<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ILO 3 1.82 in BladeSystem - General</title>
    <link>https://community.hpe.com/t5/bladesystem-general/ilo-3-1-82/m-p/6751688#M24586</link>
    <description>&lt;P&gt;It seems that both powershell and rhloe scripting gets broken when you upgrade a ilo3 to 1.82.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the option of going back to 1.8 (which restores functionality) or waiting for a newer version to fix this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Only problem is how can I automate several hundred blade firmware changes when scripting is broken?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also anyone have any ideas of a workaround or a way to fix the broken functionality&amp;gt;?&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jun 2015 05:09:59 GMT</pubDate>
    <dc:creator>Ravager1</dc:creator>
    <dc:date>2015-06-02T05:09:59Z</dc:date>
    <item>
      <title>ILO 3 1.82</title>
      <link>https://community.hpe.com/t5/bladesystem-general/ilo-3-1-82/m-p/6751688#M24586</link>
      <description>&lt;P&gt;It seems that both powershell and rhloe scripting gets broken when you upgrade a ilo3 to 1.82.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the option of going back to 1.8 (which restores functionality) or waiting for a newer version to fix this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Only problem is how can I automate several hundred blade firmware changes when scripting is broken?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also anyone have any ideas of a workaround or a way to fix the broken functionality&amp;gt;?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2015 05:09:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/ilo-3-1-82/m-p/6751688#M24586</guid>
      <dc:creator>Ravager1</dc:creator>
      <dc:date>2015-06-02T05:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: ILO 3 1.82</title>
      <link>https://community.hpe.com/t5/bladesystem-general/ilo-3-1-82/m-p/6752581#M24587</link>
      <description>&lt;P&gt;What scripting tool are you using?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We were forced to disable SSLv3 in all our iLO because, the lazy port scanners began flagging iLOs as vulnerable to POODLE. &amp;nbsp;(POODLE is a MITM vulnerability that can only be exploited on Web Browsers that support SSLv3, not webservers.&amp;nbsp;And&amp;nbsp;these port scanners cannot test web browsers so they turned their attention to the webservers).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are using the hponcfg&amp;nbsp;from the OA CLI, you need to upgrade OA to version 4.30 or later. &amp;nbsp;The&amp;nbsp;hponcfg in older OA versions only used SSLv3 to connect to iLO.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2015 14:07:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/ilo-3-1-82/m-p/6752581#M24587</guid>
      <dc:creator>Oscar A. Perez</dc:creator>
      <dc:date>2015-06-04T14:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: iLO 3 1.82</title>
      <link>https://community.hpe.com/t5/bladesystem-general/ilo-3-1-82/m-p/6753002#M24588</link>
      <description>&lt;P&gt;&amp;gt;We were forced to disable SSLv3 in all our iLO because, the lazy port scanners began flagging iLOs as vulnerable to POODLE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's NOT how the security mindset works.&amp;nbsp; If you provide telnet access to iLO and a customer uses it, who gets dinged as a security flaw?&lt;/P&gt;&lt;P&gt;So if you disallow SSLv3, problem is gone.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2015 19:47:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/ilo-3-1-82/m-p/6753002#M24588</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2015-06-05T19:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: iLO 3 1.82</title>
      <link>https://community.hpe.com/t5/bladesystem-general/ilo-3-1-82/m-p/6753453#M24589</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/22676"&gt;@Dennis Handly&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;&amp;gt;We were forced to disable SSLv3 in all our iLO because, the lazy port scanners began flagging iLOs as vulnerable to POODLE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's NOT how the security mindset works.&amp;nbsp; If you provide telnet access to iLO and a customer uses it, who gets dinged as a security flaw?&lt;/P&gt;&lt;P&gt;So if you disallow SSLv3, problem is gone.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Speaking of&amp;nbsp;&lt;SPAN&gt;security mindset&lt;/SPAN&gt;, how do you explain that these very same lazy port scanners that are making a big deal&amp;nbsp;&lt;SPAN&gt;about POODLE won't even warn users &lt;/SPAN&gt;&lt;SPAN&gt;with&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Self-Signed SSL Certificates that as long as they &amp;nbsp;have those Certs in place, they are vulnerable to MITM attacks regardless of POODLE?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Any adversary&amp;nbsp;with 2 inches of forehead isn't going to waste&amp;nbsp;one second trying to&amp;nbsp;exploit&amp;nbsp;any of these scary MITM attacks with&amp;nbsp;All-CAPS letters we read&amp;nbsp;on the news, if your webserver is presenting an "untrusted" SSL Certificate. &amp;nbsp;All t&lt;SPAN&gt;he attacker needs to do is to create a fake Cert with your server info in the&amp;nbsp;Subject&amp;nbsp;and then, present&amp;nbsp;that fake certificate&amp;nbsp;to users who will gladly&amp;nbsp;ignore the annoying&amp;nbsp;browser warnings about untrusted websites.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And yet, these scanners flag POODLE as high risk but, where in the scanner report do you find a warning that&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;your users could be&amp;nbsp;just one-click away from&lt;/SPAN&gt;&lt;SPAN&gt; allowing MITM&amp;nbsp;attackers to take over their SSL/TLS connections because&amp;nbsp;of the use of&amp;nbsp;"untrusted" SSL Certificates in their environment?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Sorry but,&amp;nbsp;it is not the&amp;nbsp;&lt;SPAN&gt;security mindset what drives these port scanner companies, it is the profit motive. &amp;nbsp;Reporting issues that require their own customer base to do painful configuration changes to their entire environment (setting up a PKI and issue certs for everything) does not sell. &amp;nbsp;What&amp;nbsp;sells is to&amp;nbsp;flag third party vendors&amp;nbsp;as vulnerable, even when&amp;nbsp;isn't true&amp;nbsp;or, when there are&amp;nbsp;simple configuration changes can&amp;nbsp;take care of the problem without breaking backward compatability like in this case. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2015 03:01:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/ilo-3-1-82/m-p/6753453#M24589</guid>
      <dc:creator>Oscar A. Perez</dc:creator>
      <dc:date>2015-06-10T03:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: ILO 3 1.82</title>
      <link>https://community.hpe.com/t5/bladesystem-general/ilo-3-1-82/m-p/6975336#M24590</link>
      <description>&lt;P&gt;Oscar, I know this is an old post, but how did you disable SSL3 on ILO3? We tried the "Enforce AES/3DES Encryption" option in the GUI, but SSL3 is still enabled after this.&lt;/P&gt;&lt;P&gt;From what I can tell, you have to disable SSL3 through the ILO command line, but I'm unable to find any information on how to do this.&lt;/P&gt;&lt;P&gt;If you remember the specific command or can point me in the right direction, that would be very helpful.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 19:56:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/ilo-3-1-82/m-p/6975336#M24590</guid>
      <dc:creator>user5000</dc:creator>
      <dc:date>2017-08-31T19:56:04Z</dc:date>
    </item>
  </channel>
</rss>

