Dell™ Systems Management Administrator's Guide Notes, Notices, and Cautions Information in this document is subject to change without notice.
TLS PKI – Remote Configuration Settings The remote configuration options are contained under the TLS PKI sub menu. There are four remote configurat
The Manage Certificate Hash screen has several keyboard controls available to you to manage the hashes on the computer. The following keys are valid
Set PKI DNS Suffix When the Set PKI DNS Suffix option is selected under the Remote Configuration menu, you are prompted to enter the PKI DNS Suffix o
SOL/IDE-R l Username and Password – DISABLED** / ENABLED This option provides the user authentication for SOL/IDER session. If the Kerberos protoc
Set PRTC Enter PRTC in GMT (UTC) format (YYYY:MM:DD:HH:MM:SS). Valid date range is 1/1/2004 – 1/4/2021. Setting PRTC value is used for virtually mai
Intel AMT in DHCP Mode Settings Example The table below shows a basic field settings example for the Intel AMT Configuration menu page to configure t
Save and exit MEBx and then boot computer to the Microsoft®Windows®operating system. MEBx Default Settings The table below lists all the default
3 Un-provision setting only seen if the box is provisioned. Back to Contents Page
Back to Contents Page About Intel® Active Management Technology Dell™ Systems Management Administrator's Guide Intel® Active Management Technolo
Back to Contents Page Redirecting Serial and IDE Communications Dell™ Systems Management Administrator's Guide Intel® AMT makes it possible to r
Back to Contents Page Deployment Dell™ Systems Management Administrator's Guide Once you are ready to deploy a computer to a user, plug the comp
Back to Contents Page Intel® AMT Setup and Configuration Overview Dell™ Systems Management Administrator's Guide Terms Setup and Configuration
Back to Contents Page Provisioning: Completing the Setup and Configuration Process Dell™ Systems Management Administrator's Guide Using Remote
1. An IT technician inserts a USB drive key into a computer with a management console. 2. The technician requests local setup and configuration recor
3. Select AMT Quick Start from the left navigation menu to open the Altiris Console. 4. Click the plus (+) to expand the Intel AMT Getting Started
6. Click the plus (+) to expand the Basic Provisioning (without TLS) section. 7. Select Step 1. Configure DNS. The notification server with an out
8. Click Test on the DNS Configuration screen to verify that DNS has the ProvisionServer entry and that it resolves to the correct Intel setup and co
9. Select Step 2. Discovery Capabilities. 10. Verify that the setting is Enabled. If Disabled, click the checkbox next to Disabled and click Apply.
11. Select Step 3. View Intel AMT Capable Computers. Any Intel AMT capable computers on the network are visible in this list.
12. Select Step 4. Create Profile. 13. Click the plus (+) to add a new profile.
14. On the General tab the administrator can modify the profile name and description along with the password. The administrator sets a standard passw
Back to Contents Page Intel® Management Engine BIOS Extension (MEBx) Dell™ Systems Management Administrator's Guide Intel MEBx Overview Config
16. The TLS (Transport Layer Security) tab provides the ability to enable TLS. If enabled, several other pieces of information are required includin
19. Select Step 5. Generate Security Keys. 20. Select the icon with the arrow pointing out to Export Security Keys to USB Key.
21. Select the Generate keys before export radio button. 22. Enter the number of keys to generate (depends on the number of computers that need to
23. The Intel ME default password is admin. Configure the new Intel ME password for the environment. 24. Click Generate. Once the keys have been cr
25. Insert the previously formatted USB device into a USB connector on the ProvisioningServer. 26. Click the Download USB key file link to download s
27. Close the Export Security Keys to USB Key and drive explorer windows to return to the Altiris Console. 28. Take the USB device to the computer,
32. Select Step 6. Configure Automatic Profile Assignments. 33. Verify that the setting setting is enabled. In the Intel AMT 2.0+ dropdown, select
The computers for which the keys were applied begin to appearing in the system list. At first the status is Unprovisioned, then the system status cha
The computers for which profiles were assigned appear in the list. Each computer is identified by the FQDN, UUID, and Profile Name columns. Once the
Using MEBx Interface to Complete Provisioning Intel®AMT can be set up for either Enterprise or Small and Medium Business operational modes (also ca
l Eight characters l One uppercase letter l One lowercase letter l A number l A special (nonalphanumeric) character, such as !, $, or ; excluding
Intel AMT configuration must occur over a network. The network can be encrypted using the Transport Layer Security Pre-Shared Key (TLS-PSK) protocol.
3. Select Change Intel ME Password. Press <Enter>. Type the new password twice for verification. The new password must include the followin
5. The following message appears: System resets after configuration change. Continue (Y/N). Press <y>. 6. Intel ME State Control is the next
7. Select Intel ME Firmware Local Update Qualifier. Press <Enter>. 8. Select Always Open. Press <Enter>. The default setting for this op
10. Manageability Feature Selection is the next option. This feature sets the platform management mode. The default setting is Intel AMT. Selecting
12. Select Intel ME Power Control. Press <Enter>. 13. Intel ME ON in Host Sleep States is the next option. The default setting is Desktop:
14. Select Return to Previous Menu. Press <Enter>. 15. Select Return to Previous Menu. Press <Enter>.
16. Exit the MEBx Setup and save the ME configuration. The computer displays an Intel ME Configuration Complete message and then restarts. After the
5. Select TCP/IP. Press <Enter>. The following messages appear: l Disable Network Interface: (Y/N) Press <n>. If the network is disab
l Domain Name Type the domain name into the field. 6. Select Provision Model from the menu. Press <Enter>. The following message appears:
When enabled, the ME State Control option lets you disable ME to isolate the ME computer from the main platform while debugging a field malfunction.
7. Select Setup and Configuration from the menu. Press <Enter>. 8. Select Current Provisioning Mode to display the current mode. Press <En
9. Select Provisioning Record. The provisioning record displays the provision PSK/PKI record data of the computer. If the data has not been entered,
12. Type the port in the Port number field and press <Enter>. The default setting is 0. If left at the default setting of 0, the Intel AMT atte
14. Set PID and PPS is the next option. The PID and PPS can be input manually or by using a USB key once the SCS generates the codes. This option is
17. Select TLS PKI from the menu. Press <Enter>. 18. Select Remote Configuration Enable/Disable from the menu. Press <Enter>. This opti
19. Manage Certificate Hashes option is the next option. Four hashes are configured by default. Hashes can be deleted or added per customer needs.
21. Select Set PKI DNS Suffix from the menu. Press <Enter>. Type the PKI DNS Suffix in the text field and press <Enter>. 22. Select Ret
23. Select Return to Previous Menu. Press <Enter>. This returns you to the Intel AMT Configuration menu. 24. Skip the Un-Provision option. Thi
27. The following messages appear, and require the response indicated in the following bulleted list: l [Caution] System resets after configuration
l Serial Over LAN Select Enabled and then press <Enter>. l IDE Redirection Select Enabled and then press <Enter>.
Always Open qualifies the override counter and allows local ME firmware updates. The override counter is a value set in the factory that, by default,
28. Secure Firmware Update is the next option. The default setting is Enabled. 29. Skip Set PRTC.
30. Idle Timeout is the next option. The default setting is 1. This timeout is applicable only when a WoL option is selected in step 13 of the proces
32. Select Exit. Press <Enter>. 33. The following message appears: Are you sure you want to exit? (Y/N): Press <y>.
34. The computer restarts. Turn off the computer and disconnect the power cable. The computer is now in setup state and is ready for deployment. SM
3. Select Change Intel ME Password. Press <Enter>. Type the new password twice for verification. The new password must include the followin
5. The following message appears: System resets after configuration change. Continue (Y/N). Press <y>. 6. Intel ME State Control is the next
7. Select Intel ME Firmware Local Update Qualifier.Press<Enter>. 8. Select Always Open. Press <Enter>. The default setting for this o
10. Manageability Feature Selection is the next option. This feature sets the platform management mode. The default setting is Intel AMT. Selecting
12. Select Intel ME Power Control. Press <Enter>. 13. Intel ME ON in Host Sleep States is the next option. The default setting is Desktop:
14. Select Return to Previous Menu. Press <Enter>. 15. Select Return to Previous Menu. Press <Enter>.
The power package selected determines when the ME is turned ON. The default power package turns off the ME in all Sx (S3/S4/S5) states. The end user
16. Exit the MEBx Setup and save the ME configuration. The computer displays an Intel ME Configuration Complete message and then restarts. After the
6. Select TCP/IP. Press <Enter>. 7. The following messages appear and require the response indicated in the following bulleted list: l Dis
l Domain Name Type the domain name into the field. 8. Select Provision Model from the menu. Press <Enter>. 9. The following message appear
10. Skip the Un-Provision option. This option returns the computer to factory defaults. See Return to Default for more information about unprovisioni
14. The following messages appear and require the response indicated in the following bulleted list: l [Caution] System resets after configuration c
l Serial Over LAN Select Enabled and then press <Enter>. l IDE Redirection Select Enabled and then press <Enter>.
15. Secure Firmware Update is the next option. The default setting is Enabled. 16. Skip Set PRTC.
17. Idle Timeout is the next option. The default setting is 1. This timeout is applicable only when a WoL option is selected in step 13 of the proces
19. Select Exit. Press <Enter>. 20. The following message appears: Are you sure you want to exit? (Y/N): Press <y>.
21. The computer restarts. Turn off the computer and disconnect the power cable. The computer is now in setup state and is ready for deployment. Bac
The Intel AMT Configuration page contains the user-configurable options listed below. For images of these menu options, see Enterprise Mode and SMB M
Back to Contents Page Troubleshooting Dell™ Systems Management Administrator's Guide Return to Default (Un-Provisioning) Firmware Flash Seria
5. Select Un-Provision. 6. Press <Enter>. 7. Select Full Unprovision. 8. Press <Enter>. 9. Reconfigure the settings on the Intel AMT C
Back to Contents Page Using the Intel® AMT WebGUI Dell™ Systems Management Administrator's Guide The Intel® AMT WebGUI is a Web browser-based in
The menu contains the parameters for the setup and configuration server. This menu also contains the security settings for PSK and PKI configurations.
Komentáře k této Příručce