HP Xw460c HP Integrated Lights-Out 2 User Guide for Firmware 1.75 and 1.77 - Page 43

iLO 2 Security Override Switch administration, Trusted Platform Module support

Page 43 highlights

• RBSU Disabled (most secure) If iLO 2 RBSU is disabled, user access is prohibited. This prevents modification using the RBSU interface. iLO 2 Security Override Switch administration The iLO 2 Security Override Switch allows the administrator full access to the iLO 2 processor. This access may be necessary for any of the following conditions: • iLO 2 must be re-enabled after it has been disabled. • All user accounts with the Administer User Accounts privilege have been locked out. • A bad configuration keeps the iLO 2 from displaying on the network and RBSU has been disabled. • The boot block must be flashed. Ramifications of setting the Security Override Switch include: • All security authorization checks are disabled while the switch is set. • iLO 2 RBSU runs if the host server is reset. • iLO 2 is not disabled and might display on the network as configured. • iLO 2, if disabled while the Security Override Switch is set, does not log the user out and complete the disable process until the power is cycled on the server. • The boot block is exposed for programming. A warning message is displayed on iLO 2 browser pages indicating that the iLO 2 Security Override Switch is currently in use. An iLO 2 log entry records the use of the iLO 2 Security Override Switch. An SNMP alert can also be sent upon setting or clearing the iLO 2 Security Override Switch. Setting the iLO 2 Security Override Switch also enables you to flash the iLO 2 boot block. HP does not anticipate that you will need to update the iLO 2 boot block. If an iLO 2 boot block update is ever required, physical presence at the server will be required to reprogram the boot block and reset iLO 2. The boot block will be exposed until iLO 2 is reset. For maximum security, HP recommends that you disconnect the iLO 2 from the network until the reset is complete. The iLO 2 Security Override Switch is located inside the server and cannot be accessed without opening the server enclosure. To set the iLO 2 Security Override Switch: 1. Power off the server. 2. Set the switch. 3. Power on the server. Reverse the procedure to clear the iLO 2 Security Override Switch. Depending on the server, the iLO 2 Security Override Switch might be a single jumper or a specific switch position on a dip switch panel. To access and locate the iLO 2 Security Override Switch, refer to the server documentation. The iLO 2 Security Override Switch can also be located using the diagrams on the server access panel. Trusted Platform Module support TPM is a hardware based system security feature. It is a computer chip that securely stores artifacts used to authenticate the platform. These artifacts can include passwords, certificates, or encryption keys. You can also use a TPM to store platform measurements to help ensure that the platform remains trustworthy. Configuring iLO 2 43

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235

Configuring iLO 2 43
RBSU Disabled (most secure)
If iLO 2 RBSU is disabled, user access is prohibited. This prevents modification using the RBSU
interface.
iLO 2 Security Override Switch administration
The iLO 2 Security Override Switch allows the administrator full access to the iLO 2 processor. This access
may be necessary for any of the following conditions:
iLO 2 must be re-enabled after it has been disabled.
All user accounts with the Administer User Accounts privilege have been locked out.
A bad configuration keeps the iLO 2 from displaying on the network and RBSU has been disabled.
The boot block must be flashed.
Ramifications of setting the Security Override Switch include:
All security authorization checks are disabled while the switch is set.
iLO 2 RBSU runs if the host server is reset.
iLO 2 is not disabled and might display on the network as configured.
iLO 2, if disabled while the Security Override Switch is set, does not log the user out and complete
the disable process until the power is cycled on the server.
The boot block is exposed for programming.
A warning message is displayed on iLO 2 browser pages indicating that the iLO 2 Security Override
Switch is currently in use. An iLO 2 log entry records the use of the iLO 2 Security Override Switch. An
SNMP alert can also be sent upon setting or clearing the iLO 2 Security Override Switch.
Setting the iLO 2 Security Override Switch also enables you to flash the iLO 2 boot block. HP does not
anticipate that you will need to update the iLO 2 boot block. If an iLO 2 boot block update is ever
required, physical presence at the server will be required to reprogram the boot block and reset iLO 2.
The boot block will be exposed until iLO 2 is reset. For maximum security, HP recommends that you
disconnect the iLO 2 from the network until the reset is complete. The iLO 2 Security Override Switch is
located inside the server and cannot be accessed without opening the server enclosure.
To set the iLO 2 Security Override Switch:
1.
Power off the server.
2.
Set the switch.
3.
Power on the server.
Reverse the procedure to clear the iLO 2 Security Override Switch.
Depending on the server, the iLO 2 Security Override Switch might be a single jumper or a specific switch
position on a dip switch panel. To access and locate the iLO 2 Security Override Switch, refer to the
server documentation. The iLO 2 Security Override Switch can also be located using the diagrams on the
server access panel.
Trusted Platform Module support
TPM is a hardware based system security feature. It is a computer chip that securely stores artifacts used
to authenticate the platform. These artifacts can include passwords, certificates, or encryption keys. You
can also use a TPM to store platform measurements to help ensure that the platform remains trustworthy.