option ROM A warning message appears. After selecting OK, you can Measuring, the installation is not silent, and a system ROM continue. The installation is not canceled. must be updated. If TPM is detected and enabled with Option ROM Measuring, the installation is silent, the /tpmbypass switch is not given, and any firmware updated must be applied to the server. No warning appears. A new log file is generated (%systemdrive%\cpqsystem\log\cpqstub.log). Because the installation is silent, the installation is terminated and cannot continue. If TPM is detected and enabled, the installation is silent, the installation occurs, and the /tpmbypass switch is supplied. The installation occurs. Launching and logging into HP SUM Launching HP SUM HP SUM supports 32-bit and 64-bit processors. When you launch HP SUM, a script chooses the version of HP SUM to run. HP SUM logs you in using your current user credentials. To run HP SUM, your userid needs to be part of the administrator group, or, on a Linux system, you can run HP 14 Downloading, installing, and launching HP SUM

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77

the BitLocker Drive Encryption can be re-enabled. Once the BitLocker Drive Encryption has been
re-enabled, the plain text key is removed and BitLocker secures the drive again.
CAUTION:
Temporarily disabling BitLocker Drive Encryption can compromise drive security and
should only be attempted in a secure environment. If you are unable to provide a secure
environment, HP recommends providing the boot password and leaving BitLocker Drive Encryption
enabled throughout the firmware update process. This requires setting the
/tpmbypass
parameter
for HP SUM or the firmware update is blocked.
To temporarily disable BitLocker support to allow firmware updates:
1.
Click
Start
, and then search for
gpedit.msc
in the Search Text box.
2.
When the Local Group Policy Editor starts, click
Local Computer Policy
.
3.
Click
Computer Configuration
Administrative Templates
Windows Components
BitLocker
Drive Encryption
.
4.
When the BitLocker settings are displayed, double-click
Control Panel Setup: Enable Advanced
startup options
.
5.
When the dialog box appears, click
Disable
.
6.
Close all windows, and then start the firmware update.
To enable advanced startup options:
1.
Enter
cscript manage-bde.wsf -protectors -disable c:
2.
When the firmware update process is completed, the BitLocker Drive Encryption support can
be re-enabled by following steps 1 through 4 but clicking
Enabled
in step 5 instead. The
following command can be used to re-enable BitLocker Drive Encryption after firmware
deployment has completed.
3.
Enter
cscript manage-bde.wsf -protectors -enable c:
The following table describes TPM detection scenarios that you might encounter.
Result
Scenario
A warning message appears. Select
OK
to continue. The
installation is not canceled.
If TPM is detected and enabled, the installation is not silent,
and a system ROM must be updated.
No warning appears. A new log file is generated
(%systemdrive%\cpqsystem\log\cpqstub.log
).
If TPM is detected and enabled, the installation is silent,
the
/tpmbypass
switch is not given, and any firmware
updated must be applied to the server.
Because the installation is silent, the installation is
terminated and cannot continue.
A warning message appears. After selecting
OK
, you can
continue. The installation is not canceled.
If TPM is detected and enabled with Option ROM
Measuring, the installation is not silent, and a system ROM
must be updated.
No warning appears. A new log file is generated
(
%systemdrive%\cpqsystem\log\cpqstub.log
).
If TPM is detected and enabled with Option ROM
Measuring, the installation is silent, the
/tpmbypass
Because the installation is silent, the installation is
terminated and cannot continue.
switch is not given, and any firmware updated must be
applied to the server.
The installation occurs.
If TPM is detected and enabled, the installation is silent,
the installation occurs, and the
/tpmbypass
switch is
supplied.
Launching and logging into HP SUM
Launching HP SUM
HP SUM supports 32–bit and 64–bit processors. When you launch HP SUM, a script chooses the
version of HP SUM to run. HP SUM logs you in using your current user credentials. To run HP SUM,
your userid needs to be part of the administrator group, or, on a Linux system, you can run HP
14
Downloading, installing, and launching HP SUM