1
The Intel AMT computer is connected to the network and plugged-in for the
first time.
2
The Intel AMT device opens its network interface for 24 hours, and starts
sending Hello messages.
Note:
The interface is open for 24 hours only the first time that it is enabled.
If the time runs out before the setup and configuration completes or the Intel
AMT device is unconfigured or partially unconfigured, any subsequent calls
to start configuration will open the interface for only six hours.
See
“About resending Hello messages”
on page 89.
3
Intel SCS on the configuration server extracts the hashes from the Hello
message.
4
Intel SCS sends a certificate chain that includes a trusted root certificate
matching one of the received hashes.
5
The Intel AMT device validates the Intel SCS certificate. Intel AMT checks
that the OID or the OU is correct and that it is derived from a certification
authority that matches one of the root certificate hashes.
6
The Intel AMT device verifies that the suffix matches the DNS suffix in the
Intel SCS certificate.
7
Intel SCS and the Intel AMT device perform a complete mutual authentication
session key exchange:
■
The Intel AMT device uses a self-signed certificate and sends its public
key.
■
Intel SCS creates a TLS session master key, encrypts it with the Intel AMT
device public key, and sends it to the Intel AMT device.
■
The device decrypts the master key with its private key. The key is the
shared secret used to establish the setup and configuration TLS session.
8
One-Time Password (OTP) verification: Intel SCS requests the OTP from the
Intel AMT device. The device sends the OTP securely. The SCS verifies the
OTP for correctness.
9
Intel SCS changes the Intel AMT password from its default and completes
the setup and configuration process.
See
“Initializing Intel AMT computers using the Remote Configuration feature”
on page 65.
Configuring Intel AMT computers for out-of-band management
Configuring Intel AMT computers for out-of-band management
68
Содержание ALTIRIS OUT OF BAND MANAGEMENT COMPONENT 7.0 SP3 - V1.0
Страница 1: ...Altiris Out of Band Management Component from Symantec Implementation Guide Version 7 0 SP3 MR1 ...
Страница 6: ......
Страница 30: ...Introducing Out of Band Management Component Where to get more information 30 ...
Страница 48: ...Installing Out of Band Management Component Uninstalling Out of Band Management Component 48 ...
Страница 110: ...Configuring TLS Configuring TLS with mutual authentication 110 ...
Страница 176: ...Troubleshooting Out of Band Management Component Troubleshooting OOB site server installation 176 ...