Setting up and configuring Intel AMT in HP Business Notebooks, Desktops, and Workstations - Technical white paper
Note  
The admin password, PID, and PPS can be pre-populated by HP during manufacturing. Refer to the OEM TLS-PSK 
provisioning section for more information.  
Legacy (zero-touch) provisioning uses a default certificate; no PID or PPS are needed. PKI is active in the base image, 
which contains 15 pre-installed certificates.  
–  Delete PID and PPS 
This option is used to delete the current PID and PPS entries and should be skipped. 
After configuring TLS-PSK, return to the previous menu.  
–  TLS PKI 
Select this menu item in order to configure TLS-PKI via the Intel Remote Configuration screen,
11
 shown in Figure 25.  
Figure 25. Configuring TLS-PKI provisioning 
Options are: 
–  Remote Configuration 
This option enables (recommended; default) or disables TLS-PKI provisioning.  
–  PKI DNS Suffix 
This option allows the PKI DNS suffix for the SCS to be specified. 
–  Manage Hashes 
This option shows the hashes that are in the system, providing names and status (active/inactive). If there are no 
hashes in the system, you are given the option to add hashes; if hashes are available, you are given the option to 
delete one or more. For more information on supported certificates, refer to Appendix D: Supported certificates
.  
11
 Intel refers to TLS-PKI provisioning as remote configuration. 
35 










