background image

Note:

  

A

 

PPS

 

value

 

of

 

‘0000-0000-0000-0000-0000-0000-0000-0000’

 

will

 

not

 

change

 

the

 

setup

 

configuration

 

state.

 

If

 

this

 

value

 

is

 

used,

 

the

 

setup

 

and

 

configuration

 

state

 

will

 

stay

 

as

 

Not-started

.

 

   

Delete

 

PID

 

and

 

PPS

 

 

Delete

 

the

 

current

 

PID

 

and

 

PPS

 

stored

 

in

 

Intel

 

ME.

Note:

  

Using

 

this

 

option

 

will

 

set

 

the

 

setup

 

and

 

configuration

 

process

 

parameter

 

to

 

In

 

Process

.

v

   

TLS

 

PKI

:

 

This

 

menu

 

contains

 

options

 

for

 

the

 

TLS

 

PKI

 

configuration

 

settings.

 

Select

 

TLS

 

PKI

.

 

The

 

TLS

 

PKI

 

setting

 

menu

 

displays.

Note:

  

This

 

option

 

is

 

also

 

only

 

needed

 

for

 

Enterprise

 

mode.

 

If

 

you

 

choose

 

SMB

 

mode,

 

you

 

need

 

not

 

to

 

enter

 

this

 

option

 

button.

The

 

Remote

 

configuration

 

options

 

are

 

contained

 

under

 

the

 

TLS

 

PKI

 

submenu.

 

There

 

are

 

four

 

remote

 

configuration

 

items:

 

   

Remote

 

Configuration

 

Enable/Disable

 

Remote

 

Configuration

 

=

 

Enabled

:

 

To

 

enable

 

remote

 

configuration.

 

Remote

 

Configuration

 

=

 

Disabled

:

 

Remote

 

configuration

 

cannot

 

occur.

 

The

 

menu

 

options

 

will

 

be

 

displayed,

 

but

 

cannot

 

be

 

used

 

until

 

remote

 

configuration

 

is

 

enabled.

Note:

  

This

 

option

 

cannot

 

be

 

modified

 

once

 

the

 

setup

 

and

 

configuration

 

procedure

 

is

 

in

 

process.

 

This

 

parameter

 

can

 

only

 

be

 

modified

 

while

 

the

 

system

 

is

 

in

 

unprovisioned

 

state.

 

Enabling/Disabling

 

Remote

 

configuration

 

will

 

cause

 

a

 

partial

 

unprovision

 

if

 

the

 

setup

 

and

 

configuration

 

is

 

“In-process”.

 

   

Manage

 

Certificate

 

Hashes

 

Select

 

Manage

 

Certificate

 

Hashes

 

option,

 

the

 

manage

 

certificate

 

hashes

 

menu

 

displays.

 

This

 

option

 

will

 

enable

 

you

 

to

 

enumerate

 

the

 

hashes

 

in

 

the

 

system,

 

and

 

display

 

the

 

Hash

 

Name,

 

the

 

active

 

and

 

default

 

state.

 

The

 

manage

 

certificate

 

hashes

 

screen

 

has

 

several

 

keyboard

 

controls

 

available

 

to

 

the

 

user

 

to

 

manage

 

the

 

hashes

 

on

 

the

 

system.

 

These

 

keys

 

are

 

valid

 

in

 

the

 

Manage

 

Certificate

 

Hashes

 

menu

 

and

 

listed

 

below:

 

-

   

[ESC]

 

 

To

 

exit

 

from

 

the

 

menu

 

-

   

[INS]

 

 

To

 

add

 

a

 

customized

 

certificate

 

hash

 

to

 

the

 

system.

 

Press

 

[INS],

 

and

 

type

 

the

 

hash

 

name.

 

The

 

hash

 

name

 

must

 

be

 

a

 

maximum

 

of

 

32

 

characters.

 

The

 

Certificate

 

hash

 

value

 

is

 

a

 

20

 

byte

 

hexadecimal

 

number.

 

The

 

user

 

must

 

enter

 

the

 

hash

 

data

 

in

 

the

 

correct

 

format.

 

Otherwise,

 

the

 

message

 

prompts,

 

indicating

 

Invalid

 

Hash

 

Certificate

 

Entered

 

-

 

Try

 

Again

 

Upon

 

pressing

 

Enter

 

the

 

user

 

is

 

asked

 

about

 

setting

 

the

 

active

 

state

 

of

 

the

 

hash.

 

This

 

query

 

allows

 

for

 

setting

 

the

 

active

 

state

 

of

 

the

 

customized

 

hash.

 

v

   

Yes

 

 

The

 

customized

 

hash

 

will

 

be

 

marked

 

as

 

active.

 

v

   

No

 

(Default)

 

 

VA_Hash

 

will

 

be

 

maintained

 

within

 

EPS

-

   

[DEL]

 

 

To

 

delete

 

the

 

currently

 

selected

 

certificate

 

hash

 

from

 

system.

 

Press

 

[DEL]

 

v

   

Yes

 

 

MEBx

 

will

 

send

 

the

 

message

 

to

 

FW

 

to

 

delete

 

the

 

selected

 

hash.

 

v

   

No

 

 

MEBx

 

will

 

not

 

delete

 

the

 

selected

 

hash

 

and

 

will

 

return

 

to

 

the

 

remote

 

configuration.

-

   

[+]

 

To

 

change

 

the

 

active

 

state

 

of

 

the

 

currently

 

selected

 

certificate

 

hash.

 

Press

 

+

 

in

 

the

 

Manage

 

Certificate

 

Hash

 

screen,

 

and

 

Yes

 

will

 

toggle

 

the

 

active

 

 

Chapter

 

5.

 

Intel

 

AMT

 

setup

 

and

 

configuration

 

based

 

on

 

Lenovo

 

ThinkCentre

 

M58p

 

15

Summary of Contents for ThinkCentre M58p

Page 1: ......

Page 2: ......

Page 3: ...ThinkCentre M58p with Intel Active Management Technology ...

Page 4: ...First Edition October 2008 ...

Page 5: ...guration 10 Entering MEBx configuration user interface 10 Changing Intel ME password 10 Intel ME configuration 10 Intel AMT setup and configuration 13 Driver description 18 Chapter 6 Web user interface 19 Access the Web user interface 19 Provision the Intel AMT system 19 Logging onto the client system 19 Function in Web user interface 20 Appendix A Two examples of Intel AMT setup and configuration...

Page 6: ...iv ThinkCentre M58p with Intel AMT White Paper ...

Page 7: ...tel vPro and Intel AMT technology on page 1 This chapter provides a general introduction to the Intel vPro technology and Intel AMT technology Chapter 2 Lenovo ThinkCentre computer equipped with Intel AMT technology on page 3 This chapter describes the benefits of Intel vPro built in computers Chapter 3 ISV solution introduction on page 5 This chapter provides detailed information on the ISV solut...

Page 8: ...vi ThinkCentre M58p with Intel AMT White Paper ...

Page 9: ...are turned off or have an inoperable operating system as long as the system is connected to a power source and a network Acronyms Acronym Description AMT Active Management Technology ASF Alert Standard Format CIRA Client Initiated Remote Access DHCP Dynamic Host Configuration Protocol DNS Domain Name Server FQDN Fully Qualified Domain Name FW Firmware HECI Host Embedded Controller Interface ICH I ...

Page 10: ...TLS Transport Layer Security UI User Interface VLAN Virtual Local Area Network ZTC Zero Touch Configuration 2 ThinkCentre M58p with Intel AMT White Paper ...

Page 11: ...ven when computers are powered off v Restore The built in manageability of Intel AMT provides Out of Band OOB management capabilities to allow IT administrators to remotely recover systems even if the operating system is not operable Alerting and event logging help IT administrators detect problems quickly to reduce downtime v Protect The Intel AMT System Defense feature enables better inbound pro...

Page 12: ...g and recovery Significantly reduces desk side visits and increases the efficiency of IT technical staff Proactive alerting Decreases downtime and minimizes time to repair Remote Hardware asset tracking Increases speed and accuracy over manual inventory tracking and reduces asset accounting costs Third party nonvolatile storage Increases speed and accuracy over manual inventory tracking and reduce...

Page 13: ...features such as out of band access to asset information event logs hardware and software tables and embedded capabilities To ensure the usability and efficiency of our computers Lenovo as an OEM is planning to develop complete solutions with Intel and leading third party security and enterprise management software vendors Table 2 List of common third party management software ISV Application Micr...

Page 14: ...6 ThinkCentre M58p with Intel AMT White Paper ...

Page 15: ...er Cycle v Asset Management E Asset Tag OOB HW Inventory v Integrated Device Electronics Redirection IDE R Floppy Redirection CD Redirection v Serial Over LAN SOL Screen Redirection Based on Text Keyboard Redirection Network Redirection v Remote Reboot Reboot from local HD Reboot from local CD DVD v Event Management Event Alerting Event Logging Audit Log v Agent Presence v System Defense v Client ...

Page 16: ...8 ThinkCentre M58p with Intel AMT White Paper ...

Page 17: ...x crashes in the process of the configuration the changes that have been made will not be saved Note To use the CIRA technology you need not do any additional setup and configuration in MEBx You only need to configure your computer in MEBx for SMB or Enterprise mode then use the CIRA through ISV applications Associated Intel AMT setup and configuration in BIOS Press and hold the F1 key during POST...

Page 18: ...criteria defined below v Have 8 32 characters in length v Contain at least one alphabetic character one numeric character and one symbol v Have at least one seven bit ASCII non alphanumeric character v Contain one upper case letter and one lower case letter v You can also use the space bar and underscore _ Intel ME configuration Select Intel ME Configuration A window displays indicating that the s...

Page 19: ...are Local Update Qualifier which enables or disables firmware local update in the field The default value is Always Open Always Open Intel Management Engine FW local update channel is always enabled Boot cycle will not change enabled to disabled Intel Management Engine FW Local Update option can be ignored Never Intel Management Engine FW local update is controlled by Intel ME FW Local Update Opti...

Page 20: ... thermal performance of the system in both steady state and transient power conditions Select Intel Quiet System Technology You are able to set the state of Intel QST feature to Enabled or Disabled Enabled Intel Quiet System Technology is enabled Disabled Intel Quiet System Technology is disabled Return to Previous Menu Enables you to return to the previous menu Intel ME Power Control Intel ME Pow...

Page 21: ...be the same with the operating system machine name TCP IP Select TCP IP you will see the following TCP IP configuration menu of Intel AMT It allows you to change the TCP IP configuration There are two options of DHCP DHCP Enabled TCP IP settings will be configured by a DHCP server DHCP Disabled It is required to set up the static TCP IP settings for Intel AMT If the system is in static mode a seco...

Page 22: ...iguration process was not host initiated Yes indicates the setup and configuration process was host initiated PKI only Hash Data Display the 40 character certificate hash data PKI only Hash Algorithm Describe the hash type Currently only SHA1 is supported PKI only IsDefault Bit Display Yes if the Hash algorithm is the default algorithm selected Displays No if the hash algorithm is not the default ...

Page 23: ...s Select Manage Certificate Hashes option the manage certificate hashes menu displays This option will enable you to enumerate the hashes in the system and display the Hash Name the active and default state The manage certificate hashes screen has several keyboard controls available to the user to manage the hashes on the system These keys are valid in the Manage Certificate Hashes menu and listed...

Page 24: ...et all Intel AMT settings to their default values including the PID PPS and user entered Hash certificate But the MEBx password will remain untouched v MEBx Reset This option will clear all MEBx parameters to their default values including the PID PPS the MEBx password and user entered Hash certificate Also if USB key and remote configuration data are not their default parameters this option will ...

Page 25: ...nterface only during the setup and configuration process Once the setup and configuration process is completed you can no longer modify the MEBx password v Anytime You can change the MEBx password through the network interface at anytime Secure Firmware Update Select Secure Firmware Update in the Intel AMT configuration menu This option will allow the user to enable or disable secure firmware upda...

Page 26: ...mware can initiate transactions In addition transactions can be completed asynchronously by the Intel AMT ME and then synchronized later LMS Local Manageability Service LMS is a service that runs locally in the user space in the host operating system LMS exposes AMT functionality through standard interfaces for example general info interface firmware update interface local agent presence interface...

Page 27: ...t a host name for example LenovoM58p 5 In the Intel AMT Configuration menu select TCP IP You will be prompted to choose Disable DHCP Y N If there is a DHCP server on the network you can press N or press Y to set a static IP for your AMT machine When DHCP is enabled you need to input the domain name as well If DHCP is disabled input IP address for example 192 168 1 13 Subnet mask and Default Gatewa...

Page 28: ... OK You will go to the client Web user interface Function in Web user interface The Web server built into each Intel AMT system enables you to v View the system status v View the hardware information of AMT computer including system processor memory and disk v View start stop and clear the event log 20 ThinkCentre M58p with Intel AMT White Paper ...

Page 29: ...power off and on reset normal boot boot from local CD DVD drive and boot from local hard drive v View and manage Intel AMT power policies v View and manage Intel AMT network settings v View and manage Intel AMT user accounts Chapter 6 Web user interface 21 ...

Page 30: ...22 ThinkCentre M58p with Intel AMT White Paper ...

Page 31: ... TCP IP N Y c Select Provision Model Small Business d Make sure the setting is SOL IDE R Y e Username Password Enabled f Serial Over LAN Enabled g IDE Redirection Enabled 6 Generally use default values for Intel R ME configuration Password Policy Secure Firmware Update Set PRTC and Idle Timeout See Appendix B Default configuration values for Intel MEBx on page 25 for the detailed information 7 Sel...

Page 32: ...r Current Provisioning Mode Provisioning Record Provisioning Server and TLS PSK 2 Select TLS PKI Remote Configuration Enable Disable Enabled 3 Select Manage Certificate Hashes and press the Insert key 4 Enter your certificate hashes in the prompt message box 5 Use default values for Set FQDN and Set PKI DNS Suffix d Make sure the setting is SOL IDE R Y e Username Password Enabled f Serial Over LAN...

Page 33: ...ashes VeriSign Class 3 Primary CA G1 Manageability Feature Selection Intel R AMT VeriSign Class 3 Primary CA G3 Intel R Quiet System Technology Enabled Go Daddy Class 2 CA Intel R ME ON in Host Sleep States Desktop ON in S0 ME Wake in S3 Comodo AAA CA Host Name Blank Starfield Class 2 CA DHCP Enabled Set FQDN Blank Domain Name Blank Set PKI DNS Suffix Blank Provision Model Enterprise Unprovision F...

Page 34: ...26 ThinkCentre M58p with Intel AMT White Paper ...

Page 35: ...ied warranties in certain transactions therefore this statement may not apply to you This information could include technical inaccuracies or typographical errors Changes are periodically made to the information herein these changes will be incorporated in new editions of the publication Lenovo may make improvements and or changes in the product s and or the program s described in this publication...

Page 36: ...lts may vary Users of this document should verify the applicable data for their specific environment Trademarks The following terms are trademarks of Lenovo in the United States other countries or both Lenovo the Lenovo logo ThinkCentre Microsoft Windows and Windows Vista are trademarks or registered trademarks of Microsoft Corporation in the United States other countries or both Intel and vPro ar...

Page 37: ......

Page 38: ...Part Number 53Y5286 Printed in USA 1P P N 53Y5286 ...

Reviews: