248
Configuring encryption settings
IMPORTANT:
For iLO 5 Firmware Version 1.15 Aug 17 2017 or earlier:Does not use encryption
settings and leave it as default. If you change encryption settings, Express report
service and Product Info Collection Utility etc. will not work.
SSH cipher, key exchange, and MAC support
iLO provides enhanced encryption through the SSH port for secure CLP transactions. Based on
the configured security state, iLO supports the following:
• AES256-CBC, AES128-CBC, 3DES-CBC, and AES256-CTR ciphers
• diffie-hellman-group14-sha1 and diffie-hellman-group1-sha1 key exchange
• hmac-sha1 or hmac-sha2-256 MACs
SSL cipher and MAC support
SSL cipher and MAC support
iLO provides enhanced security for remote management in distributed IT environments. SSL
encryption protects web browser data. Encryption of HTTP data provided by SSL ensures that
the data is secure as it is transmitted across the network.
When you log in to iLO through a browser, the browser and iLO negotiate a cipher setting to
use during the session. The negotiated cipher is displayed on the Encryption page.
Based on the configured security state, iLO supports the following:
Production
• 256-bit AES-GCM with RSA, ECDH, and an AEAD MAC (ECDHE-RSA-AES256-GCM-
SHA384)
• 256-bit AES with RSA, ECDH, and a SHA384 MAC (ECDHE-RSA-AES256-SHA384)
• 256-bit AES with RSA, ECDH, and a SHA1 MAC (ECDHE-RSA-AES256-SHA)
• 256-bit AES-GCM with RSA, DH, and an AEAD MAC (DHE-RSA-AES256-GCM-SHA384)
• 256-bit AES with RSA, DH, and a SHA256 MAC (DHE-RSA-AES256-SHA256)
• 256-bit AES with RSA, DH, and a SHA1 MAC (DHE-RSA-AES256-SHA)
• 256-bit AES-GCM with RSA, and an AEAD MAC (AES256-GCM-SHA384)
• 256-bit AES with RSA, and a SHA256 MAC (AES256-SHA256)
• 256-bit AES with RSA, and a SHA1 MAC (AES256-SHA)
• 128-bit AES-GCM with RSA, ECDH, and an AEAD MAC (ECDHE-RSA-AES128-GCM-
SHA256)
• 128-bit AES with RSA, ECDH, and a SHA256 MAC (ECDHE-RSA-AES128-SHA256)
• 128-bit AES with RSA, ECDH, and a SHA1 MAC (ECDHE-RSA-AES128-SHA)
• 128-bit AES-GCM with RSA, DH, and an AEAD MAC (DHE-RSA-AES128-GCM-SHA256)
• 128-bit AES with RSA, DH, and a SHA256 MAC (DHE-RSA-AES128-SHA256)