HP dc7800 - Convertible Minitower PC Setup And Configuration Manual

HP dc7800 - Convertible Minitower PC Setup And Configuration Manual

Vpro setup and configuration for the dc7800p business pc with intel vpro processor technology
Hide thumbs Also See for dc7800 - Convertible Minitower PC:

Advertisement

vPro Setup and Configuration for the dc7800p Business PC
with Intel vPro Processor Technology
Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3
AMT Setup and Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
AMT System Phases . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
SMB Mode - AMT Setup and Configuration with MEBx . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
SMB Mode - AMT Setup and Configuration Steps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6
Intel AMT WebGUI . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Connecting with the Intel AMT WebGUI - SMB Example . . . . . . . . . . . . . . . . . . . . . . . . . 14
Setup and Configuration Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
Setup and Configuration Server Availability . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
Enterprise Mode Setup and Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
Enterprise Mode - AMT Setup and Configuration Steps . . . . . . . . . . . . . . . . . . . . . . . . . . 17
Provisioning Methods . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24
Legacy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24
IT TLS-PSK . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24
OEM TLS-PSK . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24
USB Drive Key Set Up and Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25
USB Drive Key Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26
Remote Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26
Remote Configuration: Bare-Metal vs. Delayed . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
Remote Configuration Time-outs in HP Systems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28
Remote Configuration Prerequisites . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28
MEBx and Hashes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28
List of Supported CA Certificates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 30
Return to Default . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 31
Full Return to Factory Defaults . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32
Appendix A: Frequently Asked Questions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32
Appendix B: Power / Sleep / Global States Explained . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34
Appendix C: Wake-On-ME Explained . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35
1

Advertisement

Table of Contents
loading

Summary of Contents for HP dc7800 - Convertible Minitower PC

  • Page 1: Table Of Contents

    vPro Setup and Configuration for the dc7800p Business PC with Intel vPro Processor Technology Introduction ............3 AMT Setup and Configuration .
  • Page 2: Introduction

    2.x feature set. HP has updated this white paper to include the new features of AMT 3.0. By default, AMT shipping on the HP Compaq dc7800p Business PC will be inactive. It must be set up and configured in the system before it can be used. The setup and configuration process is also known as pro- visioning.
  • Page 3: Amt Setup And Configuration

    AMT Setup and Configuration AMT Setup involves the necessary steps to enable AMT such as setting up the system for AMT mode and enabling network connectivity. This setup is generally performed only once in the lifetime of a system. When AMT is enabled, it can be discovered by management software over a network. AMT Configuration sets up all other AMT options not covered in AMT Setup, such as enabling the system for Serial-Over-LAN (SOL) or IDE-Redirect (IDE-R).
  • Page 4 BIOS revision of at least version 1.04 and a ME firmware of at least 3.0.1.1 104 and a MEBx of at least version 3.0.2.0004. Shipping HP Compaq dc7700p Business PCs with AMT 2.0 or 2.1 can be upgraded to AMT 2.2 through a BIOS upgrade available using Web download.
  • Page 5: Smb Mode - Amt Setup And Configuration Steps

    PCs have a BIOS revision of at least version 3.03, an ME firmware of at least version 2.2.1.1034, and a MEBx of at least version 2.1.4.000. Updating an HP Compaq dc7700p system from AMT 2.0 or 2.1 to AMT 2.2 by flashing the BIOS will install five Verisign certificates so the system can be used in Remote Configuration.
  • Page 6 Change the password to establish AMT ownership. The system will go from Factory phase to In-Setup phase. The ME and AMT options within the MEBx are accessible and you can access the system using the AMT WebGUI. Select the Intel ME Platform Configuration. A window displays indicating that the system resets after configuration.
  • Page 7 Default Setting = Intel AMT, Recommended Setting = Intel AMT This option sets the platform management mode: None, Intel AMT, or ASF. By default, HP Compaq dc7800p Business PCs are set to Intel AMT, and ASF is an available option.
  • Page 8 Select Intel ME Power Control. Figure 4 Intel ME Power Control Screen a. Select Intel ME ON in Host Sleep States, and then select Desktop:ON in S0, S3, ME WoL in S3, S4-5, OFF After Power Loss. Default Setting = Desktop: ON in S0, Recommended Setting = Desktop: ON is S0, S3, ME WoL in S3, S4-5, OFF After Power Loss This option sets the ME power policy when the system is in a sleep state (Sx) and when returning from a G3 power loss.
  • Page 9 ME ON in Host Sleep State ME Behavior Option 6 ME is ON at all times S0, S3, S4, and S5. ME will not auto- matically initialize after recovering from a G3 power loss. Option 7 ME is ON only when the system is in S0. It will be asleep in S3 - S5 unless it is called upon.
  • Page 10 NOTES: Spaces are not accepted in the host name. Make sure there is not a duplicate host name on the network. You can use host names in place of the system’s IP for any applications requiring the IP address. Select TCP/IP. a.
  • Page 11 The domain name is blank by default. If not populated, then the default domain of “Provisionserver” is used when connecting to a Setup and Configuration Server. If the name of the S&CS is not “Provisionserver” and the domain name is blank, then an alias must be set up in the DHCP server to redirect the connection for "Provisionserver"...
  • Page 12: Intel Amt Webgui

    d. Select IDE Redirection, and then select Enabled. Default Setting = Enabled, Recommended Setting = Enabled This option enables/disables IDE Redirection (IDE-R) functionality. Select Secure Firmware Update, and then select Enabled. Default Setting = Enabled, Recommended Setting = Enabled This option enables/disables the ability to remotely update the ME firmware. Skip Set PRTC.
  • Page 13: Connecting With The Intel Amt Webgui - Smb Example

    The AMT WebGUI is accessible from the following Web Browsers: • Microsoft Internet Explorer 6 SP1 or newer • Netscape Navigator 7.1 or newer • Mozilla Firefox 1.0 or newer • Mozilla 1.7 or newer Limited remote system management includes: •...
  • Page 14 Type the user name and password. The default username is admin and the password is what you set during AMT Setup in the MEBx. Figure 6 Intel AMT WebGUI Screen Review system information and/or make any necessary changes. NOTE: You can change the MEBx password for the remote system in the WebGUI. Changing the password in the WebGUI or a remote console results in two passwords.
  • Page 15: Setup And Configuration Server

    Setup and Configuration Server A Setup and Configuration Server (SCS) is an application that executes over a network performing AMT Setup and Configuration. It is required for Enterprise mode setup and configuration. In a PSK Setup and Configuration, both the AMT client system and the SCS must share a set of Provision- ing ID (PID) and Provisioning Passphrase (PPS).
  • Page 16: Enterprise Mode Setup And Configuration

    Enterprise Mode Setup and Configuration Enterprise mode is for large corporate customers. An SCS is required for Enterprise mode Setup and Con- figuration. The SCS is also known as a Provisioning Server as seen in the MEBx. Enterprise Mode - AMT Setup and Configuration Steps The AMT Setup portion for Enterprise mode is the same as SMB mode.
  • Page 17 Select Intel AMT Configuration. The Intel AMT Configuration screen includes numerous options, which are available by scrolling down the menu. Figure 7 Intel AMT Configuration Screen Figure 8 Intel AMT Configuration Screen Continued Select Host Name, and then type a host name Default Setting = HPSystem, Recommended Setting = User Dependent Spaces are not accepted in the host name.
  • Page 18 Select TCP/IP. a. Select Disabling Network Interface, and then select N. Default Setting = Network Interface Enabled, Recommended Setting = Network Interface Enabled If network is disabled, then all remote AMT capabilities are disabled and TCP/IP settings will not be necessary. This option is a toggle, and the next time you access it you are prompted with the opposite setting.
  • Page 19 This option shows the current provisioning TLS mode. The three options are: None, PKI, and PSK. This option is only for display, no changes can be made here. b. Select Provisioning Record. Default Setting = Not Present This option shows provision record data of the system. The provisioning record for a system with PSK provisioning will include the following information: •...
  • Page 20 d. Select TLS PSK. Figure 10 Intel TLS PSK Configuration Screen i. Select Set PID and PPS. This option is for Provisioning ID (PID) and Provisioning Passphrase (PPS) entry. PIDs are 8 characters and PPS are 32 characters. There are dashes between every set of four characters so counting dashes, PIDs are 9 characters and PPS are 40 characters.
  • Page 21 Select SOL/IDE-R, and then select Y. a. A message window indicates that the system resets after configuration. b. Select Username and Password, and then select Enabled. Default Setting = Enabled, Recommended Setting = Enabled This option allows you to add users and passwords from the WebGUI. If the option is disabled, then only the administrator has MEBx remote access.
  • Page 22 Plug the system into a power source and connect the network. Use the integrated Intel 82566DM NIC. Intel AMT does not work with any other NIC solution. When power is reapplied to the system, the system immediately looks for a Setup and Configuration Server.
  • Page 23: Provisioning Methods

    Provisioning Methods There are three methods of provisioning a system with Enterprise mode: • Legacy • IT TLS-PSK • OEM TLS-PSK Legacy If you want TLS, execute legacy method of AMT set up and configuration on an isolated network separate from the corporate network.
  • Page 24: Usb Drive Key Set Up And Configuration

    Alternatively, the customer can provide HP with their own Administrator password, PID, and PPS to use for the order, which HP will use to bring the systems into the In-Setup phase. In the second stage, the customer receives the In-Setup systems and the PID, PPS, and password informa- tion.
  • Page 25: Usb Drive Key Requirements

    RCFG is available starting with AMT 2.2 for the dc7700p HP Compaq Business PC and with AMT 3.0 for the dc7800p HP Compaq Business PC. It is not available with AMT 2.0 and AMT 2.1 on the dc7700p HP Compaq Business PC. Systems with older AMT revisions must be upgraded to at least AMT 2.2 to take...
  • Page 26: Remote Configuration: Bare-Metal Vs. Delayed

    AMT system is configured without the use of a local agent and does not use One Time Password (OTP) authentication. Bare-Metal RCFG is only available for AMT 3.0 on the dc7800p HP Compaq Business PC. It is not avail- able for AMT 2.2 on the dc7700p HP Compaq Business PC.
  • Page 27: Remote Configuration Time-Outs In Hp Systems

    The HP Compaq dc7700p Business PCs that are AMT 2.2 compliant will be shipped out of the factory in Delayed mode. When initiated by a remote console, Hello messages are broadcast for 6 hours.
  • Page 28 Select TLS PKI. Figure 1 1 Intel Remote Configuration Screen Select Remote Configuration Enable/Disable. Default Setting = Enabled, Recommended Setting = Enabled This option enables or disables remote configuration. Skip Manage Certificate Hashes. This option shows the hashes in the system, including the name of the hash and whether it is active. If no hashes are in the system, then an option to add one is available.
  • Page 29: List Of Supported Ca Certificates

    List of Supported CA Certificates The following list provides supported Certificate Authorities and certificates. Not all certificates are popu- lated in certain configurations. • VeriSign Class 3 Primary CA-G1 • End Date: 8/1/2028 • SHA1 Fingerprint: 74 2C 31 92 E6 07 E4 24 EB 45 49 54 2B E1 BB C5 3E 61 74 E2 •...
  • Page 30: Return To Default

    Return to Default Return to Default is also know as Unprovisioning. An AMT Setup and Configured system can be unprovi- sioned. It is done through the AMT Configuration Screen and the Un-Provision option. Figure 12 Intel AMT Unprovisioning Screen Depending on how the system was previously provisioned, one or both unprovisioning options may appear.
  • Page 31: Full Return To Factory Defaults

    Full Return to Factory Defaults All AMT settings can be returned to the factory default by clearing CMOS. This includes resetting the password to the default “admin”. However, setting in the ME such as the ME Power Settings will not be reset.
  • Page 32 Why does a new password set with the WebGUI cannot be used locally in the MEBx? A password set with the WebGUI is a remote password and will only work when accessing the MEBx remotely. It does not work with the MEBx locally. The local password must be used to locally access the MEBx.
  • Page 33: Appendix B: Power / Sleep / Global States Explained

    Appendix B: Power / Sleep / Global States Explained A computer can be in one of several power states under the Advanced Configuration and Power Interface (ACPI) specification. These power states are also known as Sleep (Sx) states or Global (Gx) states. •...
  • Page 34: Appendix C: Wake-On-Me Explained

    Appendix C: Wake-On-ME Explained Wake-On-ME, also known as ME WoL, is a feature that allows the ME to go into a low power state when it is not used. There are three conditions that must be met for Wake-On-ME to function. •...

This manual is also suitable for:

Dc7800

Table of Contents