<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: iLO5 v3.01 missing &amp;quot;high security&amp;quot; encryption mode in ProLiant Servers (ML,DL,SL)</title>
    <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7207037#M185541</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just checked an iLO 5 running 3.01 in the lab environment I have access to and it does have the High Security option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think one thing being overlooked here is the CURRENT security state. On the one that does not list High Security or Production you have it currently set for FIPS. When in FIPS or CNSA you cannot go back to High Security or Production. You must factory reset the iLO in order to get access back.&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docId=a00105236en_us&amp;amp;docLocale=en_US&amp;amp;page=GUID-D7147C7F-2016-0901-06D0-000000000E35.html" target="_blank"&gt;https://support.hpe.com/hpesc/public/docDisplay?docId=a00105236en_us&amp;amp;docLocale=en_US&amp;amp;page=GUID-D7147C7F-2016-0901-06D0-000000000E35.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Wed, 21 Feb 2024 19:15:00 GMT</pubDate>
    <dc:creator>thutchings</dc:creator>
    <dc:date>2024-02-21T19:15:00Z</dc:date>
    <item>
      <title>iLO5 v3.01 missing "high security" encryption mode</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7206897#M185497</link>
      <description>&lt;P&gt;I have several iLO5's all running v3.01 firmware but they don't all have the same options for security state under encryption options.&amp;nbsp; I would like to configure all for "high security" but some only have FIPS/CNSA options.&amp;nbsp; The reason I need "high security" is because a Qualys vulnerability scan flags the FIPS iLOs with missing "strict-security-header for HTTP" but the iLOs configured with "high security" somehow aren't flagged for this even though my understanding is that FIPS should be a more secure option?&amp;nbsp; &amp;nbsp; I guess, the other option would be to figure out how to enable "strict security headers" on the FIPS iLOs but seems easier to try to get "high security" option going first.&amp;nbsp; Any ideas?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="iLO5-1.png" style="width: 546px;"&gt;&lt;img src="https://community.hpe.com/t5/image/serverpage/image-id/139707i05917953DFB317F6/image-dimensions/546x331?v=v2" width="546" height="331" role="button" title="iLO5-1.png" alt="iLO5-1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="iLO5-2.png" style="width: 522px;"&gt;&lt;img src="https://community.hpe.com/t5/image/serverpage/image-id/139706i3CA3D1A2D30702ED/image-dimensions/522x325?v=v2" width="522" height="325" role="button" title="iLO5-2.png" alt="iLO5-2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 04:55:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7206897#M185497</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-02-23T04:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: iLO5 v3.01 missing "high security" encryption mode</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7206986#M185527</link>
      <description>&lt;P dir="auto" style="margin: 0;"&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P dir="auto" style="margin: 0;"&gt;1. Please find the below options available in iLO 3.01&lt;/P&gt;
&lt;P dir="auto" style="margin: 0;"&gt;iLO Security States:&lt;BR /&gt;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docId=a00105236en_us&amp;amp;docLocale=en_US&amp;amp;page=GUID-258790EA-BD83-434C-809A-C150AD70946B.html" target="_blank"&gt;https://support.hpe.com/hpesc/public/docDisplay?docId=a00105236en_us&amp;amp;docLocale=en_US&amp;amp;page=GUID-258790EA-BD83-434C-809A-C150AD70946B.html&lt;/A&gt;&lt;BR /&gt;Enabling the High Security security state : &lt;BR /&gt;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docId=a00105236en_us&amp;amp;docLocale=en_US&amp;amp;page=GUID-AB1DA160-6EC8-4FE8-B646-8BF975DFC816.html" target="_blank"&gt;https://support.hpe.com/hpesc/public/docDisplay?docId=a00105236en_us&amp;amp;docLocale=en_US&amp;amp;page=GUID-AB1DA160-6EC8-4FE8-B646-8BF975DFC816.html&lt;/A&gt;&lt;/P&gt;
&lt;P dir="auto" style="margin: 0;"&gt;&lt;BR /&gt;2. If the option is not available, please reset iLO.&lt;/P&gt;
&lt;P dir="auto" style="margin: 0;"&gt;iLO web interface&lt;BR /&gt;Use the Reset button on the Diagnostics page.&lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 05:05:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7206986#M185527</guid>
      <dc:creator>ManBha</dc:creator>
      <dc:date>2024-02-21T05:05:37Z</dc:date>
    </item>
    <item>
      <title>Re: iLO5 v3.01 missing "high security" encryption mode</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7207037#M185541</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just checked an iLO 5 running 3.01 in the lab environment I have access to and it does have the High Security option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think one thing being overlooked here is the CURRENT security state. On the one that does not list High Security or Production you have it currently set for FIPS. When in FIPS or CNSA you cannot go back to High Security or Production. You must factory reset the iLO in order to get access back.&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docId=a00105236en_us&amp;amp;docLocale=en_US&amp;amp;page=GUID-D7147C7F-2016-0901-06D0-000000000E35.html" target="_blank"&gt;https://support.hpe.com/hpesc/public/docDisplay?docId=a00105236en_us&amp;amp;docLocale=en_US&amp;amp;page=GUID-D7147C7F-2016-0901-06D0-000000000E35.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 19:15:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7207037#M185541</guid>
      <dc:creator>thutchings</dc:creator>
      <dc:date>2024-02-21T19:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: iLO5 v3.01 missing "high security" encryption mode</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7207042#M185542</link>
      <description>&lt;P&gt;Also, prior to a factory reset, I would make sure you have the default password noted and the license key (if you have an additional license) as these will be lost.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 19:17:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7207042#M185542</guid>
      <dc:creator>thutchings</dc:creator>
      <dc:date>2024-02-21T19:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: iLO5 v3.01 missing "high security" encryption mode</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7207068#M185546</link>
      <description>&lt;P&gt;I was afraid of that answer.&amp;nbsp; I can certainly reset it but it's a PITA because the server(s) are in a colo center over 1 hour away.&amp;nbsp; My fear is that it won't fix my problem with Qualys.&amp;nbsp; Does it make sense that an iLO5 with latest firmware and running in FIPS mode would not have HTTP security headers enabled??&amp;nbsp; Below is the specific issue I am running into:&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;EM&gt;Qualys Scan&amp;nbsp; /&amp;nbsp;&amp;nbsp;&lt;FONT face="terminal,monaco" size="2"&gt;QID: 11827 /&amp;nbsp;&lt;/FONT&gt;&lt;FONT face="terminal,monaco" size="2"&gt;Category: CGI&lt;/FONT&gt;&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;EM&gt;&lt;FONT face="terminal,monaco" size="2"&gt;RESULTS:&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;FONT face="terminal,monaco" size="2"&gt;Strict-Transport-Security HTTP Header missing on port 443.&lt;/FONT&gt;&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="terminal,monaco" size="2"&gt;GET / HTTP/1.1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="terminal,monaco" size="2"&gt;Host: ilo5-myserver.mydomain.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="terminal,monaco" size="2"&gt;Connection: Keep-Alive&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="terminal,monaco" size="2"&gt;User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/93.0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="terminal,monaco" size="2"&gt;HTTP/1.1 200 OK&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="terminal,monaco" size="2"&gt;Content-Type: text/html&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="terminal,monaco" size="2"&gt;Content-Length: 11007&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="terminal,monaco" size="2"&gt;Connection: keep-alive&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="terminal,monaco" size="2"&gt;Content-Security-Policy: script-src 'self' 'unsafe-inline' 'unsafe-eval';&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="terminal,monaco" size="2"&gt;Date: Wed, 14 Feb 2024 00:47:34 GMT&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="terminal,monaco" size="2"&gt;ETag: "8001af65"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="terminal,monaco" size="2"&gt;X-Content-Type-Options: nosniff&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="terminal,monaco" size="2"&gt;X-Frame-Options: sameorigin&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="terminal,monaco" size="2"&gt;X-XSS-Protection: 1; mode=block&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 21:10:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7207068#M185546</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-02-21T21:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: iLO5 v3.01 missing "high security" encryption mode</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7207073#M185547</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe all that should be required to get HSTS to work correctly is to perform the following:&lt;BR /&gt;&lt;BR /&gt;1. Ensure you have a CA signed cert installed onto the iLO's&lt;/P&gt;&lt;P&gt;2. Enabled the option under the "Remote Console and Media" -&amp;gt; Security section for "IRC requires a trusted certificate in iLO"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 23:23:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7207073#M185547</guid>
      <dc:creator>thutchings</dc:creator>
      <dc:date>2024-02-21T23:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: iLO5 v3.01 missing "high security" encryption mode</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7207074#M185548</link>
      <description>&lt;P&gt;I already have GoDaddy signed certs on these units so step #1 is good.&amp;nbsp; Now I just enabled the setting that you suggsted.&amp;nbsp; Next step is to wait because our auditing firm runs these scans only once a month and they just ran a cycle.&amp;nbsp; I promise to post back with results after the next scan.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 00:02:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7207074#M185548</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-02-22T00:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: iLO5 v3.01 missing "high security" encryption mode</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7207143#M185553</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I tested this out in my lab environment and I was able to enable HSTS using the procedure I indicated above. Using Nmap, I issued the following:&lt;/P&gt;&lt;P&gt;nmap -p 443 --script http-security-headers &amp;lt;iLO IP address&amp;gt;&lt;/P&gt;&lt;P&gt;This came back with the following result:&lt;/P&gt;&lt;P&gt;443/tcp open https&lt;/P&gt;&lt;P&gt;| http-security-headers:&lt;BR /&gt;| Strict_Transport_Security:&lt;BR /&gt;&lt;FONT color="#FFFF00"&gt;|&lt;FONT color="#FF0000"&gt; HSTS not configured in HTTPS Server&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I installed the cert from the CA and enabled the "IRC requires a trusted certificate in iLO" option. These are the results now:&lt;/P&gt;&lt;P&gt;443/tcp open https&lt;/P&gt;&lt;P&gt;| http-security-headers:&lt;BR /&gt;| Strict_Transport_Security:&lt;BR /&gt;&lt;FONT color="#339966"&gt;| Header: Strict-Transport-Security: max-age=31536000; includeSubDomains&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 13:00:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7207143#M185553</guid>
      <dc:creator>thutchings</dc:creator>
      <dc:date>2024-02-22T13:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: iLO5 v3.01 missing "high security" encryption mode</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7207158#M185556</link>
      <description>&lt;P&gt;all my iLOs tested good for HSTS with nmap.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 14:28:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7207158#M185556</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-02-22T14:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: iLO5 v3.01 missing "high security" encryption mode</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7207322#M185593</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/363786"&gt;@tato386&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Perfect!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are glad to know the problem has been resolved.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 07:18:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/ilo5-v3-01-missing-quot-high-security-quot-encryption-mode/m-p/7207322#M185593</guid>
      <dc:creator>Sunitha_Mod</dc:creator>
      <dc:date>2024-02-26T07:18:10Z</dc:date>
    </item>
  </channel>
</rss>

