• iLO operates in a mode intended to comply with the SuiteB requirements defined by the NSA, and
intended to secure systems used to hold United States government top secret classified data.
• You cannot connect to the server with network-based tools that do not support TLS 1.2.
• The system maintenance switch setting to bypass iLO security (sometimes called the iLO Security
Override switch) does not disable the password requirement for logging in to iLO.
SSH cipher, key exchange, and MAC support
iLO provides enhanced encryption through the SSH port for secure CLP transactions.
Based on the configured security state, iLO supports the following:
Production
• AES256-CBC, AES128-CBC, 3DES-CBC, and AES256-CTR ciphers
• diffie-hellman-group14-sha1 and diffie-hellman-group1-sha1 key exchange
• hmac-sha1 or hmac-sha2-256 MACs
FIPS or HighSecurity
• AES256-CTR, AEAD_AES_256_GCM, and AES256-GCM ciphers
• diffie-hellman-group14-sha1 key exchange
• hmac-sha2-256 or AEAD_AES_256_GCM MACs
SuiteB
• AEAD_AES_256_GCM and AES256-GCM ciphers
• ecdh-sha2-nistp384 key exchange
• AEAD_AES_256_GCM MAC
SSL cipher and MAC support
iLO provides enhanced security for remote management in distributed IT environments. SSL encryption
protects web browser data. Encryption of HTTP data provided by SSL ensures that the data is secure as
it is transmitted across the network.
When you log in to iLO through a browser, the browser and iLO negotiate a cipher setting to use during
the session. The negotiated cipher is displayed on the
Encryption
page.
The following lists of supported ciphers apply to all iLO SSL connections, including connections to LDAP
servers, ESKM servers, SSO servers, Insight Remote Support servers, https:// URLs used in Virtual
Media, the iLO RESTful API, CLI commands, and iLO Federation Group Firmware updates.
Based on the configured security state, iLO supports the following ciphers:
Production
• 256-bit AES-GCM with RSA, ECDH, and an AEAD MAC (ECDHE-RSA-AES256-GCM-SHA384)
• 256-bit AES with RSA, ECDH, and a SHA384 MAC (ECDHE-RSA-AES256-SHA384)
• 256-bit AES with RSA, ECDH, and a SHA1 MAC (ECDHE-RSA-AES256-SHA)
SSH cipher, key exchange, and MAC support
263