background image

Chapter

 

1.

 

Introduction

 

to

 

Intel

 

vPro

 

and

 

Intel

 

AMT

 

technology

 

The

 

Intel

 

vPro

 

technology

 

is

 

a

 

business

 

computer

 

platform

 

brand,

 

enabling

 

business

 

computers

 

with

 

enhanced

 

remote

 

management

 

capabilities.

 

For

 

computers

 

built

 

with

 

Intel

 

vPro

 

technology,

 

IT

 

administrators

 

can

 

use

 

a

 

third

 

party

 

software

 

to

 

remotely

 

collect

 

inventory

 

information,

 

diagnose

 

problems,

 

and

 

provide

 

various

 

services

 

regardless

 

of

 

the

 

system

 

power

 

state

 

or

 

operating

 

system

 

condition.

 

Administrators

 

can

 

also

 

isolate

 

and

 

protect

 

individual

 

computers

 

and

 

the

 

network

 

from

 

threats

 

quickly.

 

The

 

Intel

 

AMT

 

is

 

part

 

of

 

the

 

Intel

 

Management

 

Engine

 

(ME),

 

which

 

is

 

built

 

into

 

computers

 

with

 

Intel

 

vPro

 

technology.

 

It

 

is

 

designed

 

to

 

provide

 

remote

 

management

 

even

 

to

 

computers

 

that

 

are

 

turned

 

off

 

or

 

have

 

an

 

inoperable

 

operating

 

system

 

as

 

long

 

as

 

the

 

system

 

is

 

connected

 

to

 

a

 

power

 

source

 

and

 

a

 

network.

 

Acronyms

 

 

Acronym

 

Description

 

AMT

 

Active

 

Management

 

Technology

 

ASF

 

Alert

 

Standard

 

Format

 

CIRA

 

Client

 

Initiated

 

Remote

 

Access

 

DHCP

 

Dynamic

 

Host

 

Configuration

 

Protocol

 

DNS

 

Domain

 

Name

 

Server

 

FQDN

 

Fully

 

Qualified

 

Domain

 

Name

 

FW

 

Firmware

 

HECI

 

Host

 

Embedded

 

Controller

 

Interface

 

ICH

 

I/O

 

Controller

 

Hub

 

IDE-R

 

Integrated

 

Device

 

Electronics

 

Redirection

 

ISV

 

Independent

 

Software

 

Vendor

 

LMS

 

Local

 

Manageability

 

Service

 

ME

 

Management

 

Engine

 

MEBx

 

Management

 

Engine

 

BIOS

 

Extension

 

MEI

 

Management

 

Engine

 

Interface

 

NAT

 

Network

 

Address

 

Translation

 

NVM

 

Non-volatile

 

Memory

 

OEM

 

Original

 

Equipment

 

Manufacturer

 

PID/PPS

 

Provisioning

 

ID

 

and

 

Provisioning

 

Pre-shared

 

Key

 

PKI

 

Public

 

Key

 

Infrastructure

 

PRTC

 

Protected

 

Real

 

Time

 

Clock

 

PSK

 

Pre-shared

 

Key

 

SMB

 

Small

 

and

 

Medium

 

Businesses

 

SOL

 

Serial-Over-LAN

 

TCP

 

Transmission

 

Control

 

Protocol

 

 

  

1

Summary of Contents for ThinkCentre M58p

Page 1: ......

Page 2: ......

Page 3: ...ThinkCentre M58p with Intel Active Management Technology ...

Page 4: ...First Edition October 2008 ...

Page 5: ...guration 10 Entering MEBx configuration user interface 10 Changing Intel ME password 10 Intel ME configuration 10 Intel AMT setup and configuration 13 Driver description 18 Chapter 6 Web user interface 19 Access the Web user interface 19 Provision the Intel AMT system 19 Logging onto the client system 19 Function in Web user interface 20 Appendix A Two examples of Intel AMT setup and configuration...

Page 6: ...iv ThinkCentre M58p with Intel AMT White Paper ...

Page 7: ...tel vPro and Intel AMT technology on page 1 This chapter provides a general introduction to the Intel vPro technology and Intel AMT technology Chapter 2 Lenovo ThinkCentre computer equipped with Intel AMT technology on page 3 This chapter describes the benefits of Intel vPro built in computers Chapter 3 ISV solution introduction on page 5 This chapter provides detailed information on the ISV solut...

Page 8: ...vi ThinkCentre M58p with Intel AMT White Paper ...

Page 9: ...are turned off or have an inoperable operating system as long as the system is connected to a power source and a network Acronyms Acronym Description AMT Active Management Technology ASF Alert Standard Format CIRA Client Initiated Remote Access DHCP Dynamic Host Configuration Protocol DNS Domain Name Server FQDN Fully Qualified Domain Name FW Firmware HECI Host Embedded Controller Interface ICH I ...

Page 10: ...TLS Transport Layer Security UI User Interface VLAN Virtual Local Area Network ZTC Zero Touch Configuration 2 ThinkCentre M58p with Intel AMT White Paper ...

Page 11: ...ven when computers are powered off v Restore The built in manageability of Intel AMT provides Out of Band OOB management capabilities to allow IT administrators to remotely recover systems even if the operating system is not operable Alerting and event logging help IT administrators detect problems quickly to reduce downtime v Protect The Intel AMT System Defense feature enables better inbound pro...

Page 12: ...g and recovery Significantly reduces desk side visits and increases the efficiency of IT technical staff Proactive alerting Decreases downtime and minimizes time to repair Remote Hardware asset tracking Increases speed and accuracy over manual inventory tracking and reduces asset accounting costs Third party nonvolatile storage Increases speed and accuracy over manual inventory tracking and reduce...

Page 13: ...features such as out of band access to asset information event logs hardware and software tables and embedded capabilities To ensure the usability and efficiency of our computers Lenovo as an OEM is planning to develop complete solutions with Intel and leading third party security and enterprise management software vendors Table 2 List of common third party management software ISV Application Micr...

Page 14: ...6 ThinkCentre M58p with Intel AMT White Paper ...

Page 15: ...er Cycle v Asset Management E Asset Tag OOB HW Inventory v Integrated Device Electronics Redirection IDE R Floppy Redirection CD Redirection v Serial Over LAN SOL Screen Redirection Based on Text Keyboard Redirection Network Redirection v Remote Reboot Reboot from local HD Reboot from local CD DVD v Event Management Event Alerting Event Logging Audit Log v Agent Presence v System Defense v Client ...

Page 16: ...8 ThinkCentre M58p with Intel AMT White Paper ...

Page 17: ...x crashes in the process of the configuration the changes that have been made will not be saved Note To use the CIRA technology you need not do any additional setup and configuration in MEBx You only need to configure your computer in MEBx for SMB or Enterprise mode then use the CIRA through ISV applications Associated Intel AMT setup and configuration in BIOS Press and hold the F1 key during POST...

Page 18: ...criteria defined below v Have 8 32 characters in length v Contain at least one alphabetic character one numeric character and one symbol v Have at least one seven bit ASCII non alphanumeric character v Contain one upper case letter and one lower case letter v You can also use the space bar and underscore _ Intel ME configuration Select Intel ME Configuration A window displays indicating that the s...

Page 19: ...are Local Update Qualifier which enables or disables firmware local update in the field The default value is Always Open Always Open Intel Management Engine FW local update channel is always enabled Boot cycle will not change enabled to disabled Intel Management Engine FW Local Update option can be ignored Never Intel Management Engine FW local update is controlled by Intel ME FW Local Update Opti...

Page 20: ... thermal performance of the system in both steady state and transient power conditions Select Intel Quiet System Technology You are able to set the state of Intel QST feature to Enabled or Disabled Enabled Intel Quiet System Technology is enabled Disabled Intel Quiet System Technology is disabled Return to Previous Menu Enables you to return to the previous menu Intel ME Power Control Intel ME Pow...

Page 21: ...be the same with the operating system machine name TCP IP Select TCP IP you will see the following TCP IP configuration menu of Intel AMT It allows you to change the TCP IP configuration There are two options of DHCP DHCP Enabled TCP IP settings will be configured by a DHCP server DHCP Disabled It is required to set up the static TCP IP settings for Intel AMT If the system is in static mode a seco...

Page 22: ...iguration process was not host initiated Yes indicates the setup and configuration process was host initiated PKI only Hash Data Display the 40 character certificate hash data PKI only Hash Algorithm Describe the hash type Currently only SHA1 is supported PKI only IsDefault Bit Display Yes if the Hash algorithm is the default algorithm selected Displays No if the hash algorithm is not the default ...

Page 23: ...s Select Manage Certificate Hashes option the manage certificate hashes menu displays This option will enable you to enumerate the hashes in the system and display the Hash Name the active and default state The manage certificate hashes screen has several keyboard controls available to the user to manage the hashes on the system These keys are valid in the Manage Certificate Hashes menu and listed...

Page 24: ...et all Intel AMT settings to their default values including the PID PPS and user entered Hash certificate But the MEBx password will remain untouched v MEBx Reset This option will clear all MEBx parameters to their default values including the PID PPS the MEBx password and user entered Hash certificate Also if USB key and remote configuration data are not their default parameters this option will ...

Page 25: ...nterface only during the setup and configuration process Once the setup and configuration process is completed you can no longer modify the MEBx password v Anytime You can change the MEBx password through the network interface at anytime Secure Firmware Update Select Secure Firmware Update in the Intel AMT configuration menu This option will allow the user to enable or disable secure firmware upda...

Page 26: ...mware can initiate transactions In addition transactions can be completed asynchronously by the Intel AMT ME and then synchronized later LMS Local Manageability Service LMS is a service that runs locally in the user space in the host operating system LMS exposes AMT functionality through standard interfaces for example general info interface firmware update interface local agent presence interface...

Page 27: ...t a host name for example LenovoM58p 5 In the Intel AMT Configuration menu select TCP IP You will be prompted to choose Disable DHCP Y N If there is a DHCP server on the network you can press N or press Y to set a static IP for your AMT machine When DHCP is enabled you need to input the domain name as well If DHCP is disabled input IP address for example 192 168 1 13 Subnet mask and Default Gatewa...

Page 28: ... OK You will go to the client Web user interface Function in Web user interface The Web server built into each Intel AMT system enables you to v View the system status v View the hardware information of AMT computer including system processor memory and disk v View start stop and clear the event log 20 ThinkCentre M58p with Intel AMT White Paper ...

Page 29: ...power off and on reset normal boot boot from local CD DVD drive and boot from local hard drive v View and manage Intel AMT power policies v View and manage Intel AMT network settings v View and manage Intel AMT user accounts Chapter 6 Web user interface 21 ...

Page 30: ...22 ThinkCentre M58p with Intel AMT White Paper ...

Page 31: ... TCP IP N Y c Select Provision Model Small Business d Make sure the setting is SOL IDE R Y e Username Password Enabled f Serial Over LAN Enabled g IDE Redirection Enabled 6 Generally use default values for Intel R ME configuration Password Policy Secure Firmware Update Set PRTC and Idle Timeout See Appendix B Default configuration values for Intel MEBx on page 25 for the detailed information 7 Sel...

Page 32: ...r Current Provisioning Mode Provisioning Record Provisioning Server and TLS PSK 2 Select TLS PKI Remote Configuration Enable Disable Enabled 3 Select Manage Certificate Hashes and press the Insert key 4 Enter your certificate hashes in the prompt message box 5 Use default values for Set FQDN and Set PKI DNS Suffix d Make sure the setting is SOL IDE R Y e Username Password Enabled f Serial Over LAN...

Page 33: ...ashes VeriSign Class 3 Primary CA G1 Manageability Feature Selection Intel R AMT VeriSign Class 3 Primary CA G3 Intel R Quiet System Technology Enabled Go Daddy Class 2 CA Intel R ME ON in Host Sleep States Desktop ON in S0 ME Wake in S3 Comodo AAA CA Host Name Blank Starfield Class 2 CA DHCP Enabled Set FQDN Blank Domain Name Blank Set PKI DNS Suffix Blank Provision Model Enterprise Unprovision F...

Page 34: ...26 ThinkCentre M58p with Intel AMT White Paper ...

Page 35: ...ied warranties in certain transactions therefore this statement may not apply to you This information could include technical inaccuracies or typographical errors Changes are periodically made to the information herein these changes will be incorporated in new editions of the publication Lenovo may make improvements and or changes in the product s and or the program s described in this publication...

Page 36: ...lts may vary Users of this document should verify the applicable data for their specific environment Trademarks The following terms are trademarks of Lenovo in the United States other countries or both Lenovo the Lenovo logo ThinkCentre Microsoft Windows and Windows Vista are trademarks or registered trademarks of Microsoft Corporation in the United States other countries or both Intel and vPro ar...

Page 37: ......

Page 38: ...Part Number 53Y5286 Printed in USA 1P P N 53Y5286 ...

Reviews: