<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Blog Posts From  Tagged With tls</title>
    <link>http://communities.intel.com/community/vproexpert/blog</link>
    <description />
    <pubDate>Thu, 17 Jan 2013 23:11:33 GMT</pubDate>
    <generator>Jive SBS 5.0.2.0  (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2013-01-17T23:11:33Z</dc:date>
    <item>
      <title>Why is my certificate template missing from Intel SCS Console?</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2013/01/17/why-is-my-certificate-template-missing-from-intel-scs-console</link>
      <description>&lt;!-- [DocumentBodyStart:163916a1-aaaa-4bf2-b25d-f487772c1b26] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;When creating an Intel AMT Configuration profile with Transport Layer Security (TLS), a target Microsoft Certificate Authority (CA) and certificate template must be specified.&amp;nbsp; When using TLS with Intel AMT, a Server Authentication certificate must be defined and applied into the firmware of each system.&amp;nbsp;&amp;nbsp; The easiest choice is the WebServer certificate template.&amp;nbsp;&amp;nbsp; In some environments, this template might be disabled or removed due to security policies.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The following steps summarize the required steps.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;First - if a valid Server Authentication certificate template has not be published, a screen similar to the following will occur.&amp;nbsp;&amp;nbsp; The certificate template field is blank with no available options&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15616-231171/pic1.png"&gt;&lt;img alt="pic1.png" class="jive-image-thumbnail jive-image" height="261" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15616-231171/620-261/pic1.png" width="620"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Within the Microsoft Enterprise CA, duplicate the WebServer certificate template.&amp;nbsp; When prompted, select the default option for "Windows 2003 Server, Enterprise Edition"&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15616-231172/pic2.png"&gt;&lt;img alt="pic2.png" class="jive-image-thumbnail jive-image" height="345" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15616-231172/620-345/pic2.png" width="620"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Provide the details for the certificate template.&amp;nbsp;&amp;nbsp; Shown below the certificate template name is "Intel AMT TLS Cert".&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15616-231173/pic3.png"&gt;&lt;img alt="pic3.png" class="jive-image" height="461" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15616-231173/402-461/pic3.png" width="402"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;On the security tab, provide access to the template for the logon account of RCSserver.&amp;nbsp;&amp;nbsp; In this example, RCSserver is running under the Network Service Account of a system with hostname SCS8, thus the select "SCS8$".&amp;nbsp;&amp;nbsp; Grant the "Read" and "Enroll" permissions&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15616-231174/pic4.png"&gt;&lt;img alt="pic4.png" class="jive-image" height="387" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15616-231174/403-387/pic4.png" width="403"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Next, issue the certificate template.&amp;nbsp;&amp;nbsp; Right click on Certificate Templates under the target Microsoft CA (Note: Required only for Microsoft Enterprise CA to issue certificate templates to the Microsoft Active Directory.&amp;nbsp;&amp;nbsp; Microsoft Standalone CA implementations do not include this option.)&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15616-231175/pic5.png"&gt;&lt;img alt="pic5.png" class="jive-image-thumbnail jive-image" height="199" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15616-231175/620-199/pic5.png" width="620"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;With the certificate template issued...&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15616-231176/pic6.png"&gt;&lt;img alt="pic6.png" class="jive-image-thumbnail jive-image" height="163" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15616-231176/620-163/pic6.png" width="620"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;... in the Intel SCS console, select "Refresh CAs &amp;amp;Templates".&amp;nbsp;&amp;nbsp; Via the pull down list, select the target certificate template.&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15616-231177/pic7.png"&gt;&lt;img alt="pic7.png" class="jive-image-thumbnail jive-image" height="262" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15616-231177/620-262/pic7.png" width="620"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Two final reminders - ensure the logon account for RCSserver (the server component of the Intel SCS installation) has rights to "Issue and Manage Certificates" along with "Request Certificates" as required for the Web Enrollment process.&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15616-231178/pic8.png"&gt;&lt;img alt="pic8.png" class="jive-image" height="377" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15616-231178/402-377/pic8.png" width="402"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;And ensure the Policy Module setting allows for automatically issuing certificates&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15616-231179/pic9.png"&gt;&lt;img alt="pic9.png" class="jive-image-thumbnail jive-image" height="162" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15616-231179/620-162/pic9.png" width="620"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The above information is provided in the Intel SCS User Guide.&amp;nbsp;&amp;nbsp; This article provides a summary and reminder&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:163916a1-aaaa-4bf2-b25d-f487772c1b26] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">intel_amt</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">intel_scs</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">tls</category>
      <pubDate>Thu, 17 Jan 2013 23:11:33 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2013/01/17/why-is-my-certificate-template-missing-from-intel-scs-console</guid>
      <dc:date>2013-01-17T23:11:33Z</dc:date>
      <clearspace:dateToText>5 months, 2 days ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/why-is-my-certificate-template-missing-from-intel-scs-console</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=15616</wfw:commentRss>
    </item>
    <item>
      <title>Why consider TLS within Intel AMT configuration?</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2011/09/09/why-consider-tls-within-intel-amt-configuration</link>
      <description>&lt;!-- [DocumentBodyStart:2e3affb1-cef8-4066-9dfe-da0642b61ca7] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;If you are concerned about securing communications on your internal network, here are a few items you should know.&amp;nbsp;&amp;nbsp;&amp;nbsp; Be sure to share these insights with those you might not be concerned.&amp;nbsp;&amp;nbsp; This blog provides a few more insights beyond to the statement "Risks of not using TLS" found in the &lt;a class="jive-link-wiki-small" data-containerId="2005" data-containerType="14" data-objectId="1989" data-objectType="102" href="http://communities.intel.com/docs/DOC-1989"&gt;vPRO Security FAQ&lt;/a&gt;&lt;span&gt; .&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Two key security risks should be considered in regards to Intel AMT network traffic:&lt;/p&gt;&lt;ol start="1"&gt;&lt;li&gt;Risk of data exposure to an eavesdropper&lt;/li&gt;&lt;li&gt;Risk of machine being hijacked by an eavesdropper&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Key points to consider for these risks:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Intel AMT authentication method used (i.e. Digest or Kerberos)&lt;/li&gt;&lt;li&gt;Encryption of Intel AMT network traffic (i.e. no-TLS or TLS)&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Focusing in on the risk of data exposure, if no encryption is used communications to Intel AMT are in the clear on the network.&amp;nbsp;&amp;nbsp; An eavesdropper can see data sent back and forth.&amp;nbsp;&amp;nbsp; The majority of the data will be Intel AMT messages over HTTP or WS-Management traffic.&amp;nbsp;&amp;nbsp;&amp;nbsp; In addition to Intel AMT traffic, the eavesdropper will see other communications between the client and the infrastructure.&amp;nbsp;&amp;nbsp; (Side note: This assumes the eavesdropper has placed a network sniffer between the client and infrastructure connection AND that they know when to capture packets specific to Intel AMT.&amp;nbsp;&amp;nbsp; If the eavesdropper is capturing packets between the server and network infrastructure, they will likely be looking for more than Intel AMT related traffic)&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;To address the data exposure risk, use TLS with the Intel AMT configuration.&amp;nbsp;&amp;nbsp; The method of authentication (i.e. Digest or Kerberos) will not address the data exposure risk.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Focusing on the risk of hijacking requires a little more understanding of Intel AMT authentication.&amp;nbsp;&amp;nbsp; If Kerberos authentication is used, no username or password are sent on the network.&amp;nbsp; Instead, Intel AMT authentication is handled via a Microsoft Kerberos sequence with the Intel AMT device acting as a network service.&amp;nbsp;&amp;nbsp; If Digest authentication is used, the majority of Intel AMT use cases require an MD5 digest authentication.&amp;nbsp;&amp;nbsp;&amp;nbsp; In this scenario, the username for authentication is sent in the clear but the password is a hashed nonce (i.e. hashed value calculated based on that specific session using among other items the password value known by server and client).&amp;nbsp;&amp;nbsp;&amp;nbsp; The exception is redirection scenarios (i.e. IDE-Redirect and Serial-over-LAN).&amp;nbsp;&amp;nbsp;&amp;nbsp; In these scenarios, if digest authentication is to be used the username and password are sent in the clear.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;To help reinforce the above points, there are 3 images below of various network traces.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The first image shows a network capture of an MD5 Digest authentication to Intel AMT for a power-on event.&amp;nbsp; Note that the username is seen, but the password is a nonce value. (which cannot be repeated\replayed)&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-14760-219664/MD5+Digest.png"&gt;&lt;img alt="MD5 Digest.png" class="jive-image-thumbnail jive-image" height="100" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-14760-219664/620-100/MD5+Digest.png" width="620"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The second image shows network capture with digest authentication during an IDE-Redirect session.&amp;nbsp; Note that the username and password are in clear text.&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-14760-219665/Digest+IDER.png"&gt;&lt;img alt="Digest IDER.png" class="jive-image-thumbnail jive-image" height="266" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-14760-219665/620-266/Digest+IDER.png" width="620"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The third image shows network capture with digest authentication and TLS enabled.&amp;nbsp;&amp;nbsp; What you see is the TLS session being established followed by garbled data due to the encryption.&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-14760-219675/Digest+TLS.png"&gt;&lt;img alt="Digest TLS.png" class="jive-image-thumbnail jive-image" height="351" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-14760-219675/620-351/Digest+TLS.png" width="620"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The following chart may be a useful summary:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" cellpadding="3" cellspacing="0" style="width: 100%; border: #000000 1px solid;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th align="center" style="border:1px solid black;border: #000000 1px solid;background-color:#6690BC;" valign="middle"&gt;&lt;span style="color: #ffffff;"&gt;&lt;strong&gt;Authentication \ Encryption&lt;/strong&gt;&lt;/span&gt;&lt;/th&gt;&lt;th align="center" style="border:1px solid black;border: #000000 1px solid;background-color:#6690BC;" valign="middle"&gt;&lt;span style="color: #ffffff;"&gt;&lt;strong&gt;TLS&lt;/strong&gt;&lt;/span&gt;&lt;/th&gt;&lt;th align="center" style="border:1px solid black;border: #000000 1px solid;background-color:#6690BC;" valign="middle"&gt;&lt;span style="color: #ffffff;"&gt;&lt;strong&gt;No TLS&lt;/strong&gt;&lt;/span&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="border:1px solid black;border: #000000 1px solid;"&gt;Kerberos&lt;/td&gt;&lt;td style="border:1px solid black;border: #000000 1px solid;"&gt;Data cannot be read.&amp;nbsp;&amp;nbsp; Machine cannot be hijacked&lt;/td&gt;&lt;td style="border:1px solid black;border: #000000 1px solid;"&gt;Data can be read.&amp;nbsp;&amp;nbsp; Machine cannot be hijacked&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border:1px solid black;border: #000000 1px solid;"&gt;Digest (Username/password)&lt;/td&gt;&lt;td style="border:1px solid black;border: #000000 1px solid;"&gt;Data cannot be read.&amp;nbsp;&amp;nbsp; Machine cannot be hijacked&lt;/td&gt;&lt;td style="border:1px solid black;border: #000000 1px solid;"&gt;&lt;p&gt;Data can be read.&amp;nbsp;&amp;nbsp; Username can be captured.&lt;/p&gt;&lt;p&gt;If using redirection, password can also be captured.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;span&gt; &lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;A few additional points to consider:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;If you are not planning to use Intel AMT redirection and want best performance, a Digest with no-TLS situation may be preferred.&lt;/li&gt;&lt;li&gt;From a performance standpoint, a simple digest authentication with no-TLS (i.e. no encryption) will be the best situation.&amp;nbsp;&amp;nbsp; &lt;/li&gt;&lt;li&gt;The longest latency will occur with TLS added to the Intel AMT configuration.&amp;nbsp;&amp;nbsp; &lt;/li&gt;&lt;li&gt;Both Kerberos and TLS will require the FQDN of the Intel AMT device to be synchronized with the operating system hostname and correctly resolved within the infrastructure.&amp;nbsp; &lt;/li&gt;&lt;li&gt;Adding TLS configuration to Intel AMT will require an internal Certificate Authority with the root certificate applied to all systems accessing the Intel AMT device&lt;/li&gt;&lt;li&gt;If you want to ensure that only certain management systems are able to communication with Intel AMT systems, a mutual TLS configuration is recommended (note: this is very rare and may not be supported by all Intel AMT capable applications)&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:2e3affb1-cef8-4066-9dfe-da0642b61ca7] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">intel_amt</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">tls</category>
      <pubDate>Fri, 09 Sep 2011 14:30:37 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2011/09/09/why-consider-tls-within-intel-amt-configuration</guid>
      <dc:date>2011-09-09T14:30:37Z</dc:date>
      <clearspace:dateToText>1 year, 9 months ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/why-consider-tls-within-intel-amt-configuration</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=14760</wfw:commentRss>
    </item>
    <item>
      <title>Intel&amp;reg; vPro&amp;trade; Security FAQ</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2008/10/03/intelreg-vprotrade-security-faq</link>
      <description>&lt;!-- [DocumentBodyStart:e2bfece9-2a42-4845-b7b7-8d2302301923] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;This page was created to address frequently asked questions (FAQ) related to security of provisioning and configuration of vPro&amp;#8482; machines as well as value added security features introduced with vPro&amp;#8482; technology.&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" data-containerId="2005" data-containerType="14" data-objectId="1989" data-objectType="102" href="http://communities.intel.com/docs/DOC-1989"&gt;Intel&amp;reg; vPro&amp;#8482; Security FAQ &lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:e2bfece9-2a42-4845-b7b7-8d2302301923] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">system_defense</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">tls</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">certificate</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">ssl</category>
      <pubDate>Fri, 03 Oct 2008 19:34:10 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2008/10/03/intelreg-vprotrade-security-faq</guid>
      <dc:date>2008-10-03T19:34:10Z</dc:date>
      <clearspace:dateToText>4 years, 8 months ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/intelreg-vprotrade-security-faq</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=11609</wfw:commentRss>
    </item>
    <item>
      <title>Top 5 things I would change about Intel AMT</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2008/02/24/top-5-things-i-would-change-about-intel-amt</link>
      <description>&lt;!-- [DocumentBodyStart:96333650-efaa-4d48-9413-95401c44b130] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;The &lt;a class="jive-link-external-small" href="http://www.intel.com/software/amt-dtk" target="_blank"&gt;Intel AMT Developer Tool Kit (DTK)&lt;/a&gt; is now over a year old and by many accounts, the most popular software package for using Intel AMT that exists today. As I work on improvements and new features I also get to interact with my users, developers, IT departments, testers, etc. I also come across many common ideas for how Intel AMT should be improved. Today I decided to compile my own list of changes I would make to improve Intel AMT. Even if I work at Intel, I have no special access or power over what gets changed, so it&amp;#8217;s important that users of Intel AMT make your voices heard if you think you have changes you need made.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;1. No TLS, Serial-over-LAN/IDE-R password in the clear&lt;/strong&gt;. As many of you have discovered, when using Intel AMT in small business or enterprise mode without TLS, the login username and password is sent on the network in the clear when the administrator performs a serial-over-LAN or IDE redirect operation. With so many coffee shops, schools, Internet cafes playing around with Intel AMT features, this could be a big problem. Imagine a classroom with a few vPro computers with AMT setup in SMB mode by an unsuspecting teacher. A student running a packet sniffer, obtaining the password and rebooting AMT computers remotely. This can be avoided by setting up TLS using Intel AMT Director, but this should not be problem in the first place. The HTTP digest used for web pages could easily be adapted and used.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;2. Allow TLS in SMB mode&lt;/strong&gt;. This is a long time feature request that is somewhat related to the first issue. In my work with Intel AMT, I can do everything I need to setup TLS in SMB mode except enabling it. Allowing administrators to setup server-side authenticated TLS would be very easy to add to Intel AMT and would provide improved security with almost no work. In fact, Intel AMT Commander could just prompt the administrator on first connect if he or she want to enable TLS when a non-TLS SMB computer is found. A new root certificate would be generated if none already exist. Strictly speaking, it would not provide &amp;#8220;bank level&amp;rdquo; security, but would go a long way for shops, schools, small business owners that have more to think about than understanding secure manageability.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;3. Release the SOL/IDE-R redirection source code&lt;/strong&gt;. The library called &amp;#8220;IMRSDK.dll&amp;rdquo; is compiled by Intel and not available in source code form. It&amp;#8217;s available in Windows and Linux but it has been a problem for people trying to port this feature on to other platforms. It&amp;#8217;s also a problem because this library is far from perfect and I would be the first to make changes to it. One of the most critical changes I would make involves knowing if the Serial-over-LAN is connected or not. Imagine how annoying it is to have the SOL connection drop and that application not know about it. Intel AMT Terminal will show &amp;#8220;Connected&amp;rdquo; at the top even when it&amp;#8217;s really not. I also want a debugging feature to know exactly what is going on, people report in forums and privately to me that SOL has problems and I have no way to help. My list does not end there; I have more changes I really need made.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;4. Make Intel AMT discovery and connection easier&lt;/strong&gt;. Some Intel AMT software have a discovery feature that attempts to sweep a network to find Intel AMT computers and add them to a management console. To make it easier on the user, Intel AMT Commander also attempts to automatically detect that type of AMT computer it&amp;#8217;s talking to. Once you discover a computer, the work is not done. Is the computer setup with TLS? Is it in WSMAN only mode? Is it using TLS mutual-auth? Are you talking to LMS? What version is this? The Intel AMT DTK has an elaborate system to attempt gather this data when a user connects. With new version of Intel AMT, transition to WSMAN and more, it&amp;#8217;s getting more and more difficult to correctly detect and connect to all versions of Intel AMT. Developers looking at the DTK&amp;#8217;s connection algorithm will be stunned, we need to simplify this process.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;5. Get permitted access realms upon connection&lt;/strong&gt;. So you setup Intel AMT with various user accounts, one for asset monitoring only, one for packet control, another for remote repair. When software like Intel AMT Commander connects to Intel AMT using one of these accounts, it has no idea what types of permissions this account has. As a result, the software is left to assume it has all rights, or fail with an error when things start to go wrong. I don&amp;#8217;t think it would be unreasonable to be able to query the allowed realms upon connection for the account currently being used. This would make it easy for Intel AMT Commander to remove from the UI features that are not allowed.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Of course, being an avid fan of Intel AMT, I could write many things I like about it, just look at my many blogs. It&amp;#8217;s my hope that this list will spur discussion and action. If you read this, take the time to write a small comment saying which one of these would want fixed first, or tell me if you have your own issue.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Ylian (&lt;a class="jive-link-external-small" href="http://www.intel.com/software/ylian" target="_blank"&gt;Intel AMT Blog&lt;/a&gt;)&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:96333650-efaa-4d48-9413-95401c44b130] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">amt</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">dtk</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">commander</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">serial-over-lan</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">tls</category>
      <pubDate>Mon, 25 Feb 2008 07:06:45 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2008/02/24/top-5-things-i-would-change-about-intel-amt</guid>
      <dc:date>2008-02-25T07:06:45Z</dc:date>
      <clearspace:dateToText>5 years, 3 months ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/top-5-things-i-would-change-about-intel-amt</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=10938</wfw:commentRss>
    </item>
  </channel>
</rss>

