<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remote console, SSL certificates, and port 80 in ProLiant Servers (ML,DL,SL)</title>
    <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/remote-console-ssl-certificates-and-port-80/m-p/6774484#M150231</link>
    <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully there’s somebody out there than can help with this issue.&lt;/P&gt;&lt;P&gt;I have a StoreEasy 1450 with ILO4 out on a customer site. The customer has configured a port forward from 4433 to 443 so I can get access to the ILO interface.&lt;/P&gt;&lt;P&gt;I can log in to ILO but when I try and launch the remote console nothing happens.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After a bit of Googling I believe it may be trying to redirect through port 80 due to an untrusted certificate.&lt;/P&gt;&lt;P&gt;&lt;A href="http://h20565.www2.hpe.com/hpsc/doc/public/display?sp4ts.oid=5195931&amp;amp;docId=mmr_kc-0106591&amp;amp;lang=en-us&amp;amp;cc=us&amp;amp;docLocale=en_US" target="_blank"&gt;http://h20565.www2.hpe.com/hpsc/doc/public/display?sp4ts.oid=5195931&amp;amp;docId=mmr_kc-0106591&amp;amp;lang=en-us&amp;amp;cc=us&amp;amp;docLocale=en_US&lt;/A&gt;&lt;/P&gt;&lt;P&gt;However the above article states that Java RC would work, but for me it does not.&lt;/P&gt;&lt;P&gt;The site is added to trusted sites in IE, and I have tried with protected mode off.&lt;/P&gt;&lt;P&gt;IE, Chrome and Firefox all the same, nothing happens and no clue why.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I have installed a Digicert certificate which is trusted by the browser, but maybe not by the web server in ILO, not 100% sure about that.&lt;/P&gt;&lt;P&gt;Still no joy.&lt;/P&gt;&lt;P&gt;Ports 443 and 80 are in use so there is no option to use them.&lt;/P&gt;&lt;P&gt;I’m pretty sure it’s not a client side issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ILO Firmware is 2.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The digicert SSL certificate was sent with a certificate for an intermediate trusted CA, but it looks like only one SSL certificate can be installed in ILO.&lt;/P&gt;&lt;P&gt;I believe this must be a very common usage scenario given most small businesses only have one public IP address, and would be hosting a website on port 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any succinct thoughts and suggestions gratefully received.&lt;/P&gt;</description>
    <pubDate>Thu, 13 Aug 2015 05:46:56 GMT</pubDate>
    <dc:creator>Richardw-au</dc:creator>
    <dc:date>2015-08-13T05:46:56Z</dc:date>
    <item>
      <title>Remote console, SSL certificates, and port 80</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/remote-console-ssl-certificates-and-port-80/m-p/6774484#M150231</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully there’s somebody out there than can help with this issue.&lt;/P&gt;&lt;P&gt;I have a StoreEasy 1450 with ILO4 out on a customer site. The customer has configured a port forward from 4433 to 443 so I can get access to the ILO interface.&lt;/P&gt;&lt;P&gt;I can log in to ILO but when I try and launch the remote console nothing happens.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After a bit of Googling I believe it may be trying to redirect through port 80 due to an untrusted certificate.&lt;/P&gt;&lt;P&gt;&lt;A href="http://h20565.www2.hpe.com/hpsc/doc/public/display?sp4ts.oid=5195931&amp;amp;docId=mmr_kc-0106591&amp;amp;lang=en-us&amp;amp;cc=us&amp;amp;docLocale=en_US" target="_blank"&gt;http://h20565.www2.hpe.com/hpsc/doc/public/display?sp4ts.oid=5195931&amp;amp;docId=mmr_kc-0106591&amp;amp;lang=en-us&amp;amp;cc=us&amp;amp;docLocale=en_US&lt;/A&gt;&lt;/P&gt;&lt;P&gt;However the above article states that Java RC would work, but for me it does not.&lt;/P&gt;&lt;P&gt;The site is added to trusted sites in IE, and I have tried with protected mode off.&lt;/P&gt;&lt;P&gt;IE, Chrome and Firefox all the same, nothing happens and no clue why.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I have installed a Digicert certificate which is trusted by the browser, but maybe not by the web server in ILO, not 100% sure about that.&lt;/P&gt;&lt;P&gt;Still no joy.&lt;/P&gt;&lt;P&gt;Ports 443 and 80 are in use so there is no option to use them.&lt;/P&gt;&lt;P&gt;I’m pretty sure it’s not a client side issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ILO Firmware is 2.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The digicert SSL certificate was sent with a certificate for an intermediate trusted CA, but it looks like only one SSL certificate can be installed in ILO.&lt;/P&gt;&lt;P&gt;I believe this must be a very common usage scenario given most small businesses only have one public IP address, and would be hosting a website on port 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any succinct thoughts and suggestions gratefully received.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2015 05:46:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/remote-console-ssl-certificates-and-port-80/m-p/6774484#M150231</guid>
      <dc:creator>Richardw-au</dc:creator>
      <dc:date>2015-08-13T05:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: Remote console, SSL certificates, and port 80</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/remote-console-ssl-certificates-and-port-80/m-p/6774553#M150235</link>
      <description>&lt;P&gt;The document you mention could be part of an issue you're seeing. As a test, you could download the stand alone IRC application that doesn't require it to be downloaded from the iLO.&amp;nbsp; Is there also a port forward setup for 17990?&amp;nbsp;iLO uses port 17990 for remote console.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HP Lights-Out Stand Alone Remote Console for Windows&lt;/P&gt;&lt;P&gt;&lt;A href="http://h20566.www2.hpe.com/hpsc/swd/public/detail?sp4ts.oid=5264039&amp;amp;swItemId=MTX_4f842ceb31cf48d392e22705a8&amp;amp;swEnvOid=4060#tab-history" target="_blank"&gt;http://h20566.www2.hpe.com/hpsc/swd/public/detail?sp4ts.oid=5264039&amp;amp;swItemId=MTX_4f842ceb31cf48d392e22705a8&amp;amp;swEnvOid=4060#tab-history&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've seen others recommend as a best practice to use a VPN to access the remote network instead of poking a bunch of&amp;nbsp;holes in a firewall/router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Default iLO port values&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Secure Shell (SSH) Port - 22&lt;BR /&gt;Remote Console Port - 17990&lt;BR /&gt;Web Server Non-SSL Port (HTTP) - 80&lt;BR /&gt;Web Server SSL Port (HTTPS) - 443&lt;BR /&gt;Virtual Media Port - 17988&lt;BR /&gt;SNMP Port - 161&lt;BR /&gt;SNMP Trap Port - 162&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2015 09:49:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/remote-console-ssl-certificates-and-port-80/m-p/6774553#M150235</guid>
      <dc:creator>Jimmy Vance</dc:creator>
      <dc:date>2015-08-13T09:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: Remote console, SSL certificates, and port 80</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/remote-console-ssl-certificates-and-port-80/m-p/6775806#M150289</link>
      <description>&lt;P&gt;Hi Jimmy&lt;/P&gt;&lt;P&gt;Thanks for your suggestion.&lt;/P&gt;&lt;P&gt;i now have a port forward on the external IP on port 17990 to the ILO NIC. But the remote console still doesnt launch, nor does the standalone remote console connect.&lt;/P&gt;&lt;P&gt;i can telnet&amp;nbsp;to port 17990.&lt;/P&gt;&lt;P&gt;From standalone remote console i get this :&lt;/P&gt;&lt;P&gt;Received an unexpected EOF or 0 bytes from the transport stream&lt;/P&gt;&lt;P&gt;Any ideas what that means?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 01:14:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/remote-console-ssl-certificates-and-port-80/m-p/6775806#M150289</guid>
      <dc:creator>Richardw-au</dc:creator>
      <dc:date>2015-08-18T01:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: Remote console, SSL certificates, and port 80</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/remote-console-ssl-certificates-and-port-80/m-p/6776488#M150392</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/1637212"&gt;@Richardw-au&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;Hi Jimmy&lt;/P&gt;&lt;P&gt;Thanks for your suggestion.&lt;/P&gt;&lt;P&gt;i now have a port forward on the external IP on port 17990 to the ILO NIC. But the remote console still doesnt launch, nor does the standalone remote console connect.&lt;/P&gt;&lt;P&gt;i can telnet&amp;nbsp;to port 17990.&lt;/P&gt;&lt;P&gt;From standalone remote console i get this :&lt;/P&gt;&lt;P&gt;Received an unexpected EOF or 0 bytes from the transport stream&lt;/P&gt;&lt;P&gt;Any ideas what that means?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Using the standalone client I was able to access the iLO remote console.&amp;nbsp; Besides 17990 you also need to have a port forward for port 443&lt;/P&gt;&lt;P&gt;if the customer is using 443 for a webserver, you can use another port and redirect to 443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the firewall (linux iptables) I was testing with&amp;nbsp; I had&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;external&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; internal&lt;/P&gt;&lt;P&gt;17990&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;17990&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 4003&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;using the standalone client you can put everything on the command line, or in the GUI box for Netwrok addres use hostname:port&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from the command line it is&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;irc.exe -addr address:[https_port] -name login_name -password password&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;irc.exe -help will list the options&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2015 15:47:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/remote-console-ssl-certificates-and-port-80/m-p/6776488#M150392</guid>
      <dc:creator>Jimmy Vance</dc:creator>
      <dc:date>2015-08-19T15:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: Remote console, SSL certificates, and port 80</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/remote-console-ssl-certificates-and-port-80/m-p/6782788#M150989</link>
      <description>&lt;P&gt;Hi Jimmy&lt;/P&gt;&lt;P&gt;Apologies for the delay - i've been dealing with HP support on this also, and that has been a painful experience!&lt;/P&gt;&lt;P&gt;Initially i tried specifying port 17990 on the standalone remote client, and it didnt connect.&lt;/P&gt;&lt;P&gt;The one thing of value&amp;nbsp;i got from hours of sessions with HP support was that i needed to enable IRC requires a trusted certificate in iLO&amp;nbsp;setting on the Remote Console page security tab.&lt;/P&gt;&lt;P&gt;I then retried the Standalone RC using the redirected SSL port and after a really long wait, about 3 minutes, i saw the remote console!&lt;/P&gt;&lt;P&gt;Hope this is of assistance to somebody, and thanks to you for the suggestions.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2015 05:03:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/remote-console-ssl-certificates-and-port-80/m-p/6782788#M150989</guid>
      <dc:creator>Richardw-au</dc:creator>
      <dc:date>2015-09-09T05:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: Remote console, SSL certificates, and port 80</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/remote-console-ssl-certificates-and-port-80/m-p/7028460#M164965</link>
      <description>&lt;P&gt;It didn't work for me.&lt;/P&gt;&lt;P&gt;HP should really address this issue as there is no always the possibility to use port 443 facing the Internet (it is already occupied, organization policy mandates to use a different port, etc).&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 19:04:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/remote-console-ssl-certificates-and-port-80/m-p/7028460#M164965</guid>
      <dc:creator>hablutzel1</dc:creator>
      <dc:date>2018-12-13T19:04:27Z</dc:date>
    </item>
  </channel>
</rss>

