<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security issue with ILO4 in ProLiant Servers (ML,DL,SL)</title>
    <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/security-issue-with-ilo4/m-p/6970151#M158376</link>
    <description>&lt;P&gt;If your not going to update via the host OS, it is not important to match the OS. You do need to&amp;nbsp;download the firmware file in a verision your client can deal with to extract the binary firmware image. You can then update the image via the web interface. &amp;nbsp; For CentOS the Red Hat file should work without issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Jul 2017 14:30:23 GMT</pubDate>
    <dc:creator>Jimmy Vance</dc:creator>
    <dc:date>2017-07-06T14:30:23Z</dc:date>
    <item>
      <title>Security issue with ILO4</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/security-issue-with-ilo4/m-p/6970140#M158373</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;My University is scanning all the campus servers with Nessus Vulnerability Scanner and they are complaining that my ILO4 (firmware 1.10 July 17 2012) on ProLiant ML350p Gen8 HP server has a "medium" risk level of vulnerability, so they are asking to solve this issue as soon as possible, to avoid potential attacks.&lt;/P&gt;&lt;P&gt;I enclose the "medium" risk entries of the report: all the problems are connected with the 443/tcp port, it seems I should update the version of SSL protocol to improve cipher, encription and certificate...&lt;/P&gt;&lt;P&gt;Actually I do not know what to do in practice, but I am also very cautious since ILO is very useful to monitor the system and I don't want to lose functionalities.&lt;/P&gt;&lt;P&gt;Is anybody able to help me safely in this respect?&lt;/P&gt;&lt;P&gt;Thank you very much in advance!&lt;/P&gt;&lt;P&gt;Mauro&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 13:42:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/security-issue-with-ilo4/m-p/6970140#M158373</guid>
      <dc:creator>Mauro1967</dc:creator>
      <dc:date>2017-07-06T13:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: Security issue with ILO4</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/security-issue-with-ilo4/m-p/6970142#M158374</link>
      <description>&lt;P&gt;Update to the latest iLO4 firmware and have them scan it again. &amp;nbsp;You are running a very very old version of iLO firmware. Many securty fixes/enhancments have been added.&lt;/P&gt;&lt;P&gt;&lt;A href="http://h20565.www2.hpe.com/hpsc/swd/public/readIndex?sp4ts.oid=1009143853&amp;amp;lang=en&amp;amp;cc=us" target="_blank"&gt;http://h20565.www2.hpe.com/hpsc/swd/public/readIndex?sp4ts.oid=1009143853&amp;amp;lang=en&amp;amp;cc=us&lt;/A&gt; &amp;nbsp;Select your OS and then exapnd the firmware tab&lt;/P&gt;&lt;P&gt;You can review the revision history to see the changes that have been made&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 13:55:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/security-issue-with-ilo4/m-p/6970142#M158374</guid>
      <dc:creator>Jimmy Vance</dc:creator>
      <dc:date>2017-07-06T13:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: Security issue with ILO4</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/security-issue-with-ilo4/m-p/6970147#M158375</link>
      <description>&lt;P&gt;Dear Jimmy, thank you indeed for the quick suggestion, I will do the update.&lt;/P&gt;&lt;P&gt;However my Operative System is:&lt;/P&gt;&lt;P&gt;CentOS release 6.2 (Final)&lt;/P&gt;&lt;P&gt;which is not present in the list of the web page you suggested me.&lt;/P&gt;&lt;P&gt;Which one should I use? Actually I thought that ILO is&lt;/P&gt;&lt;P&gt;independent with respect to the OS, is it really important&lt;/P&gt;&lt;P&gt;to match the OS?&lt;/P&gt;&lt;P&gt;thank you again&lt;/P&gt;&lt;P&gt;Mauro&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 14:13:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/security-issue-with-ilo4/m-p/6970147#M158375</guid>
      <dc:creator>Mauro1967</dc:creator>
      <dc:date>2017-07-06T14:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: Security issue with ILO4</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/security-issue-with-ilo4/m-p/6970151#M158376</link>
      <description>&lt;P&gt;If your not going to update via the host OS, it is not important to match the OS. You do need to&amp;nbsp;download the firmware file in a verision your client can deal with to extract the binary firmware image. You can then update the image via the web interface. &amp;nbsp; For CentOS the Red Hat file should work without issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 14:30:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/security-issue-with-ilo4/m-p/6970151#M158376</guid>
      <dc:creator>Jimmy Vance</dc:creator>
      <dc:date>2017-07-06T14:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: Security issue with ILO4</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/security-issue-with-ilo4/m-p/6970239#M158386</link>
      <description>&lt;P&gt;Dear Jimmy,&lt;/P&gt;&lt;P&gt;ok, I will update to the latest iLO4 firmware first,&lt;/P&gt;&lt;P&gt;then I will check if the security issues will disappear (hopefully)!&lt;/P&gt;&lt;P&gt;Thank you again!&lt;/P&gt;&lt;P&gt;Mauro&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2017 12:34:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/security-issue-with-ilo4/m-p/6970239#M158386</guid>
      <dc:creator>Mauro1967</dc:creator>
      <dc:date>2017-07-07T12:34:45Z</dc:date>
    </item>
  </channel>
</rss>

