rkulkarni

Enabling Dell Latitude 7480 Notebook for DASH Management

Discussion created by rkulkarni Employee on Dec 26, 2018

This post will illustrate how to provision Dell Latitude Notebook and managing this using AMD DASH Tools

Host Based Configuration of AMT DASH System

Following are the steps for configuring the system using Host based configuration:

  • Initiate the configuration using ACUWizard.exe:

pic1.png



  • Select Configure via windows option:

pic2.png

  • Enter the password to encrypt the xml file:

pic3.png

  • Enter current Password (if reconfiguring) and new password:

pic4.png

 

  • Click on configure to configure the device:

pic5.png

 

Command
line Configuration

  • After the system is configured, Profile.xml is
    generated in the folder of ACUWizard, copy the same to ACUConfig.exe folder and
    run the below command in Command Prompt on acuconfig.exe path - “ACUConfig.exe
    ConfigAMT <filename> /decryptionpassword <Password>"

A log file is generated and below output ensures the configuration being successful:

2018-01-15 14:26:35:(INFO) : ACU Configurator , Category: HandleOutPut: Starting log 2018-01-15 14:26:35

2018-01-15 14:26:35:(INFO) : ACU Configurator, Category: : ACUConfig 11.2.0.35 2018-01-15
14:26:35:(INFO) : ACU Configurator, Category: -Unknown Operation-:
DESKTOP-O5HVT8E: Starting to configure AMT... 2018-01-15
14:26:47:(INFO) : localhost, Category: AMT Interface : Wire support:************** 1 2018-01-15
14:26:51:(INFO) : localhost, Category: AMT Interface : Wire support:************** 1 2018-01-15
14:27:19:(SUCCESS) : ACU Configurator, Category: Exit: ***********Exit withcode 0. Details: Success
.

 

REMOTE CONFIGURATION OF AMT DASH SYSTEM

Following are the pre-requisites:

  • Self-signed certificate
  • Un-configure network access to full un-provision mode by setting ACL to default
  • Install the generated certificate in the target in the root CA location
  • The certificate can be generated using any of the remote configuration methods as mentioned in Intel SCS user guide
  • As part of this procedure creating and installing own certificate procedure has been used

 

 

 

Follow the below steps to push the hashes/Thumbprint to Firmware:

 

  • Reboot the system and press
    F12 to go-to Bios setting menu and select MEBx
  • Provide the MEBx password
  • Go-to Intel AMT Configuration

 

 

 

  • Select the Un-configure Network Access as mentioned.

pic6.jpg

  • Select the Full Unprovision menu.

 

pic7.jpg

 

 

  • This resets the network setting and ACL’s to factory default as mentioned above.

 

pic8.jpg

 

 

  • Select Remote Setup and Configuration.

pic9.jpg

 

 

  • Select TLS PKI option.

pic10.jpg

 

 

  • Select Manage Hashes

pic11.jpg

 

 

  • The default certificates supported by Intel AMT are displayed.
  • Press Insert Key to add Custom Hash Certificate Name.
  • Enter Name of the certificate to be added.

 

pic12.jpg

 

 

  • Enter the Thumbprint /Hashvalue of certificate to be added

pic13.jpg

 

  • Set the hash certificate as active

pic14.jpg

 

 

  • Scroll down to make sure that the custom certificate is added as part of certificate list
  • Press ESC and save the configuration and reboot the system

 

pic15.jpg

 

 

 

 

Managing AMT DASH System using AMD DASH Tools

 

  • Discover the system in AMD Management Console (AMC)

pic16.png

 

  • Discover the system using AMD DASHCLI

 

  1. Command for discovery is as below:

dashcli.exe -h <IP Address> -u <username> -P <Password> discover info

 

pic17.png

 

2. Command for power operationquery on AMT DASH SYSTEM

dashcli.exe -h <IP Address> -u <username> -P <Password> -t computersystem[0] power

 

pic18.png

 

Message was edited by: Rahul Kulkarni

Outcomes