HP Integrated Lights-Out Security, 7th edition

18
Figure 11. Process for HP SIM Single Sign-On to iLO
Authentication and authorization processes for CLI access
The iLO command-line interface (CLI) is an alternate method to access critical iLO functions such as the
virtual power, text-based remote console, and virtual serial port. The iLO CLI uses the industry-
standard SSH protocol to encrypt the data stream and all keystrokes sent between iLO and the client.
When a user requests an SSH session, the iLO processor performs the following negotiation steps to
ensure a secure login:
1. The iLO processor retrieves the encryption keys from NVRAM. If the keys are not present or are
invalid, the iLO processor generates the keys.
NOTE
Encryption keys are preloaded at the HP factory. However, for a
field upgrade, creating the keys could take up to 25 minutes after
upgrading the firmware. If users try to login through SSH
immediately after upgrading, they could have to wait for up to 25