The Sun Fire V20z and Sun Fire V40z servers include a dedicated SP for complete server independence and maximum availability of server management. The SP is an embedded PowerPC that provides the following functions:
Environmental monitoring of the platform (such as temperatures, voltages, fan speeds and panel switches)
Alert messages when problems occur
Remote control of server operations (boot, shutdown and reboot of the server’s operating system, turning the server’s power on and off, stopping the server’s boot process in BIOS, and upgrading BIOS)
After supplying AC power to the server, you are ready to begin configuring the SP by setting an IP address and associated network settings for the SP. You can configure the SP network settings by using DHCP or by using a static IP address.
Defining SP Network Settings
This section contains two alternate methods you can use to define SP network settings:
The following procedure describes how to set the SP network settings using DHCP from the Operator Panel. If your network does not use DHCP, or you want to assign a static IP address to the SP, follow the instructions in Assigning Static SP Network Settings.
1. Press any operator panel button on the server front panel (see FIGURE 2-1).
The LCD panel displays the first menu option:
Menu:
Server Menu
FIGURE 2-1 Operator Panel Buttons
2. Press the Forward button until you reach the SP menu:
Menu:
SP menu
3. Press the Select button to display the SP menu options.
SP Menu:
Set SP IP info?
4. Press the Select button.
The following prompt appears with the default response:
SP use DHCP?
No
5. Press the Forward button to change to Yes, then press the Select button.
6. Press the Select button at the confirmation prompt.
SP use DHCP:
Yes?
The server attempts to contact a DHCP server for an IP address. When the server receives a DHCP response, the LCD panel displays the DHCP-assigned SP IP addresses. The SP address is configured and the server is ready for use.
From the operator panel, follow these steps to set the SP network settings using a static IP address. You must specify a subnet mask and default gateway. This example uses the following sample settings:
IP Address: 10.10.30.5
Subnet Mask: 255.255.255.0
Default Gateway: 10.10.30.254
1. Press any operator panel button on the server front panel (see FIGURE 2-1).
The LCD panel displays the first menu option:
Menu:
Server Menu
2. Press the Forward operator panel button until you reach the SP menu:
Menu:
SP menu
3. Press the Select operator panel button to display the SP menu options.
SP Menu:
Set SP IP info?
4. Press the Select operator panel button. The following prompt displays with the default response:
SP use DHCP?
No
5. Press the Select operator panel button.
The LCD displays as follows:
SP IP Address:
0.0.0.0
6. With the cursor in the first field, increase or decrease the value using the Back or Forward operator panel button.
This field can hold a value between 0 and 255.
SP IP Address:
10.0.0.0
7. After reaching your desired value, press the Select operator panel button to advance the cursor to the next field.
SP IP Address:
10.0.0.0
8. Repeat Step 6 and Step 7 for each field until the desired IP address is displayed, then use the Enter button combination to save the IP Address.
The process continues to the next network setting, the Subnet Mask. The LCD displays as follows:
SP netmask:
255.255.255.0
9. Edit the subnet mask setting in the same manner as you did for the IP address. When finished, use the Enter button combination to save the subnet mask.
The process continues to the next network setting, the default gateway. The LCD displays as follows:
SP IP Gateway
10.10.30.1
10. Edit the default gateway setting in the same manner as you did for the IP address and the subnet mask. When finished, use the Enter button combination to save the default gateway.
The LCD displays the following confirmation prompt:
Use new IP data:
Yes?
11. Press the Select operator panel button to use the new data, or use the Cancel button combination to disregard.
The SP address is now configured and the server is ready for use.
After you install the server and configure the SP’s network settings, you must create the initial manager account. You can then perform initial configuration of the server and create additional user accounts. Only the administrator who does the initial system configuration can create the initial manager account.
A setup account is included with each server. This setup account has no password. When you log in to the SP the first time using the setup account, you are prompted to define the initial manager account with a password and an optional public key.
Usernames and passwords are strings that consist of any alphanumeric character, underscore, hyphen, or period.
Usernames must be unique and must begin with an alphabetic character.
Passwords can contain any printable character and are case-sensitive.
A username or a password is limited to 32 characters and cannot be a null or an empty string.
There are two methods you can use to create the initial manager account:
Log in to the setup account and create the initial manager account by following this procedure:
1. Using an SSHv1 or SSHv2 client, connect to the IP address of the SP.
2. Authenticate as the user setup with no password required:
# ssh sp_ip_address -l setup
3. Follow the on-screen prompts to create the initial manager account.
After you create the initial manager account, the setup account is deleted and you are logged out of the server. You can then log in using the new initial manager account, from which you can create other user accounts.
To create the initial manager account from the SM Console:
1. Enter the SP name or IP address as the URL or address in a browser, to enter the SM Console.
2. At the Create Initial Manager-Level User ID screen, enter a user ID for this account.
3. Enter a password for the account.
4. Re-enter the password to confirm.
5. Click the check mark button.
6. Use the SM Console to select initial configuration options.
After you create the initial manager-level user, the Initial Configuration Checklist screen displays in the SM Console. This enables you to determine the options you want for the initial setup of the SP.
The Initial Configuration Checklist is a table that lists the SM Console menu options and the commands you use to configure each option. It also includes links to the online help that provides instructions for each option.
If desired, you can define a name for the server that will be displayed in the operator-panel LCD when the SP is idle. After you define a name, the name and the IP address of the SP alternate every few seconds in the LCD.
1. When the server is in background state, press any operator-panel button (see FIGURE 2-1).
After you press a button, the LCD panel displays the first menu option:
Menu:
Server Menu
2. Press the Forward button until you reach the Panel menu:
Menu:
Panel menu
3. Press the Select button to display the Panel menu options.
4. Press the Forward button until the Name for LCD menu option displays:
Panel Menu:
Name for LCD?
5. Press the Select button to enable data entry.
6. Enter an alphanumeric string to display on the first line of the LCD.
You can enter letters A through Z, digits 0 through 9, hyphen and space.
a. Use the Forward and Back buttons to locate the character you wish to enter in each field.
b. Press the Select button when you locate the character you want.
c. Repeat this process until the entire name is complete.
7. Use the Enter button combination (Forward plus Select) to save your entry.
A potential vulnerability has been identified with the HP ProLiant DL585 server, where a remote unauthorized user may gain access to the server controls, when the server is powered down.
REFERENCES: None
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
HP ProLiant DL585 Integrated Lights Out (ILO) firmware prior to version 1.81
BACKGROUND:
For a PGP signed version of this Security Bulletin please write to security-alert@hp.com.
RESOLUTION:
Until a new version of the Integrated Lights-Out firmware (version 1.81) for ProLiant DL585 servers is available, HP is providing the following workaround:
To eliminate this vulnerability until ILO version 1.81 becomes available, unplug the power cord whenever the server is powered down. This will prohibit the remote access exploit.
This Bulletin will be updated when version 1.81 of the Integrated Lights-Out (ILO) firmware becomes available.
BULLETIN REVISION HISTORY:
Initial release
9 August 2005
SUPPORT: For further information, contact normal HP Services support channel.
REPORT: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com. It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information. To obtain the security-alert PGP key please send an e-mail message to security-alert@hp.com with the Subject of ‘get key’ (no quotes).
SUBSCRIBE: To initiate a subscription to receive future HP Security Bulletins via Email:
* The Software Product Category that this Security Bulletin relates to is represented by the 5th and 6th characters of the Bulletin number:
GN = HP General SW, MA = HP Management Agents, MI = Misc. 3rd party SW, MP = HP MPE/iX, NS = HP NonStop Servers, OV = HP OpenVMS, PI = HP Printing & Imaging, ST = HP Storage SW, TL = HP Trusted Linux, TU = HP Tru64 UNIX, UX = HP-UX, VV = HP Virtual Vault
System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions.
"HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin. HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action. HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user’s use or disregard of the information provided in this Bulletin. To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement."
最近评论