- Community Home
- >
- Servers and Operating Systems
- >
- ProLiant
- >
- ProLiant Servers (ML,DL,SL)
- >
- ILO3 TLS 1.2 capabilities
-
- Forums
-
- Advancing Life & Work
- Advantage EX
- Alliances
- Around the Storage Block
- HPE Ezmeral: Uncut
- OEM Solutions
- Servers & Systems: The Right Compute
- Tech Insights
- The Cloud Experience Everywhere
- HPE Blog, Austria, Germany & Switzerland
- Blog HPE, France
- HPE Blog, Italy
- HPE Blog, Japan
- HPE Blog, Middle East
- HPE Blog, Russia
- HPE Blog, Saudi Arabia
- HPE Blog, South Africa
- HPE Blog, UK & Ireland
-
Blogs
- Advancing Life & Work
- Advantage EX
- Alliances
- Around the Storage Block
- HPE Blog, Latin America
- HPE Blog, Middle East
- HPE Blog, Saudi Arabia
- HPE Blog, South Africa
- HPE Blog, UK & Ireland
- HPE Ezmeral: Uncut
- OEM Solutions
- Servers & Systems: The Right Compute
- Tech Insights
- The Cloud Experience Everywhere
-
Information
- Community
- Welcome
- Getting Started
- FAQ
- Ranking Overview
- Rules of Participation
- Tips and Tricks
- Resources
- Announcements
- Email us
- Feedback
- Information Libraries
- Integrated Systems
- Networking
- Servers
- Storage
- Other HPE Sites
- Support Center
- Aruba Airheads Community
- Enterprise.nxt
- HPE Dev Community
- Cloud28+ Community
- Marketplace
-
Forums
-
Blogs
-
Information
-
English
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
03-28-2018 06:53 AM
03-28-2018 06:53 AM
ILO3 TLS 1.2 capabilities
We have an HP Proliant DL360 G7 . we are looking to disable TLS 1.0 and 1.1 only leaving TLs 1.2 enabled.
Upgraded to the latest firmware and placed ILO in FIPS mode, but this did not enable TLS 1.2 , it only enabled TLS 1.1 exclusively.
Any suggesstions or input on how to configure the DL360 G7 to only use TLS 1.2 will be appreciated. Thank you.
- Tags:
- SSL
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
04-03-2018 02:32 AM
04-03-2018 02:32 AM
Re: ILO3 TLS 1.2 capabilities
Hi,
Here is the TLS support for ilo.
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00020426en_us
G7 server has iLO 3, which supports only TLS 1.0 and 1.1
Thank You!
I am a HPE employee
_________________________________________
Was the post useful? Click on the white KUDOS! Thumb below. Kudos is a way of saying thank you to a post.
// Useful Links for ProLiant Servers / Community FAQ / Rules of Participation / Servers Blog //
I work for HPE
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
07-19-2018 11:18 AM - last edited on 07-19-2018 11:36 PM by VidyaVI
07-19-2018 11:18 AM - last edited on 07-19-2018 11:36 PM by VidyaVI
Re: ILO3 TLS 1.2 capabilities
@Suman_1978 wrote:
Hi,
Here is the TLS support for ilo.
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00020426en_usG7 server has iLO 3, which supports only TLS 1.0 and 1.1
Thank You!
I am a HPE employee
_________________________________________
Was the post useful? Click on the white KUDOS! Thumb below. Kudos is a way of saying thank you to a post.
// Useful Links for ProLiant Servers / Community FAQ / Rules of Participation / Servers Blog //
Obviously you dont support it but will you be adding support to it or should I just add this to the list of justifications for not purchasing any more HP servers as we replace our existing 250 G7 servers that have current HPE support contracts? Tls 1.0 and 1.1 both have security issues that were announced before the EOL of iLO 3 support and as such it should have been updated to use 1.2.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
07-23-2018 03:01 PM
07-23-2018 03:01 PM
Re: ILO3 TLS 1.2 capabilities
New servers don't have iLO 3 in them. HPE ProLiant Gen8, Gen 9 and Gen10 servers have iLO 4 and iLO 5, which both support TLSv1.2
But iLO 3 did address the TLSv1.0 and TLSv1.1 issues.
iLO 3 implemented both the split record fix and TLS bad padding alert masking, which mitigate the IV implementation problems and the padding-check oracles which are the root cause problems for TLSv1.0 and TLSv1.1 (and TLSv1.2, actually in some implementations)
iLO 3 added the ability to disable the HTTPS webserver entirely, which certainly addresses the issues, and works well for some customers who are primarily using SSH for management.
It's worth mentioning that many such attacks require code injection, an active or forwarding man in the middle, and tens of thousands of requests made against iLO. Those tend to be impossible to practically execute on iLO's small processor/webserver with static page content.
If there truly are concerns about a man-in-the-middle; a properly trusted iLO SSL certificate and a policy of respecting the browser's warnings is necessary to defeat those attacks, regardless of the presence of TLSv1.2+.
Hewlett Packard Enterprise International
- Communities
- HPE Blogs and Forum
© Copyright 2021 Hewlett Packard Enterprise Development LP