In May 2017 Intel publicly confirmed the vulnerability in own firmware for vPro/AMT. To download and patch such computers from Dell use links inside the PDF file from following link. But as i mentioned in my linkedin post it&#8217;s possible to protect even noname computers (without updated BIOS) with compromised ME firmware &#8212; implementing SSL/TLS certificates for mutual authentication. In this post i will show how it can be done. At first let&#8217;s consider that you know that your computer supports vPro/AMT, ME version, you  <span><a href="https://www.itforce.mn/index.php/2017/11/19/how-to-enable-for-vpro-amt-computers-mutual-authentication-using-certificates/" class="readmore">Continue reading &rarr;</a></span>{"id":948,"date":"2017-11-19T12:38:59","date_gmt":"2017-11-19T04:38:59","guid":{"rendered":"https:\/\/www.itforce.mn\/?p=948"},"modified":"2017-11-19T15:30:17","modified_gmt":"2017-11-19T07:30:17","slug":"how-to-enable-for-vpro-amt-computers-mutual-authentication-using-certificates","status":"publish","type":"post","link":"https:\/\/www.itforce.mn\/index.php\/2017\/11\/19\/how-to-enable-for-vpro-amt-computers-mutual-authentication-using-certificates\/","title":{"rendered":"How to enable for vPro\/AMT computers mutual authentication using certificates."},"content":{"rendered":"<p><a href=\"https:\/\/www.theregister.co.uk\/2017\/05\/07\/dell_patches_amtvulnerable_systems\">In May 2017 Intel publicly confirmed the vulnerability in own firmware for vPro\/AMT.<\/a><\/p>\n<p>To download and patch such computers from Dell use links inside the PDF file from following <a href=\"http:\/\/en.community.dell.com\/techcenter\/extras\/m\/white_papers\/20443914\">link<\/a>.<\/p>\n<p>But as i mentioned in my linkedin post it&#8217;s possible to protect even noname computers (without updated BIOS) with compromised ME firmware &#8212; implementing SSL\/TLS certificates for mutual authentication. In this post i will show how it can be done.<\/p>\n<p>At first let&#8217;s consider that<\/p>\n<ul>\n<li>you know that your computer supports vPro\/AMT, ME version, you know AMT type (ISM or full AMT and so on)<\/li>\n<li>you already use intel ME (you know how to press Ctl-P and configure AMT), but you have problem to find out fixed against vulnerability version of ME firmware<\/li>\n<li>AMT version is &gt;= 7<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>We will use several free tools for vPro\/AMT:<\/p>\n<ol>\n<li><a href=\"https:\/\/downloadcenter.intel.com\/download\/26505\/Intel-Setup-and-Configuration-Software-Intel-SCS-?product=39104\">Intel\u00ae Setup and Configuration Software (Intel\u00ae SCS) v11.2 (2017-09-15)<\/a> or Intel AMT Configuration Utility (ACU) Wizard (just unpack and run ACUWizard.exe)<\/li>\n<li><a href=\"http:\/\/www.meshcommander.com\/open-manageability\">Open Manageability Developer Tool Kit<\/a> and inside it Manageability Commander Tool and Manageability Director Tool<\/li>\n<\/ol>\n<p>Let&#8217;s consider that we configured already vPro\/AMT from BIOS (pressing Ctl-P during Dell logo):<\/p>\n<ul>\n<li>172.16.1.14<\/li>\n<li>password is configured and known<\/li>\n<li>&#8220;Configured Network Access&#8221; &#8211; allowed vpro\/amt configuration over network.<\/li>\n<li>adminpc.itforce.local is not 172.16.1.14, for example 172.16.1.100 (by the way you cannot ping\/access your vpro IP from the OS on the same computer because builtin intel NIC has two MAC addresses &#8211; one for vpro and another for OS; AcuWizard.exe uses not IP, but ME driver in OS &#8211; AcuWizard should be run only on vpro\/amt computer, not remotely !!!)<\/li>\n<\/ul>\n<p>After installation of Open Manageability Developer Tool Kit (prerequisite is Dot.Net framework) run\u00a0Manageability Director Tool to create new CA and issue\/generate certificates\u00a0 for each vPro\/AMT computer, plus certificates for each admin console\/workstation.<\/p>\n<ol>\n<li>run\u00a0Manageability Director Tool and click on &#8220;Create Root Certificate&#8221;<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1042\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro1.jpg\" alt=\"\" width=\"800\" height=\"600\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro1.jpg 800w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro1-300x225.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro1-768x576.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro1-624x468.jpg 624w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/li>\n<li>For &#8220;Common name&#8221; better to use FQDN (hostname is virtual non-existing computer name, never connected directly by any vpro and so on, needed just to create CA and name it)<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1043\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro2.jpg\" alt=\"\" width=\"797\" height=\"595\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro2.jpg 797w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro2-300x224.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro2-768x573.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro2-624x466.jpg 624w\" sizes=\"auto, (max-width: 797px) 100vw, 797px\" \/><\/li>\n<li>save as asked into your registry on adminpc (computer on which you are running Manageability Director Tool ) your new Root Certificate (to migrate\/backup and restore &#8211; later we will export all these certificates)<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1044\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro3.jpg\" alt=\"\" width=\"946\" height=\"610\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro3.jpg 946w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro3-300x193.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro3-768x495.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro3-624x402.jpg 624w\" sizes=\"auto, (max-width: 946px) 100vw, 946px\" \/><\/li>\n<li>Result you can see below:<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1045\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro4.jpg\" alt=\"\" width=\"1126\" height=\"611\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro4.jpg 1126w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro4-300x163.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro4-768x417.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro4-1024x556.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro4-624x339.jpg 624w\" sizes=\"auto, (max-width: 1126px) 100vw, 1126px\" \/><\/li>\n<li>To control it&#8217;s useful to run mmc, certificates &#8211; we will see the same certificate and where it was installed:<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1046\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro5.jpg\" alt=\"\" width=\"1251\" height=\"556\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro5.jpg 1251w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro5-300x133.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro5-768x341.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro5-1024x455.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro5-624x277.jpg 624w\" sizes=\"auto, (max-width: 1251px) 100vw, 1251px\" \/><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1061\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro20.jpg\" alt=\"\" width=\"955\" height=\"380\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro20.jpg 955w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro20-300x119.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro20-768x306.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro20-624x248.jpg 624w\" sizes=\"auto, (max-width: 955px) 100vw, 955px\" \/><\/li>\n<li>now we need to generate certificates for each vpro\/amt machine (before you need to select by mouse your CA certificate &#8211; there could be several CA certs for signing vpro certs):<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1047\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro6.jpg\" alt=\"\" width=\"798\" height=\"590\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro6.jpg 798w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro6-300x222.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro6-768x568.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro6-624x461.jpg 624w\" sizes=\"auto, (max-width: 798px) 100vw, 798px\" \/><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1048\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro7.jpg\" alt=\"\" width=\"1140\" height=\"683\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro7.jpg 1140w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro7-300x180.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro7-768x460.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro7-1024x614.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro7-624x374.jpg 624w\" sizes=\"auto, (max-width: 1140px) 100vw, 1140px\" \/><\/li>\n<li>when you finish generating certs for all vpro\/amt machines, it&#8217;s time to generate certs as well for admin consoles (in our case it&#8217;s adminpc.itforce.local) with\u00a0Manageability Director\/Commander Tool (we are configuring Mutual Auth)<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1049\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro8.jpg\" alt=\"\" width=\"1017\" height=\"640\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro8.jpg 1017w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro8-300x189.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro8-768x483.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro8-624x393.jpg 624w\" sizes=\"auto, (max-width: 1017px) 100vw, 1017px\" \/><\/li>\n<li>To lockdown the system you can harden it using other Certificate Types instead of &#8220;All permissions certificate&#8221;<\/li>\n<li>Now we have all necessary certificates.<\/li>\n<li>Before configuring the Mutual Auth we can access vPro\/AMT thru browser like below (even when workstation is powered off):<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1050\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro9.jpg\" alt=\"\" width=\"994\" height=\"761\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro9.jpg 994w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro9-300x230.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro9-768x588.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro9-624x478.jpg 624w\" sizes=\"auto, (max-width: 994px) 100vw, 994px\" \/><\/li>\n<li>after login (as you see power\u00a0 &#8212; Off):<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1051\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro10.jpg\" alt=\"\" width=\"979\" height=\"640\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro10.jpg 979w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro10-300x196.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro10-768x502.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro10-624x408.jpg 624w\" sizes=\"auto, (max-width: 979px) 100vw, 979px\" \/><\/li>\n<li>We can using vpro\/amt(even without Mutual Auth) remotely thru network conduct hardware inventory, power on\/off, mount remotely iso\/CD\/DVD, change remote BIOS settings and so on regardless of OS (linux, windows), no matter of OS state &#8211;\u00a0 started\/shutdowned\/freezed with\u00a0Blue Screen of Death.<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1052\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro11.jpg\" alt=\"\" width=\"1280\" height=\"775\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro11.jpg 1280w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro11-300x182.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro11-768x465.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro11-1024x620.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro11-624x378.jpg 624w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/li>\n<li>Now thru\u00a0Manageability Commander Tool we can also access like below:<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1053\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro12.jpg\" alt=\"\" width=\"1280\" height=\"781\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro12.jpg 1280w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro12-300x183.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro12-768x469.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro12-1024x625.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro12-624x381.jpg 624w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/li>\n<li>To configure Mutual Auth, and also for backup\/restore and migration of the system to other workstation we better to export to pfx files all our certificates (and surely place them\/pfx and password in safe protected place)<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1054\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro13.jpg\" alt=\"\" width=\"962\" height=\"554\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro13.jpg 962w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro13-300x173.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro13-768x442.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro13-624x359.jpg 624w\" sizes=\"auto, (max-width: 962px) 100vw, 962px\" \/> <img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1055\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro14.jpg\" alt=\"\" width=\"956\" height=\"553\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro14.jpg 956w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro14-300x174.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro14-768x444.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro14-624x361.jpg 624w\" sizes=\"auto, (max-width: 956px) 100vw, 956px\" \/> <img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1056\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro15.jpg\" alt=\"\" width=\"504\" height=\"392\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro15.jpg 504w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro15-300x233.jpg 300w\" sizes=\"auto, (max-width: 504px) 100vw, 504px\" \/> <img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1057\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro16.jpg\" alt=\"\" width=\"498\" height=\"389\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro16.jpg 498w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro16-300x234.jpg 300w\" sizes=\"auto, (max-width: 498px) 100vw, 498px\" \/> <img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1058\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro17.jpg\" alt=\"\" width=\"502\" height=\"396\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro17.jpg 502w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro17-300x237.jpg 300w\" sizes=\"auto, (max-width: 502px) 100vw, 502px\" \/> <img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1059\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro18.jpg\" alt=\"\" width=\"499\" height=\"394\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro18.jpg 499w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro18-300x237.jpg 300w\" sizes=\"auto, (max-width: 499px) 100vw, 499px\" \/><\/li>\n<li>repeat above steps for all generated certificates<\/li>\n<li>OK, let&#8217;s finally configure Mutual Auth for vpro and complete the task of our post:<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1060\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro19.jpg\" alt=\"\" width=\"1269\" height=\"775\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro19.jpg 1269w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro19-300x183.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro19-768x469.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro19-1024x625.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro19-624x381.jpg 624w\" sizes=\"auto, (max-width: 1269px) 100vw, 1269px\" \/> \u00a0<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1062\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro21.jpg\" alt=\"\" width=\"445\" height=\"374\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro21.jpg 445w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro21-300x252.jpg 300w\" sizes=\"auto, (max-width: 445px) 100vw, 445px\" \/> <img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1063\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro22.jpg\" alt=\"\" width=\"446\" height=\"371\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro22.jpg 446w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro22-300x250.jpg 300w\" sizes=\"auto, (max-width: 446px) 100vw, 446px\" \/> <img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1064\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro23.jpg\" alt=\"\" width=\"1231\" height=\"679\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro23.jpg 1231w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro23-300x165.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro23-768x424.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro23-1024x565.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro23-624x344.jpg 624w\" sizes=\"auto, (max-width: 1231px) 100vw, 1231px\" \/><\/li>\n<li>below is the result of installing previously generated certificates into vpro ME on target AMT computer:<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1065\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro24.jpg\" alt=\"\" width=\"1279\" height=\"740\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro24.jpg 1279w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro24-300x174.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro24-768x444.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro24-1024x592.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro24-624x361.jpg 624w\" sizes=\"auto, (max-width: 1279px) 100vw, 1279px\" \/> <img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1066\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro25.jpg\" alt=\"\" width=\"1278\" height=\"544\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro25.jpg 1278w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro25-300x128.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro25-768x327.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro25-1024x436.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro25-624x266.jpg 624w\" sizes=\"auto, (max-width: 1278px) 100vw, 1278px\" \/><\/li>\n<li>So far we just installed into intel ME certificates, but not demanded to use them, so click on below yellow mark to start:<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1067\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro26.jpg\" alt=\"\" width=\"1278\" height=\"558\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro26.jpg 1278w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro26-300x131.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro26-768x335.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro26-1024x447.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro26-624x272.jpg 624w\" sizes=\"auto, (max-width: 1278px) 100vw, 1278px\" \/> <img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1068\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro27.jpg\" alt=\"\" width=\"1279\" height=\"773\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro27.jpg 1279w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro27-300x181.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro27-768x464.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro27-1024x619.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro27-624x377.jpg 624w\" sizes=\"auto, (max-width: 1279px) 100vw, 1279px\" \/><\/li>\n<li>on above picture step three we setup to use vpro00.itforce.local certificate as\u00a0 vpro00 ME certificate (to unlink later and delete from ME this certificate you may need to enter BIOS ME and disable completely ME on this computer and enable again, or run ACUwizard.exe without parameters for certificates, delete from MDTK connection and add vpro computer again). If you don&#8217;t complete step 5-8 on the above picture even with installed adminpc.itforce.local certificate, vPro\/AMT engine will not know for what certificate\/computer to allow access to vpro\/amt (vpro ME doesn&#8217;t try to check FQDN thru DNS or ping back, it just match subject of certificate of connecting computer with this list and stored certificate, so connecting MDTK admin workstation can have any hostname, FQDN, IP and so on; just need to have correct certificate for adminpc.itforce.local to hand it to vpro ME to prove itself, and for vpro00.itforce.local\/amtca certificates to check that connecting device is really our vpro00 device.). So each vpro ME has at least 3 certificates (one own, one for CA, one for each admin workstation). Each admin workstation has one CA cert, one own cert, and one for each needed vpro ME.<\/li>\n<li><span style=\"color: #ff0000;\"><strong>step 4 (&#8220;Include Remote Authentication(console)&#8221;) enables and disables Mutual Authentication<\/strong><\/span><\/li>\n<li>When you finished above setup, your connection to vpro\/amt will reconnect thru ssl on port 16993, but with red alert:<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1069\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro28.jpg\" alt=\"\" width=\"1279\" height=\"481\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro28.jpg 1279w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro28-300x113.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro28-768x289.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro28-1024x385.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro28-624x235.jpg 624w\" sizes=\"auto, (max-width: 1279px) 100vw, 1279px\" \/><\/li>\n<li>the reason is that we connect to vpro\/amt not thru vpro00.itforce.local, but thru ip address 172.16.1.14. To fix it just use your DNS server or host file on all adminpc consoles.<\/li>\n<li>Final result :<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1070\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro29.jpg\" alt=\"\" width=\"1277\" height=\"526\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro29.jpg 1277w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro29-300x124.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro29-768x316.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro29-1024x422.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/vpro29-624x257.jpg 624w\" sizes=\"auto, (max-width: 1277px) 100vw, 1277px\" \/><\/li>\n<\/ol>\n<p>ps<\/p>\n<p>Again: If you failed with configuration of mutual authentication and lost access to vpro you can reset it without reboot just re-applying configuration by ACUwizard from OS (for this better to leave RDP or other access just in case), or from BIOS after pressing Ctl-P and completely disabling ME and enabling again.<\/p>\n<p>Now even on intel ME with vulnerable\/not-fixed ME engine we have protected vPro\/AMT system, because rogue attacker doesn&#8217;t have necessary certificate to exploit vulnerability (without necessary certificates connection is dropped immediately &#8211; at first certificate check, and only after this appears login screen if you access thru browser)<\/p>\n<p>There is also some limitations for SSL\/TLS &#8212; IDE redirect in some cases doesn&#8217;t work. But anyway it&#8217;s recommended never to enable KVM\/VNC and IDE redirection in production, and enable (can be done remotely from the same MDTK) only in emergency cases to fix and repair (restore from backup, re-image\/format\/install new OS and so on). So in emergency cases better to use VPN + IP filters (16992\/16993\/5900 ports are allowed only for admin IPs) and move temporarily from https access to http, and after incident enable again https. And surely better to patch the system if there is available hotfix from vendor.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":null,"protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-948","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/posts\/948","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/comments?post=948"}],"version-history":[{"count":30,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/posts\/948\/revisions"}],"predecessor-version":[{"id":1092,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/posts\/948\/revisions\/1092"}],"wp:attachment":[{"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/media?parent=948"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/categories?post=948"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/tags?post=948"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}