Presentation Session Demo - HPE ProLiant Compute

Live demo Environment – HPE Value added management tools

Live demonstration environment – Purpose

The Purpose

The purpose of this demonstration environment is to show off our management tools.

During the demonstration, you will connect to HPE GreenLake and HPE Compute Ops Management. You will access numersous iLO BMCs. We are also building a Thales Cypher Trust Manager server enabled environment. More on that to follow.

By connecting to https://hpelabs.github.io/DemoPodV1.0/ you will have the latest copy of this guide.

Get Connected

You will connect to a Omnissa Horizon environment. With your browser (Chrome recommended) connect to the following URLs based on your present location:

With:

  • Username: Sent to you by email
  • Password: You set after initial login

Procedure:

  1. After clicking one of the links above, you will be presented with the “Your connection isn’t private” prompt, click on Advanced.

  2. Click on the link to Continue to your IP address. This is not an “unsafe” thing to do in this case.

  3. At the Horizon client selection screen, choose on the right side of the login box, Omnissa Horizon Web Client.

  4. At the Horizon Login screen, enter the username sent to you in email and the password you initially set and click on Login.

  5. When successfully logged in you are presented with a clickable link that launches your demo station. This is where you will work. Make sure you stay within the VPN connection when using a browser. If you connect to a site via your own browser, you will not have a network connection to the lab. You must stay within the Horizon terminal. Click on the Demo Envir… link.

  6. We are now going to launch some of the demo environment. First, log in to GreenLake from your the demo desktop. Click on Chrome in your System Tray.

  7. When Chrome loads, you may have to initially set it up.

  8. Please log out of the Horizon environment when you are done. To do this, click the three vertical bars on the left side of your VPN connection and navigate to Log Out. You can see the three vertical bars in the graphic below.

  9. You are looking for the section to Log out. Click on the link to successfully log out.

This Ends this Section.

↑ Back to Top

Starting State

Our first demonstration will be first connecting to HPE GreenLake and then launching HPE Compute Ops Management.

This Ends this Section.

↑ Back to Top

Thales Cipher Trust Manager (CTM) state before adding devices.

  1. Login into Thales Cipher Trust Manager at 192.168.115.10Admin/HPent!123.

  2. Click on Access Management.

  3. Click on Users – Show that only two users currently exist. We previously created the user called “iLO7-user”.

  4. Click on Keys – This key was created prior to the demonstration and is named “iLO7-key-master”.

  5. Click on the key itself to reveal the ID Field. This is what is needed by the iLO7 to connect to Thales.

  6. Copy the ID Field into the clipboard.
  7. Optional – In Access Management, click on Groups and explain that the iLO7-user is in the group. You must search for “iLO” to find the group.

This Ends this Section.

↑ Back to Top

HPE ProLiant Security Demo – Demonstration

Current state of iLO7 before adding it to the Thales CTM key manager

We will start by showing the participants the state of iLO7 before adding it to the Thales CTM key manager for control.

  1. Login to iLO7 at 192.168.115.11Administrator/HPent!123.
  2. From the Dashboard go to Security.
  3. Go to Remote Key Manager card

  4. Notice that the Servers entry is Not Set.
  5. Hover over the Configuration card.
  6. Point out the Account Name – This is derived from the MAC address of the iLO7.
  7. Show the iLO7 MAC address – iLO Settings -> iLO7 Network Ports -> iLO7 Dedicated Network Port to show the information for the connection.
  8. Return to Security -> Remote Key Manager.

This Ends this Section.

↑ Back to Top

Show iLO7 encryption status of the various devices used in the Demo

  1. Login to iLO7 at 192.168.115.11Administrator/HPent!123
  2. Go to Host -> Hardware -> Storage -> Storage Controllers and note that we have two controllers. The Encryption Mode for both is Disabled.

  3. Click on the HPE NS204i controller
  4. Click on the Logical Volume
  5. Click on one of the 960GB physical drives. Point out the Encryption Ability and Status and that moving from Unencrypted to Encrypted needs to be done before data is written to the drives for use. This is especially important for boot devices like the NS204i.

  6. Return to the Storage Controllers view and drill down on the HPE MR416i-p.
  7. In the Details card click View More. Point out Encryption Mode as currently Disabled

This Ends this Section.

↑ Back to Top

Configure iLO7 to use Thales CTM

We will now connect our iLO7 to the Thales CTM. Follow the steps to enable this capability.

For the initial creation of this account, iLO7 uses a deployment user account that pre-exists on the key manager with administrator privileges. For more information about the deployment user account, see the key manager documentation in the HPE Compute Security Reference Guide

  1. Login to iLO7 at 192.168.115.11Administrator/HPent!123
  2. From the Dashboard go to Security
  3. Go to Remote Key Manager card

  4. Click in the Edit Servers Pencil icon.
  5. Input 192.168.115.10 for Thales Server.
  6. Use port 9000 as Primary Key Server Port.
  7. Click Update to continue

  8. Now click the Pencil icon to edit the Configuration card.
  9. Enter the following values:

    • Account Group: ilo-group
    • Key Manager Local CA Certificate Name: The value is currently being held in the clipboard (Key ID Field)
    • Login Name: Admin
    • Password: HPent!123

    Note: you cannot change the Account Name (the MAC address derived value)

  10. Click Update.

  11. Click on the Test Connection link.
  12. Now, return to the Thales CTM.
  13. Click on Users – Show that now three users currently exist. You should see the newly created user called “iLO” with the MAC address appended to “iLO”

  • The iLO7 is now set up to manage the key exchange between the key manager and the other devices in the computer. iLO7 uses a unique user account based on its MAC address to communicate with the key manager.

This Ends this Section.

↑ Back to Top

Configure the MR Controller to request a key from the External Key Manager

We are now going to start using our newly connected external key manager. Follow the steps to get an installed harddrive controller to request an encryption key from the Thales CTM.

  1. Login to iLO7 at 192.168.115.11Administrator/HPent!123
  2. Open the iLO7 Remote Console
  3. The server should be on the UEFI System Configuration menu. If not, reboot the server and get to the UEFI prompt by clicking on F9 at the appropriate time during the computer’s boot cycle.
  4. Click on System Configuration

  5. Click on Slot 6 HPE MR416i-p Gen11

  6. Click on Main Menu

  7. Move down the list and click Controller Management

  8. Move all the way to the bottom of the frame and click on Advanced Controller Management

  9. Click on Enable Drive Security

  10. Choose the External Key Manager (EKM), which is the choice we want, and then click OK. These buttons need to be clicked so that other options become available. By clicking the selection On and Off, additional configuration can occur.
  11. At the Success banner, you are notified the system needs to restart for the changes to take effect. Click OK to continue

  12. Restart the server. Short Cuts -> CTRL + ALT + DEL This can take some seconds, please be patient.
  13. Return to System Configuration by selecting F9 for System Utilities at boot time.
  14. After the server reboots, return to the Thales server to see the key that was issued.

This Ends this Section.

↑ Back to Top

Configure the SED Devices to Unlock Encryption via Postman

We will now configure the SED storage devices.

  1. Return to the demonstration environment.

  2. Open the Postman utility in your System Tray.

  3. In the My Workspace area, locate the Z-Disk_Encryption section. These are the numbered scripts that will be used to change the SED status of our Storage devices connected to our NS204i-u boot controller.

  4. Click on 1-Get Storage Status to get the status of the storage devices in question.

  5. By clicking on the step, you load the script and are ready to then click Send to send the command to the devices.

  6. After the command is received, the status of the command is returned. You are looking for 200 OK in the results area.

  7. We will now take the second step, 2-Local- PATCH Encryption Mode UseLocalKey. Click on the script to make it active and then click Send. This changes the encryption to use a local key. You must reboot for changes to take effect.

  8. Our next step, 3-SetEncryptionKey, sets the keys to be used. Select the step and again click Send to commit the changes. Look for 200 OK to know the steps worked.

  9. Now return to the iLO7 in the Gen12 system and reboot to the System Configuration utility.

  10. Take a tour of the ILO to show that Encryption is now enabled. First, note that the Storage controller is now set to UseLocalKey.

  11. Click on the controller and then when you “View More” of the information for the NS204i-u, the Logical Volume has the Encrypted value set to True.

  12. When you drill down on the logical volume, you see that for each device the Encryption Status is Unlocked.

  • At this point you have completed the demonstration.

This Ends this Section.

↑ Back to Top

Resetting the security demonstration environment

Hopefully throughout this document we stressed the “before” and “after” nature needed to effectively show this demonstration.

The way you delete the iLO7 from the Thales server is basically the reverse of the steps you took to add the Thales server to iLO7. Go to Security -> Remote Key Manager and then remove the entries we had you add.

  1. From the Dashboard go to Security.

  2. Go to Remote Key Manager card

  3. Edit the Servers card and remove the IP address and the Port information.

  4. Edit the Configuration card. Remove the information about the Thales solution.

  5. For the MR416i-p harddrive controller, you return to the System Configuration -> Click on the Controller -> Main Menu -> Controller Management -> Advanced Controller Management and then disable drive security. Basically, reversing the steps you took to enable security.

  6. Finally, for the 960GB SED devices connected to the NS204i-u controller, from your Postman console, run the final command z-Storage.ResetTo.Defaults, make sure you click Send. This time you should get a 202 Accepted message.

  • In all these cases, changes are not made until you reboot the server.

This Ends this Section.

↑ Back to Top

Summary of what was shown

You performed the following basic steps:

  1. You showed the environment before any of the encryption elements were implemented

  2. You connected the iLO7 to the Thales CTM

  3. You configured a MR416i-p to use an external key manager with a UEFI utility

  4. You configured an NS204i-p to a UseLocalKey configuration

  5. You unlocked SED enabled NVMe storage devices

  6. You restored the environment for the next user

This Ends this Section.

↑ Back to Top

Want more?

🔔 To learn more, see the HPE Compute Security Reference Guide


Continue your journey with HPE Compute Technical Enablement demonstrations of infrastructure, security, technologies, and solutions.