Intel® Server Board S2600CP and Intel® Server System P4000CP Platform Management
Intel
®
Server Board S2600CP and Server System P4000CP TPS
Revision 1.1
Intel order number G26942-003
72
provided, so administrating some settings, such as user passwords, through this interface is not
advised.
Session establishment commands are IPMI commands that do not require authentication or an
associated session.
The BMC supports the following authentication types over the LAN interface.
1. None (no authentication)
2. Straight password/key
3. MD5
6.4.3.2 IPMI 2.0 Messaging
IPMI 2.0 messaging is built over RMCP+ and has a different session establishment protocol.
The session commands are defined by RMCP+ and implemented at the RMCP+ level, not IPMI
commands. Authentication is implemented at the RMCP+ level. RMCP+ provides link payload
encryption, so it is possible to communicate private/sensitive data (confidentiality).
The BMC supports the cipher suites identified in Table 22.
Table 22. Supported RMCP+ Cipher Suites
ID Authentication Algorithm Integrity Algorithm(s)
Confidentiality Algorithm(s)
0
1
RAKP-none None None
1 RAKP-HMAC-SHA1 None None
2 RAKP-HMAC-SHA1 HMAC-SHA1-96 None
3 RAKP-HMAC-SHA1 HMAC-SHA1-96 AES-CBC-128
6 RAKP-HMAC-MD5 None None
7 RAKP-HMAC-MD5 HMAC-MD5-128 None
8 RAKP-HMAC-MD5 HMAC-MD5-128 AES-CBC-128
11 RAKP-HMAC-MD5 MD5-128 None
12 RAKP-HMAC-MD5 MD5-128 AES-CBC-128
Note: Cipher suite 0 defaults to callback privilege for security purposes. This may be
changed by any administrator.
For user authentication, the BMC can be configured with ‘null’ user names, whereby
password/key lookup is done based on ‘privilege level only’, or with non-null user names, where
the key lookup for the session is determined by user name.
IPMI 2.0 messaging introduces payload types and payload IDs to allow data types other than
IPMI commands to be transferred. IPMI 2.0 serial-over-LAN is implemented as a payload type.
Table 23. Supported RMCP+ Payload Types
Payload Type Feature IANA
00h IPMI message N/A
01h Serial-over-LAN N/A
02h OEM explicit Intel (343)
10h – 15h Session setup N/A