Intel® Setup and Configuration Software
Total Page:16
File Type:pdf, Size:1020Kb
Intel® Setup and Configuration Software (Intel® SCS) User Guide Version 8.2 Document Release Date: March 7, 2013 License Intel®Setup and Configuration Software (Intel® SCS) is furnished under license and may only be used or copied in accordance with the terms of that license. For more information, refer to the “Exhibit A” section of the “Intel(R) SCS License Agreement.rtf”, located in the Licenses folder. Legal Notices and Disclaimers INFORMATION IN THIS DOCUMENT IS PROVIDED IN CONNECTION WITH INTEL PRODUCTS. NO LICENSE, EXPRESS OR IMPLIED, BY ESTOPPEL OR OTHERWISE, TO ANY INTELLECTUAL PROPERTY RIGHTS IS GRANTED BY THIS DOCUMENT. EXCEPT AS PROVIDED IN INTEL'S TERMS AND CONDITIONS OF SALE FOR SUCH PRODUCTS, INTEL ASSUMES NO LIABILITY WHATSOEVER AND INTEL DISCLAIMS ANY EXPRESS OR IMPLIED WARRANTY, RELATING TO SALE AND/OR USE OF INTEL PRODUCTS INCLUDING LIABILITY OR WARRANTIES RELATING TO FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, OR INFRINGEMENT OF ANY PATENT, COPYRIGHT OR OTHER INTELLECTUAL PROPERTY RIGHT. A “Mission Critical Application” is any application in which failure of the Intel Product could result, directly or indirectly, in personal injury or death. SHOULD YOU PURCHASE OR USE INTEL'S PRODUCTS FOR ANY SUCH MISSION CRITICAL APPLICATION, YOU SHALL INDEMNIFY AND HOLD INTEL AND ITS SUBSIDIARIES, SUBCONTRACTORS AND AFFILIATES, AND THE DIRECTORS, OFFICERS, AND EMPLOYEES OF EACH, HARMLESS AGAINST ALL CLAIMS COSTS, DAMAGES, AND EXPENSES AND REASONABLE ATTORNEYS' FEES ARISING OUT OF, DIRECTLY OR INDIRECTLY, ANY CLAIM OF PRODUCT LIABILITY, PERSONAL INJURY, OR DEATH ARISING IN ANY WAY OUT OF SUCH MISSION CRITICAL APPLICATION, WHETHER OR NOT INTEL OR ITS SUBCONTRACTOR WAS NEGLIGENT IN THE DESIGN, MANUFACTURE, OR WARNING OF THE INTEL PRODUCT OR ANY OF ITS PARTS. Intel may make changes to specifications and product descriptions at any time, without notice. Designers must not rely on the absence or characteristics of any features or instructions marked “reserved” or “undefined”. Intel reserves these for future definition and shall have no responsibility whatsoever for conflicts or incompatibilities arising from future changes to them. The information here is subject to change without notice. Do not finalize a design with this information. The products described in this document may contain design defects or errors known as errata which may cause the product to deviate from published specifications. Current characterized errata are available on request. Contact your local Intel sales office or your distributor to obtain the latest specifications and before placing your product order. Copies of documents which have an order number and are referenced in this document, or other Intel literature, may be obtained by calling 1-800-548-4725, or go to: http://www.intel.com/design/literature.htm. Intel® Active Management Technology (Intel®AMT) requires activation and a system with a corporate network connection, an Intel AMT-enabled chipset, network hardware and software. For notebooks, Intel AMT may be unavailable or limited over a host OS- based VPN, when connecting wirelessly, on battery power, sleeping, hibernating or powered off. Results dependent upon hardware, setup and configuration. For more information, visit Intel® Active Management Technology. Intel® vPro™ Technology is sophisticated and requires setup and activation. Availability of features and results will depend upon the setup and configuration of your hardware, software and IT environment. To learn more visit: http://www.intel.com/technology/vpro. Client Initiated Remote Access (CIRA) may not be available in public hot spots or “click to accept” locations. For more information on CIRA, visit Fast Call for Help Overview. Intel, the Intel logo, and Intel vPro, are trademarks of Intel Corporation in the U.S. and/or other countries. Microsoft, Windows, and the Windows logo are trademarks, or registered trademarks of Microsoft Corporation in the U.S. and/or other countries. * Other names and brands may be claimed as the property of others. Copyright © 2006–2013, Intel Corporation. All rights reserved. Table of Contents Table of Contents Chapter 1: Introduction...........................................................................1 About the Intel AMT Environment .......................................................................1 Intel SCS Components...........................................................................................2 Configuration Methods and Intel AMT Versions..................................................2 Host-based Configuration ..............................................................................3 SMB/Manual Configuration ..........................................................................3 One-Touch Configuration using PSK............................................................4 Remote Configuration using PKI...................................................................4 Unified Configuration Process.......................................................................5 Intel AMT and Security Considerations ................................................................7 Password Format............................................................................................7 File Encryption...............................................................................................8 Digital Signing of Files..................................................................................9 Recommendations for Secure Deployment ................................................. 10 Control Modes ............................................................................................. 11 User Consent................................................................................................ 11 Transport Layer Security Protocol............................................................... 12 Security Before and During Configuration.................................................. 12 Security After Configuration ....................................................................... 13 Access to the Intel MEBX ........................................................................... 13 Admin Permissions in the Intel AMT Device ..................................................... 14 Default Admin User (Digest)....................................................................... 14 User-Defined Admin User (Kerberos)......................................................... 15 Maintenance Policies for Intel AMT ................................................................... 16 About Maintenance Tasks............................................................................ 16 Manual/Automatic Maintenance via Jobs.................................................... 18 Manual/Automatic Maintenance using the CLI........................................... 18 Support for KVM Redirection ............................................................................. 20 Chapter 2: Prerequisites .......................................................................21 Getting Started Checklist..................................................................................... 22 Supported Intel AMT Versions............................................................................ 26 Supported Operating Systems.............................................................................. 27 Support for a Workgroup Environment............................................................... 28 Required User Permissions.................................................................................. 29 Intel® SCS User Guide iii Table of Contents Chapter 3: Setting up the RCS .............................................................30 About the RCS..................................................................................................... 31 Selecting the Type of Installation ........................................................................ 31 Using the Installer................................................................................................ 32 RCS User Account Requirements........................................................................ 32 Using the Network Service Account ................................................................... 33 Installing Database Mode .................................................................................... 35 Supported SQL Server Versions.................................................................. 35 Installer Permissions in SQL Server............................................................ 36 RCS User Permissions in SQL Server......................................................... 36 Installing the Database................................................................................. 37 Installing the Service and Console............................................................... 40 Installing Non-Database Mode ............................................................................ 44 User Permissions Required to Access the RCS................................................... 47 Defining DCOM Permissions...................................................................... 47 Defining WMI Permissions ......................................................................... 49 Backing up Data................................................................................................... 50 Locating Non-Database Mode Data Files.................................................... 50