This post will illustrate how to provision Dell Latitude Notebook and managing this using AMD DASH Tools
Host Based Configuration of AMT DASH System
Following are the steps for configuring the system using Host based configuration:
- Initiate the configuration using ACUWizard.exe:
- Select Configure via windows option:
- Enter the password to encrypt the xml file:
- Enter current Password (if reconfiguring) and new password:
- Click on configure to configure the device:
- After the system is configured, Profile.xml is
generated in the folder of ACUWizard, copy the same to ACUConfig.exe folder and
run the below command in Command Prompt on acuconfig.exe path - “ACUConfig.exe
ConfigAMT <filename> /decryptionpassword <Password>"
A log file is generated and below output ensures the configuration being successful:
2018-01-15 14:26:35:(INFO) : ACU Configurator , Category: HandleOutPut: Starting log 2018-01-15 14:26:35
2018-01-15 14:26:35:(INFO) : ACU Configurator, Category: : ACUConfig 22.214.171.124 2018-01-15
14:26:35:(INFO) : ACU Configurator, Category: -Unknown Operation-:
DESKTOP-O5HVT8E: Starting to configure AMT... 2018-01-15
14:26:47:(INFO) : localhost, Category: AMT Interface : Wire support:************** 1 2018-01-15
14:26:51:(INFO) : localhost, Category: AMT Interface : Wire support:************** 1 2018-01-15
14:27:19:(SUCCESS) : ACU Configurator, Category: Exit: ***********Exit withcode 0. Details: Success.
REMOTE CONFIGURATION OF AMT DASH SYSTEM
Following are the pre-requisites:
- Self-signed certificate
- Un-configure network access to full un-provision mode by setting ACL to default
- Install the generated certificate in the target in the root CA location
- The certificate can be generated using any of the remote configuration methods as mentioned in Intel SCS user guide
- As part of this procedure creating and installing own certificate procedure has been used
Follow the below steps to push the hashes/Thumbprint to Firmware:
- Reboot the system and press
F12 to go-to Bios setting menu and select MEBx
- Provide the MEBx password
- Go-to Intel AMT Configuration
- Select the Un-configure Network Access as mentioned.
- Select the Full Unprovision menu.
- This resets the network setting and ACL’s to factory default as mentioned above.
- Select Remote Setup and Configuration.
- Select TLS PKI option.
- Select Manage Hashes
- The default certificates supported by Intel AMT are displayed.
- Press Insert Key to add Custom Hash Certificate Name.
- Enter Name of the certificate to be added.
- Enter the Thumbprint /Hashvalue of certificate to be added
- Set the hash certificate as active
- Scroll down to make sure that the custom certificate is added as part of certificate list
- Press ESC and save the configuration and reboot the system
Managing AMT DASH System using AMD DASH Tools
- Discover the system in AMD Management Console (AMC)
- Discover the system using AMD DASHCLI
- Command for discovery is as below:
dashcli.exe -h <IP Address> -u <username> -P <Password> discover info
2. Command for power operationquery on AMT DASH SYSTEM
dashcli.exe -h <IP Address> -u <username> -P <Password> -t computersystem power
Message was edited by: Rahul Kulkarni