HP Integrated Lights-Out 2 User Guide

Table Of Contents
Securing RBSU
iLO 2 RBSU enables you to view and modify the iLO 2 configuration. RBSU access settings can
be configured using RBSU, a web browser, RIBCL scripts, or the iLO 2 Security Override Switch.
For more information, see Access options” (page 38). RBSU has three levels of security:
RBSU Login Not Required (default)
Anyone with access to the host during POST can enter the iLO 2 RBSU to view and modify
configuration settings. This is an acceptable setting if host access is controlled.
RBSU Login Required (more secure)
If RBSU login is required, then the active configuration menus are controlled by the authenticated
user's access rights.
RBSU Disabled (most secure)
If iLO 2 RBSU is disabled, user access is prohibited. This prevents modification using the RBSU
interface.
iLO 2 Security Override Switch administration
The iLO 2 Security Override Switch allows the administrator full access to the iLO 2 processor.
This access might be necessary for any of the following conditions:
The iLO 2 firmware must be re-enabled after it has been disabled.
All user accounts with the Administer User Accounts privilege have been locked out.
A bad configuration keeps the iLO 2 from displaying on the network and RBSU has been
disabled.
The boot block must be flashed.
Ramifications of setting the Security Override Switch include:
All security authorization checks are disabled while the switch is set.
The iLO 2 firmware RBSU runs if the host server is reset.
The iLO 2 firmware is not disabled and might display on the network as configured.
The iLO 2 firmware, if disabled while the Security Override Switch is set, does not log the
user out and complete the disable process until the power is cycled on the server.
The boot block is exposed for programming.
NOTE: The iLO 2 Security Override Switch is located inside the server and cannot be accessed
without opening the server enclosure.
A warning message appears on iLO 2 browser pages indicating that the iLO 2 Security Override
Switch is currently in use. An iLO 2 log entry records the use of the iLO 2 Security Override Switch.
An SNMP alert can also be sent upon setting or clearing the iLO 2 Security Override Switch.
Setting the iLO 2 Security Override Switch also enables you to flash the iLO 2 boot block. HP does
not anticipate you needing to update the iLO 2 boot block. If an iLO 2 boot block update is
required, you must perform the update at the server, then and reset iLO 2. The boot block update
cannot be done remotely. The boot block is exposed until iLO 2 is reset. For maximum security,
HP recommends that you disconnect the iLO 2 from the network until you complete the reset.
To set the iLO 2 Security Override Switch:
1. Power off the server.
2. Set the switch.
3. Power on the server.
Reverse the procedure to clear the iLO 2 Security Override Switch.
42 Configuring iLO 2