Installation Manual
• 128-bit AESGCM with RSA, DH, and a AEAD MAC (DHE-RSA-AES128-GCM-SHA256)
• 128-bit AES with RSA, DH, and a SHA256 MAC (DHE-RSA-AES128-SHA256)
• 128-bit AES with RSA, DH, and a SHA1 MAC (DHE-RSA-AES128-SHA)
• 128-bit AESGCM with RSA, and a AEAD MAC (AES128-GCM-SHA256)
• 128-bit AES with RSA, and a SHA256 MAC (AES128-SHA256)
• 128-bit AES with RSA, and a SHA1 MAC (AES128-SHA)
• 168-bit 3DES with RSA, ECDH, and a SHA1 MAC (ECDHE-RSA-DES-CBC3-SHA)
• 168-bit 3DES with RSA, DH, and a SHA1 MAC (EDH-RSA-DES-CBC3-SHA)
• 168-bit 3DES with RSA, and a SHA1 MAC (DES-CBC3-SHA)
iLO supports the following ciphers when FIPS Mode or Enforce AES/3DES Encryption is
enabled and iLO is restricted to TLS version 1.2.
• 256-bit AESGCM with RSA, ECDH, and a AEAD MAC (ECDHE-RSA-AES256-GCM-SHA384)
• 256-bit AES with RSA, ECDH, and a SHA384 MAC (ECDHE-RSA-AES256-SHA384)
• 256-bit AESGCM with RSA, DH, and a AEAD MAC (DHE-RSA-AES256-GCM-SHA384)
• 256-bit AES with RSA, DH, and a SHA256 MAC (DHE-RSA-AES256-SHA256)
• 256-bit AESGCM with RSA, and a AEAD MAC (AES256-GCM-SHA384)
• 256-bit AES with RSA, and a SHA256 MAC (AES256-SHA256)
• 128-bit AESGCM with RSA, ECDH, and a AEAD MAC (ECDHE-RSA-AES128-GCM-SHA256)
• 128-bit AES with RSA, ECDH, and a SHA256 MAC (ECDHE-RSA-AES128-SHA256)
• 128-bit AESGCM with RSA, DH, and a AEAD MAC (DHE-RSA-AES128-GCM-SHA256)
• 128-bit AES with RSA, DH, and a SHA256 MAC (DHE-RSA-AES128-SHA256)
• 128-bit AESGCM with RSA, and a AEAD MAC (AES128-GCM-SHA256)
• 128-bit AES with RSA, and a SHA256 MAC (AES128-SHA256)
SSH
iLO provides enhanced encryption through the SSH port for secure CLP transactions.
In the iLO factory default configuration:
• iLO supports AES256-CBC, AES128-CBC, 3DES-CBC, and AES256-CTR ciphers through
the SSH port.
• iLO accepts diffie-hellman-group14-sha1 and diffie-hellman-group1-sha1 key exchange,
and uses hmac-sha1, hmac-sha2-256, and hmac-md5 MACs.
When FIPS Mode or Enforce AES/DES Encryption is enabled:
• iLO supports the AES256-CTR cipher through the SSH port.
• iLO accepts diffie-hellman-group14-sha1 key exchange, and uses hmac-sha2-256 or
hmac-sha1 MACs.
FIPS mode
iLO 4 firmware version 1.20 and later supports FIPS mode. FIPS is a set of computer security
standards mandated for use by United States government agencies and contractors. When FIPS
mode is enabled, iLO operates in a mode intended to comply with the requirements of FIPS
140-2 level 1.
iLO encryption settings 85