Log out of iLO through the current browser before changing the browser cipher setting. Any changes
made to the cipher settings while you are logged in to iLO might enable the browser to continue using
a non-AES cipher.
SSH connection
For information about setting the available ciphers, see the SSH utility documentation.
RIBCL
• HPQLOCFG, displays the cipher details in the output, for example:
Detecting iLO...
Negotiated cipher: 256-bit Aes256 with 0-bit Sha384 and 384-bit 44550
• HPONCFG requires user credentials when the HighSecurity, FIPS, or SuiteB security states are
enabled.
• HPONCFG requires the following user privileges when the HighSecurity, FIPS, or SuiteB security
states are enabled: Login, Configure iLO Settings, and Administer User Accounts.
• HPONCFG for Windows is not supported when the SuiteB security state is enabled.
iLO RESTful API
Use a utility that supports TLS 1.2 and an AES cipher.
Configuring a FIPS-validated environment with iLO
Use the following instructions to operate iLO in a FIPS-validated environment. To use the FIPS security
state in iLO, see
Enabling the FIPS and SuiteB security states
It is important to decide if a FIPS-validated version of iLO is required for your environment, or if running
iLO with the FIPS security state enabled will suffice. Because of the lengthy validation process, a FIPS-
validated version of iLO might have been superseded by a nonvalidated version with new features and
security enhancements. In this situation, a FIPS-validated version of iLO might be less secure than the
latest version.
Procedure
To set up an environment with a FIPS-validated version of iLO, follow the steps in the Security Policy
document that was part of the iLO FIPS validation process.
The Security Policy documents for validated versions of iLO are available on the
. To review
information about iLO, search for the keyword iLO in the
Validated FIPS 140-1 and FIPS 140-2
Cryptographic Modules
document.
Disabling FIPS mode
Procedure
1.
To disable FIPS mode for iLO (for example, if a server is decommissioned), set iLO to the factory
default settings.
You can perform this task by using RIBCL scripts, the iLO RESTful API, or the iLO 5 Configuration
Utility.
260
Configuring a FIPS-validated environment with iLO