index.html 53 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873
  1. <!doctype html>
  2. <html lang="en" class="no-js">
  3. <head>
  4. <meta charset="utf-8">
  5. <meta name="viewport" content="width=device-width,initial-scale=1">
  6. <meta name="description" content="A remote monitoring and management tool">
  7. <meta name="author" content="Ylianst">
  8. <link rel="canonical" href="https://ylianst.github.io/MeshCentral/intelamt/">
  9. <link rel="prev" href="../meshrouter/">
  10. <link rel="next" href="../how-to-contribute/">
  11. <link rel="icon" href="../images/favicon.ico">
  12. <meta name="generator" content="mkdocs-1.6.1, mkdocs-material-9.5.40">
  13. <title>Intel AMT - MeshCentral Documentation</title>
  14. <link rel="stylesheet" href="../assets/stylesheets/main.8c3ca2c6.min.css">
  15. <link rel="stylesheet" href="../assets/stylesheets/palette.06af60db.min.css">
  16. <link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
  17. <link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Roboto:300,300i,400,400i,700,700i%7CRoboto+Mono:400,400i,700,700i&display=fallback">
  18. <style>:root{--md-text-font:"Roboto";--md-code-font:"Roboto Mono"}</style>
  19. <link rel="stylesheet" href="../stylesheets/extra.css">
  20. <script>__md_scope=new URL("..",location),__md_hash=e=>[...e].reduce(((e,_)=>(e<<5)-e+_.charCodeAt(0)),0),__md_get=(e,_=localStorage,t=__md_scope)=>JSON.parse(_.getItem(t.pathname+"."+e)),__md_set=(e,_,t=localStorage,a=__md_scope)=>{try{t.setItem(a.pathname+"."+e,JSON.stringify(_))}catch(e){}}</script>
  21. </head>
  22. <body dir="ltr" data-md-color-scheme="default" data-md-color-primary="white" data-md-color-accent="indigo">
  23. <input class="md-toggle" data-md-toggle="drawer" type="checkbox" id="__drawer" autocomplete="off">
  24. <input class="md-toggle" data-md-toggle="search" type="checkbox" id="__search" autocomplete="off">
  25. <label class="md-overlay" for="__drawer"></label>
  26. <div data-md-component="skip">
  27. <a href="#intel-amt" class="md-skip">
  28. Skip to content
  29. </a>
  30. </div>
  31. <div data-md-component="announce">
  32. </div>
  33. <header class="md-header" data-md-component="header">
  34. <nav class="md-header__inner md-grid" aria-label="Header">
  35. <a href=".." title="MeshCentral Documentation" class="md-header__button md-logo" aria-label="MeshCentral Documentation" data-md-component="logo">
  36. <img src="../images/favicon.ico" alt="logo">
  37. </a>
  38. <label class="md-header__button md-icon" for="__drawer">
  39. <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M3 6h18v2H3zm0 5h18v2H3zm0 5h18v2H3z"/></svg>
  40. </label>
  41. <div class="md-header__title" data-md-component="header-title">
  42. <div class="md-header__ellipsis">
  43. <div class="md-header__topic">
  44. <span class="md-ellipsis">
  45. MeshCentral Documentation
  46. </span>
  47. </div>
  48. <div class="md-header__topic" data-md-component="header-topic">
  49. <span class="md-ellipsis">
  50. Intel AMT
  51. </span>
  52. </div>
  53. </div>
  54. </div>
  55. <label class="md-header__button md-icon" for="__search">
  56. <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.52 6.52 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5"/></svg>
  57. </label>
  58. <div class="md-search" data-md-component="search" role="dialog">
  59. <label class="md-search__overlay" for="__search"></label>
  60. <div class="md-search__inner" role="search">
  61. <form class="md-search__form" name="search">
  62. <input type="text" class="md-search__input" name="query" aria-label="Search" placeholder="Search" autocapitalize="off" autocorrect="off" autocomplete="off" spellcheck="false" data-md-component="search-query" required>
  63. <label class="md-search__icon md-icon" for="__search">
  64. <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.52 6.52 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5"/></svg>
  65. <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M20 11v2H8l5.5 5.5-1.42 1.42L4.16 12l7.92-7.92L13.5 5.5 8 11z"/></svg>
  66. </label>
  67. <nav class="md-search__options" aria-label="Search">
  68. <button type="reset" class="md-search__icon md-icon" title="Clear" aria-label="Clear" tabindex="-1">
  69. <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M19 6.41 17.59 5 12 10.59 6.41 5 5 6.41 10.59 12 5 17.59 6.41 19 12 13.41 17.59 19 19 17.59 13.41 12z"/></svg>
  70. </button>
  71. </nav>
  72. </form>
  73. <div class="md-search__output">
  74. <div class="md-search__scrollwrap" tabindex="0" data-md-scrollfix>
  75. <div class="md-search-result" data-md-component="search-result">
  76. <div class="md-search-result__meta">
  77. Initializing search
  78. </div>
  79. <ol class="md-search-result__list" role="presentation"></ol>
  80. </div>
  81. </div>
  82. </div>
  83. </div>
  84. </div>
  85. <div class="md-header__source">
  86. <a href="https://github.com/Ylianst/MeshCentral" title="Go to repository" class="md-source" data-md-component="source">
  87. <div class="md-source__icon md-icon">
  88. <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 448 512"><!--! Font Awesome Free 6.6.0 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License) Copyright 2024 Fonticons, Inc.--><path d="M439.55 236.05 244 40.45a28.87 28.87 0 0 0-40.81 0l-40.66 40.63 51.52 51.52c27.06-9.14 52.68 16.77 43.39 43.68l49.66 49.66c34.23-11.8 61.18 31 35.47 56.69-26.49 26.49-70.21-2.87-56-37.34L240.22 199v121.85c25.3 12.54 22.26 41.85 9.08 55a34.34 34.34 0 0 1-48.55 0c-17.57-17.6-11.07-46.91 11.25-56v-123c-20.8-8.51-24.6-30.74-18.64-45L142.57 101 8.45 235.14a28.86 28.86 0 0 0 0 40.81l195.61 195.6a28.86 28.86 0 0 0 40.8 0l194.69-194.69a28.86 28.86 0 0 0 0-40.81"/></svg>
  89. </div>
  90. <div class="md-source__repository">
  91. Ylianst/MeshCentral
  92. </div>
  93. </a>
  94. </div>
  95. </nav>
  96. </header>
  97. <div class="md-container" data-md-component="container">
  98. <nav class="md-tabs" aria-label="Tabs" data-md-component="tabs">
  99. <div class="md-grid">
  100. <ul class="md-tabs__list">
  101. <li class="md-tabs__item">
  102. <a href=".." class="md-tabs__link">
  103. Home
  104. </a>
  105. </li>
  106. <li class="md-tabs__item">
  107. <a href="../install/" class="md-tabs__link">
  108. Install
  109. </a>
  110. </li>
  111. <li class="md-tabs__item">
  112. <a href="../meshcentral/" class="md-tabs__link">
  113. MeshCentral2
  114. </a>
  115. </li>
  116. <li class="md-tabs__item">
  117. <a href="../design/" class="md-tabs__link">
  118. Design and Architecture
  119. </a>
  120. </li>
  121. <li class="md-tabs__item">
  122. <a href="../meshcmd/" class="md-tabs__link">
  123. MeshCmd
  124. </a>
  125. </li>
  126. <li class="md-tabs__item">
  127. <a href="../meshctrl/" class="md-tabs__link">
  128. MeshCtrl
  129. </a>
  130. </li>
  131. <li class="md-tabs__item">
  132. <a href="../meshrouter/" class="md-tabs__link">
  133. Mesh Router
  134. </a>
  135. </li>
  136. <li class="md-tabs__item md-tabs__item--active">
  137. <a href="./" class="md-tabs__link">
  138. Intel AMT
  139. </a>
  140. </li>
  141. <li class="md-tabs__item">
  142. <a href="../how-to-contribute/" class="md-tabs__link">
  143. How to Contribute
  144. </a>
  145. </li>
  146. <li class="md-tabs__item">
  147. <a href="../other/adfs_sso_guide/" class="md-tabs__link">
  148. Other
  149. </a>
  150. </li>
  151. </ul>
  152. </div>
  153. </nav>
  154. <main class="md-main" data-md-component="main">
  155. <div class="md-main__inner md-grid">
  156. <div class="md-sidebar md-sidebar--primary" data-md-component="sidebar" data-md-type="navigation" >
  157. <div class="md-sidebar__scrollwrap">
  158. <div class="md-sidebar__inner">
  159. <nav class="md-nav md-nav--primary md-nav--lifted" aria-label="Navigation" data-md-level="0">
  160. <label class="md-nav__title" for="__drawer">
  161. <a href=".." title="MeshCentral Documentation" class="md-nav__button md-logo" aria-label="MeshCentral Documentation" data-md-component="logo">
  162. <img src="../images/favicon.ico" alt="logo">
  163. </a>
  164. MeshCentral Documentation
  165. </label>
  166. <div class="md-nav__source">
  167. <a href="https://github.com/Ylianst/MeshCentral" title="Go to repository" class="md-source" data-md-component="source">
  168. <div class="md-source__icon md-icon">
  169. <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 448 512"><!--! Font Awesome Free 6.6.0 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License) Copyright 2024 Fonticons, Inc.--><path d="M439.55 236.05 244 40.45a28.87 28.87 0 0 0-40.81 0l-40.66 40.63 51.52 51.52c27.06-9.14 52.68 16.77 43.39 43.68l49.66 49.66c34.23-11.8 61.18 31 35.47 56.69-26.49 26.49-70.21-2.87-56-37.34L240.22 199v121.85c25.3 12.54 22.26 41.85 9.08 55a34.34 34.34 0 0 1-48.55 0c-17.57-17.6-11.07-46.91 11.25-56v-123c-20.8-8.51-24.6-30.74-18.64-45L142.57 101 8.45 235.14a28.86 28.86 0 0 0 0 40.81l195.61 195.6a28.86 28.86 0 0 0 40.8 0l194.69-194.69a28.86 28.86 0 0 0 0-40.81"/></svg>
  170. </div>
  171. <div class="md-source__repository">
  172. Ylianst/MeshCentral
  173. </div>
  174. </a>
  175. </div>
  176. <ul class="md-nav__list" data-md-scrollfix>
  177. <li class="md-nav__item">
  178. <a href=".." class="md-nav__link">
  179. <span class="md-ellipsis">
  180. Home
  181. </span>
  182. </a>
  183. </li>
  184. <li class="md-nav__item md-nav__item--nested">
  185. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_2" >
  186. <label class="md-nav__link" for="__nav_2" id="__nav_2_label" tabindex="0">
  187. <span class="md-ellipsis">
  188. Install
  189. </span>
  190. <span class="md-nav__icon md-icon"></span>
  191. </label>
  192. <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_2_label" aria-expanded="false">
  193. <label class="md-nav__title" for="__nav_2">
  194. <span class="md-nav__icon md-icon"></span>
  195. Install
  196. </label>
  197. <ul class="md-nav__list" data-md-scrollfix>
  198. <li class="md-nav__item">
  199. <a href="../install/" class="md-nav__link">
  200. <span class="md-ellipsis">
  201. Quick Start Guide
  202. </span>
  203. </a>
  204. </li>
  205. <li class="md-nav__item">
  206. <a href="../install/install2/" class="md-nav__link">
  207. <span class="md-ellipsis">
  208. Full Install Guide
  209. </span>
  210. </a>
  211. </li>
  212. </ul>
  213. </nav>
  214. </li>
  215. <li class="md-nav__item md-nav__item--nested">
  216. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_3" >
  217. <label class="md-nav__link" for="__nav_3" id="__nav_3_label" tabindex="0">
  218. <span class="md-ellipsis">
  219. MeshCentral2
  220. </span>
  221. <span class="md-nav__icon md-icon"></span>
  222. </label>
  223. <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_3_label" aria-expanded="false">
  224. <label class="md-nav__title" for="__nav_3">
  225. <span class="md-nav__icon md-icon"></span>
  226. MeshCentral2
  227. </label>
  228. <ul class="md-nav__list" data-md-scrollfix>
  229. <li class="md-nav__item">
  230. <a href="../meshcentral/" class="md-nav__link">
  231. <span class="md-ellipsis">
  232. MeshCentral2 Guide
  233. </span>
  234. </a>
  235. </li>
  236. <li class="md-nav__item">
  237. <a href="../meshcentral/config/" class="md-nav__link">
  238. <span class="md-ellipsis">
  239. All Configuration Options
  240. </span>
  241. </a>
  242. </li>
  243. <li class="md-nav__item">
  244. <a href="../meshcentral/agents/" class="md-nav__link">
  245. <span class="md-ellipsis">
  246. Agent Information
  247. </span>
  248. </a>
  249. </li>
  250. <li class="md-nav__item">
  251. <a href="../meshcentral/assistant/" class="md-nav__link">
  252. <span class="md-ellipsis">
  253. Assistant
  254. </span>
  255. </a>
  256. </li>
  257. <li class="md-nav__item">
  258. <a href="../meshcentral/codesigning/" class="md-nav__link">
  259. <span class="md-ellipsis">
  260. Code Signing
  261. </span>
  262. </a>
  263. </li>
  264. <li class="md-nav__item">
  265. <a href="../meshcentral/debugging/" class="md-nav__link">
  266. <span class="md-ellipsis">
  267. Debugging
  268. </span>
  269. </a>
  270. </li>
  271. <li class="md-nav__item">
  272. <a href="../meshcentral/devicetabs/" class="md-nav__link">
  273. <span class="md-ellipsis">
  274. Device Tabs
  275. </span>
  276. </a>
  277. </li>
  278. <li class="md-nav__item">
  279. <a href="../meshcentral/plugins/" class="md-nav__link">
  280. <span class="md-ellipsis">
  281. Plugins
  282. </span>
  283. </a>
  284. </li>
  285. <li class="md-nav__item">
  286. <a href="../meshcentral/SSLnletsencrypt/" class="md-nav__link">
  287. <span class="md-ellipsis">
  288. SSL
  289. </span>
  290. </a>
  291. </li>
  292. <li class="md-nav__item">
  293. <a href="../meshcentral/security/" class="md-nav__link">
  294. <span class="md-ellipsis">
  295. Security
  296. </span>
  297. </a>
  298. </li>
  299. <li class="md-nav__item">
  300. <a href="../meshcentral/tokens/" class="md-nav__link">
  301. <span class="md-ellipsis">
  302. Tokens
  303. </span>
  304. </a>
  305. </li>
  306. <li class="md-nav__item">
  307. <a href="../meshcentral/faq/" class="md-nav__link">
  308. <span class="md-ellipsis">
  309. FAQ
  310. </span>
  311. </a>
  312. </li>
  313. <li class="md-nav__item">
  314. <a href="../meshcentral/tipsntricks/" class="md-nav__link">
  315. <span class="md-ellipsis">
  316. Tips n Tricks
  317. </span>
  318. </a>
  319. </li>
  320. <li class="md-nav__item">
  321. <a href="../messaging/" class="md-nav__link">
  322. <span class="md-ellipsis">
  323. Messaging
  324. </span>
  325. </a>
  326. </li>
  327. <li class="md-nav__item">
  328. <a href="../meshcentral/customization/" class="md-nav__link">
  329. <span class="md-ellipsis">
  330. Customization
  331. </span>
  332. </a>
  333. </li>
  334. <li class="md-nav__item">
  335. <a href="../meshcentral/openidConnectStrategy/" class="md-nav__link">
  336. <span class="md-ellipsis">
  337. openidConnectStrategy
  338. </span>
  339. </a>
  340. </li>
  341. </ul>
  342. </nav>
  343. </li>
  344. <li class="md-nav__item md-nav__item--nested">
  345. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_4" >
  346. <label class="md-nav__link" for="__nav_4" id="__nav_4_label" tabindex="0">
  347. <span class="md-ellipsis">
  348. Design and Architecture
  349. </span>
  350. <span class="md-nav__icon md-icon"></span>
  351. </label>
  352. <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_4_label" aria-expanded="false">
  353. <label class="md-nav__title" for="__nav_4">
  354. <span class="md-nav__icon md-icon"></span>
  355. Design and Architecture
  356. </label>
  357. <ul class="md-nav__list" data-md-scrollfix>
  358. <li class="md-nav__item">
  359. <a href="../design/" class="md-nav__link">
  360. <span class="md-ellipsis">
  361. Design and Architecture
  362. </span>
  363. </a>
  364. </li>
  365. </ul>
  366. </nav>
  367. </li>
  368. <li class="md-nav__item md-nav__item--nested">
  369. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_5" >
  370. <label class="md-nav__link" for="__nav_5" id="__nav_5_label" tabindex="0">
  371. <span class="md-ellipsis">
  372. MeshCmd
  373. </span>
  374. <span class="md-nav__icon md-icon"></span>
  375. </label>
  376. <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_5_label" aria-expanded="false">
  377. <label class="md-nav__title" for="__nav_5">
  378. <span class="md-nav__icon md-icon"></span>
  379. MeshCmd
  380. </label>
  381. <ul class="md-nav__list" data-md-scrollfix>
  382. <li class="md-nav__item">
  383. <a href="../meshcmd/" class="md-nav__link">
  384. <span class="md-ellipsis">
  385. MeshCmd
  386. </span>
  387. </a>
  388. </li>
  389. </ul>
  390. </nav>
  391. </li>
  392. <li class="md-nav__item md-nav__item--nested">
  393. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_6" >
  394. <label class="md-nav__link" for="__nav_6" id="__nav_6_label" tabindex="0">
  395. <span class="md-ellipsis">
  396. MeshCtrl
  397. </span>
  398. <span class="md-nav__icon md-icon"></span>
  399. </label>
  400. <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_6_label" aria-expanded="false">
  401. <label class="md-nav__title" for="__nav_6">
  402. <span class="md-nav__icon md-icon"></span>
  403. MeshCtrl
  404. </label>
  405. <ul class="md-nav__list" data-md-scrollfix>
  406. <li class="md-nav__item">
  407. <a href="../meshctrl/" class="md-nav__link">
  408. <span class="md-ellipsis">
  409. MeshCtrl
  410. </span>
  411. </a>
  412. </li>
  413. </ul>
  414. </nav>
  415. </li>
  416. <li class="md-nav__item md-nav__item--nested">
  417. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_7" >
  418. <label class="md-nav__link" for="__nav_7" id="__nav_7_label" tabindex="0">
  419. <span class="md-ellipsis">
  420. Mesh Router
  421. </span>
  422. <span class="md-nav__icon md-icon"></span>
  423. </label>
  424. <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_7_label" aria-expanded="false">
  425. <label class="md-nav__title" for="__nav_7">
  426. <span class="md-nav__icon md-icon"></span>
  427. Mesh Router
  428. </label>
  429. <ul class="md-nav__list" data-md-scrollfix>
  430. <li class="md-nav__item">
  431. <a href="../meshrouter/" class="md-nav__link">
  432. <span class="md-ellipsis">
  433. MeshCentral Router
  434. </span>
  435. </a>
  436. </li>
  437. </ul>
  438. </nav>
  439. </li>
  440. <li class="md-nav__item md-nav__item--active md-nav__item--section md-nav__item--nested">
  441. <input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_8" checked>
  442. <label class="md-nav__link" for="__nav_8" id="__nav_8_label" tabindex="">
  443. <span class="md-ellipsis">
  444. Intel AMT
  445. </span>
  446. <span class="md-nav__icon md-icon"></span>
  447. </label>
  448. <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_8_label" aria-expanded="true">
  449. <label class="md-nav__title" for="__nav_8">
  450. <span class="md-nav__icon md-icon"></span>
  451. Intel AMT
  452. </label>
  453. <ul class="md-nav__list" data-md-scrollfix>
  454. <li class="md-nav__item md-nav__item--active">
  455. <input class="md-nav__toggle md-toggle" type="checkbox" id="__toc">
  456. <label class="md-nav__link md-nav__link--active" for="__toc">
  457. <span class="md-ellipsis">
  458. Intel AMT
  459. </span>
  460. <span class="md-nav__icon md-icon"></span>
  461. </label>
  462. <a href="./" class="md-nav__link md-nav__link--active">
  463. <span class="md-ellipsis">
  464. Intel AMT
  465. </span>
  466. </a>
  467. <nav class="md-nav md-nav--secondary" aria-label="Table of contents">
  468. <label class="md-nav__title" for="__toc">
  469. <span class="md-nav__icon md-icon"></span>
  470. Table of contents
  471. </label>
  472. <ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
  473. <li class="md-nav__item">
  474. <a href="#video-walkthru" class="md-nav__link">
  475. <span class="md-ellipsis">
  476. Video Walkthru
  477. </span>
  478. </a>
  479. </li>
  480. <li class="md-nav__item">
  481. <a href="#abstract" class="md-nav__link">
  482. <span class="md-ellipsis">
  483. Abstract
  484. </span>
  485. </a>
  486. </li>
  487. <li class="md-nav__item">
  488. <a href="#history-of-amt" class="md-nav__link">
  489. <span class="md-ellipsis">
  490. History of AMT
  491. </span>
  492. </a>
  493. </li>
  494. <li class="md-nav__item">
  495. <a href="#introduction" class="md-nav__link">
  496. <span class="md-ellipsis">
  497. Introduction
  498. </span>
  499. </a>
  500. </li>
  501. <li class="md-nav__item">
  502. <a href="#bare-metal-activation-server" class="md-nav__link">
  503. <span class="md-ellipsis">
  504. Bare-Metal Activation Server
  505. </span>
  506. </a>
  507. </li>
  508. <li class="md-nav__item">
  509. <a href="#meshcentral-group-types" class="md-nav__link">
  510. <span class="md-ellipsis">
  511. MeshCentral Group Types
  512. </span>
  513. </a>
  514. </li>
  515. <li class="md-nav__item">
  516. <a href="#client-initiated-remote-access-mps-server" class="md-nav__link">
  517. <span class="md-ellipsis">
  518. Client Initiated Remote Access &amp; MPS server
  519. </span>
  520. </a>
  521. </li>
  522. <li class="md-nav__item">
  523. <a href="#activation-certificate-setup" class="md-nav__link">
  524. <span class="md-ellipsis">
  525. Activation Certificate Setup
  526. </span>
  527. </a>
  528. </li>
  529. <li class="md-nav__item">
  530. <a href="#intel-amt-mei-and-lms" class="md-nav__link">
  531. <span class="md-ellipsis">
  532. Intel AMT MEI and LMS
  533. </span>
  534. </a>
  535. </li>
  536. <li class="md-nav__item">
  537. <a href="#intel-amt-system-defense" class="md-nav__link">
  538. <span class="md-ellipsis">
  539. Intel AMT System Defense
  540. </span>
  541. </a>
  542. </li>
  543. </ul>
  544. </nav>
  545. </li>
  546. </ul>
  547. </nav>
  548. </li>
  549. <li class="md-nav__item md-nav__item--nested">
  550. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_9" >
  551. <label class="md-nav__link" for="__nav_9" id="__nav_9_label" tabindex="0">
  552. <span class="md-ellipsis">
  553. How to Contribute
  554. </span>
  555. <span class="md-nav__icon md-icon"></span>
  556. </label>
  557. <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_9_label" aria-expanded="false">
  558. <label class="md-nav__title" for="__nav_9">
  559. <span class="md-nav__icon md-icon"></span>
  560. How to Contribute
  561. </label>
  562. <ul class="md-nav__list" data-md-scrollfix>
  563. <li class="md-nav__item">
  564. <a href="../how-to-contribute/" class="md-nav__link">
  565. <span class="md-ellipsis">
  566. Contribute to MeshCentral
  567. </span>
  568. </a>
  569. </li>
  570. </ul>
  571. </nav>
  572. </li>
  573. <li class="md-nav__item md-nav__item--nested">
  574. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_10" >
  575. <label class="md-nav__link" for="__nav_10" id="__nav_10_label" tabindex="0">
  576. <span class="md-ellipsis">
  577. Other
  578. </span>
  579. <span class="md-nav__icon md-icon"></span>
  580. </label>
  581. <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_10_label" aria-expanded="false">
  582. <label class="md-nav__title" for="__nav_10">
  583. <span class="md-nav__icon md-icon"></span>
  584. Other
  585. </label>
  586. <ul class="md-nav__list" data-md-scrollfix>
  587. <li class="md-nav__item">
  588. <a href="../other/adfs_sso_guide/" class="md-nav__link">
  589. <span class="md-ellipsis">
  590. ADFS SSO Guide
  591. </span>
  592. </a>
  593. </li>
  594. <li class="md-nav__item">
  595. <a href="../other/meshcentral_satellite/" class="md-nav__link">
  596. <span class="md-ellipsis">
  597. MeshCentral Satellite
  598. </span>
  599. </a>
  600. </li>
  601. </ul>
  602. </nav>
  603. </li>
  604. </ul>
  605. </nav>
  606. </div>
  607. </div>
  608. </div>
  609. <div class="md-sidebar md-sidebar--secondary" data-md-component="sidebar" data-md-type="toc" >
  610. <div class="md-sidebar__scrollwrap">
  611. <div class="md-sidebar__inner">
  612. <nav class="md-nav md-nav--secondary" aria-label="Table of contents">
  613. <label class="md-nav__title" for="__toc">
  614. <span class="md-nav__icon md-icon"></span>
  615. Table of contents
  616. </label>
  617. <ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
  618. <li class="md-nav__item">
  619. <a href="#video-walkthru" class="md-nav__link">
  620. <span class="md-ellipsis">
  621. Video Walkthru
  622. </span>
  623. </a>
  624. </li>
  625. <li class="md-nav__item">
  626. <a href="#abstract" class="md-nav__link">
  627. <span class="md-ellipsis">
  628. Abstract
  629. </span>
  630. </a>
  631. </li>
  632. <li class="md-nav__item">
  633. <a href="#history-of-amt" class="md-nav__link">
  634. <span class="md-ellipsis">
  635. History of AMT
  636. </span>
  637. </a>
  638. </li>
  639. <li class="md-nav__item">
  640. <a href="#introduction" class="md-nav__link">
  641. <span class="md-ellipsis">
  642. Introduction
  643. </span>
  644. </a>
  645. </li>
  646. <li class="md-nav__item">
  647. <a href="#bare-metal-activation-server" class="md-nav__link">
  648. <span class="md-ellipsis">
  649. Bare-Metal Activation Server
  650. </span>
  651. </a>
  652. </li>
  653. <li class="md-nav__item">
  654. <a href="#meshcentral-group-types" class="md-nav__link">
  655. <span class="md-ellipsis">
  656. MeshCentral Group Types
  657. </span>
  658. </a>
  659. </li>
  660. <li class="md-nav__item">
  661. <a href="#client-initiated-remote-access-mps-server" class="md-nav__link">
  662. <span class="md-ellipsis">
  663. Client Initiated Remote Access &amp; MPS server
  664. </span>
  665. </a>
  666. </li>
  667. <li class="md-nav__item">
  668. <a href="#activation-certificate-setup" class="md-nav__link">
  669. <span class="md-ellipsis">
  670. Activation Certificate Setup
  671. </span>
  672. </a>
  673. </li>
  674. <li class="md-nav__item">
  675. <a href="#intel-amt-mei-and-lms" class="md-nav__link">
  676. <span class="md-ellipsis">
  677. Intel AMT MEI and LMS
  678. </span>
  679. </a>
  680. </li>
  681. <li class="md-nav__item">
  682. <a href="#intel-amt-system-defense" class="md-nav__link">
  683. <span class="md-ellipsis">
  684. Intel AMT System Defense
  685. </span>
  686. </a>
  687. </li>
  688. </ul>
  689. </nav>
  690. </div>
  691. </div>
  692. </div>
  693. <div class="md-content" data-md-component="content">
  694. <article class="md-content__inner md-typeset">
  695. <h1 id="intel-amt">Intel AMT<a class="headerlink" href="#intel-amt" title="Permanent link">&para;</a></h1>
  696. <p>Intel AMT Guide <a href="https://github.com/Ylianst/MeshCentral/blob/master/docs/MeshCentral Intel AMT Guide v0.0.1.odt?raw=true">as .odt</a></p>
  697. <h2 id="video-walkthru">Video Walkthru<a class="headerlink" href="#video-walkthru" title="Permanent link">&para;</a></h2>
  698. <div class="video-wrapper">
  699. <iframe width="320" height="180" src="https://www.youtube.com/embed/naWKE3rT6e8" frameborder="0" allowfullscreen></iframe>
  700. <iframe width="320" height="180" src="https://www.youtube.com/embed/TaKsFEVaMpg" frameborder="0" allowfullscreen></iframe>
  701. </div>
  702. <h2 id="abstract">Abstract<a class="headerlink" href="#abstract" title="Permanent link">&para;</a></h2>
  703. <p>This user guide contains all essential information for activating and using Intel® Active Management Technology (Intel® AMT) with MeshCentral. We will review how to activate, connect to and use Intel AMT features and how this benefit administrators that want to manage computers remotely. This document expect the reader to already be familiar with how to install and operate MeshCentral and have a basic understanding of how Intel® AMT works.</p>
  704. <h2 id="history-of-amt">History of AMT<a class="headerlink" href="#history-of-amt" title="Permanent link">&para;</a></h2>
  705. <div class="video-wrapper">
  706. <iframe width="320" height="180" src="https://www.youtube.com/embed/_SXT0Gr4Mls" frameborder="0" allowfullscreen></iframe>
  707. </div>
  708. <h2 id="introduction">Introduction<a class="headerlink" href="#introduction" title="Permanent link">&para;</a></h2>
  709. <p>MeshCentral is a free open source web-based remote computer management software and it fully supports Intel® Active Management Technology (Intel® AMT). MeshCentral does not require that computers it manages support Intel AMT, but if a remote computer has this capability, MeshCentral will make use of it.</p>
  710. <p>Intel AMT can be seen as a hardware based management agent that is built into some Intel PC’s. Once setup, Intel AMT can be used to remotely manage a computer regardless of the operating system health. It can be used to power on a computer when it’s in soft-off state or to provide enhanced monitoring and security to remote systems.</p>
  711. <p>Once setup, a computer can have up to management connections to MeshCentral. One of them by the Mesh Agent that lives in the operating system and another connection from Intel AMT. When remote management is made using an operating system agent, we call this “in-band management” and when management is done using a hardware based agent like Intel AMT, we call this “out-of-band management”</p>
  712. <p><img alt="" src="images/2022-05-16-23-08-15.png" /></p>
  713. <p>MeshCentral can support computers that have either or both agents. So, you can setup a computer with just the Mesh Agent, just Intel AMT or both. In this document we will show how to install computers with both agent connections or with just Intel AMT. When Intel AMT is used alone, we call this “agent-less” as there will be no operating system software required to remotely manage the computer.</p>
  714. <p>The Mesh Agent and Intel® AMT have very different and complementary capabilities and so, it’s often beneficial to use both and one will offer features the other can’t provide. Here are some of the benefits each has to offer:</p>
  715. <p>Mesh Agent</p>
  716. <ul>
  717. <li>Fast remote desktop / clipboard access.</li>
  718. <li>Remote access to operating system files.</li>
  719. <li>Remote chat and other OS features.</li>
  720. </ul>
  721. <p>Intel® AMT</p>
  722. <ul>
  723. <li>Remote desktop even when the agent or operating system is not functional.</li>
  724. <li>Remote access to BIOS.</li>
  725. <li>Connectivity when soft-off / sleeping.</li>
  726. <li>Remote power actions.</li>
  727. </ul>
  728. <p>If you are looking into managing remote computers that would be difficult to physically get access to for remote support or maintenance, one should probably look at getting a PC with Intel AMT.</p>
  729. <h2 id="bare-metal-activation-server">Bare-Metal Activation Server<a class="headerlink" href="#bare-metal-activation-server" title="Permanent link">&para;</a></h2>
  730. <p>The <code>AmtProvisioningServer</code> section in the <code>settings</code> section of the config.json will enable this feature. MeshCentral will then listen for activation requests, match against your ACM activation certificates and if everything goes well, will activate and add the device to a Intel AMT only device group. No agent or MeshCMD is involved.</p>
  731. <p>This bare-metal activation server is not enabled by default and only makes sense when activating devices on the local network.</p>
  732. <p>Once enabled, Intel AMT can send “hello” data to the MeshCentral provisioning server on port 9971 and MeshCentral will respond by connecting back, authenticating, and activating Intel AMT. MeshCentral will then log the event, add the device to a pre-defined agent-less device group and complete any remaining configuration. A trusted CA certificate is required to perform this operation fully automatically.</p>
  733. <p><img alt="baremetal" src="images/amtprovisioningserver.png" /></p>
  734. <h2 id="meshcentral-group-types">MeshCentral Group Types<a class="headerlink" href="#meshcentral-group-types" title="Permanent link">&para;</a></h2>
  735. <p>Once MeshCentral is installed, a user will typically create a new device group. Here is the first hint that MeshCentral supports Intel AMT. Device groups come in two types. You can manage using a software agent, or using Intel AMT only.</p>
  736. <p><img alt="" src="images/2022-05-16-23-10-40.png" /></p>
  737. <p>Note that if you use the OS agent to manage computers, you can also set and use Intel AMT. However, if you opt to create an Intel AMT only group, then Mesh Agents are not supported. One can create groups of both types in order to manage devices that have and don’t have the Mesh Agent installed.</p>
  738. <p><img alt="" src="images/2022-05-16-23-10-59.png" /></p>
  739. <p>The main benefit of “Intel AMT only” group is if someone does not want to install a background agent on remote systems or already have a remote management solution and intends to only use MeshCentral to supplement the existing solution with Intel AMT features.</p>
  740. <p>Once a group is created, the links MeshCentral provides to on-board devices will change depending on the group type and how the server is setup. The device on-boarding links are located in the “My Devices” page, next to the group name.</p>
  741. <p><img alt="" src="images/2022-05-16-23-11-24.png" /></p>
  742. <p>If the MeshCentral server is setup in “LAN mode” or “Hybrid mode”, options will be available to add computers on the local network. If you have an Intel AMT computer that is already activated, you can select the “Add Local” or “Scan Network” options in the “Intel AMT only” group type and start adding local network computers this way. If MeshCentral is in “WAN mode”, you will need to setup Intel AMT to connect back to MeshCentral using a feature called “Client Initiated Remote Access” or CIRA for short. We will cover that in a later section.</p>
  743. <h2 id="client-initiated-remote-access-mps-server">Client Initiated Remote Access &amp; MPS server<a class="headerlink" href="#client-initiated-remote-access-mps-server" title="Permanent link">&para;</a></h2>
  744. <p>Client Initiated Remote Access (CIRA) is a feature of Intel AMT that, then configured, makes Intel AMT connect back to the server using a TLS tunneling connection similar with a SSH tunnel. Once this tunnel connection is established, the server can perform remote management operations on Intel AMT.</p>
  745. <p>CIRA is great when remotely managing Intel AMT devices over the Internet thru network address translator (NAT) routers where the server would not be able to connect to Intel AMT. This is similar to the Mesh Agent that initiated and keeps an idle connection to the server.</p>
  746. <p>By default, MeshCentral will be configured to receive Mesh Agent connections on TCP port 443 and Intel AMT connections on TCP port 4433. These port values can be configured in the config.json file of MeshCentral.</p>
  747. <p><img alt="" src="images/2022-05-16-23-12-04.png" /></p>
  748. <p>Once connected to port 443, the Mesh agent will using secure HTTPS WebSocket to securely communicate with the server. Intel AMT will use TLS to connect to port 4433 and use a binary tunneling protocol called the Intel AMT Port Forwarding Protocol (APF). You can find documentation on this protocol at the following URL: </p>
  749. <p><a href="https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/HTMLDocuments/MPSDocuments/Intel%20AMT%20Port%20Forwarding%20Protocol%20Reference%20Manual.pdf">https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/HTMLDocuments/MPSDocuments/Intel%20AMT%20Port%20Forwarding%20Protocol%20Reference%20Manual.pdf</a></p>
  750. <p>It’s not necessary to know or understand the details of this protocol, MeshCentral will take care of handling this. In Intel AMT nomenclature, the server that receives a CIRA connection is called a “Management Presence Server” or MPS for short. In other words, MeshCentral has a MPS server on port 4433 ready to receive Intel AMT CIRA connections.</p>
  751. <p><img alt="" src="images/2022-05-16-23-12-37.png" /></p>
  752. <p>When MeshCentral is first setup, a self-signed root certificate is created along with a MPS certificate that will be presented when a device connects on port 4433. There is typically no need to use a CA signed &amp; trusted certificate on port 4433 was we only expect Intel AMT computers to connect to this port and we will be loading our self-signed root in Intel AMT for authentication purposes.</p>
  753. <p>One way to check that the MeshCentral MPS server is running correctly is to use a browser and access port 4433 using HTTPS. The browser will display a warning because the port 4433 certificate is not trusted, but this is expected.</p>
  754. <p><img alt="" src="images/2022-05-16-23-12-58.png" /></p>
  755. <p>The CIRA protocol is binary, but MeshCentral will detect that the request is made from a browser and return a short message:</p>
  756. <div class="highlight"><pre><span></span><code>MeshCentral2 MPS server.
  757. Intel® AMT computers should connect here.
  758. </code></pre></div>
  759. <p>This is practical to make sure connectivity with the MeshCentral MPS server is working. Now that we know the basics of Intel AMT CIRA and the MPS server, we can configure Intel AMT to connect.</p>
  760. <h2 id="activation-certificate-setup">Activation Certificate Setup<a class="headerlink" href="#activation-certificate-setup" title="Permanent link">&para;</a></h2>
  761. <p>If you have an Intel AMT activation certificate, you should configure MeshCentral to take advantage of it. Your activation certificate must have been issued by one of the certificate authorities (CA’s) that is trusted by Intel AMT and MeshCentral will need the entire certificate chain to be provided since the entire chain is needed to perform Intel AMT ACM activation.</p>
  762. <p><img alt="" src="images/2022-05-16-23-13-44.png" /></p>
  763. <p>The leaf certificate will have the Intel AMT activation option and a specific domain name while the hash of the trusted CA certificate must be trusted by Intel AMT. The certificate chain will have to be setup in the domain section of the MeshCentral config.json file.</p>
  764. <p>If you have a certificate chain in a .pfx or .p12 format, place that file in the “meshcentral-data” folder and add the “AmtAcmActivation” section in the domain section like so:</p>
  765. <div class="highlight"><pre><span></span><code><span class="p">{</span>
  766. <span class="w"> </span><span class="nt">&quot;settings&quot;</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
  767. <span class="w"> </span><span class="nt">&quot;Cert&quot;</span><span class="p">:</span><span class="w"> </span><span class="s2">&quot;devbox.mesh.meshcentral.com&quot;</span><span class="p">,</span>
  768. <span class="w"> </span><span class="p">},</span>
  769. <span class="w"> </span><span class="nt">&quot;domains&quot;</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
  770. <span class="w"> </span><span class="nt">&quot;&quot;</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
  771. <span class="w"> </span><span class="nt">&quot;title&quot;</span><span class="p">:</span><span class="w"> </span><span class="s2">&quot;My Server&quot;</span><span class="p">,</span>
  772. <span class="w"> </span><span class="nt">&quot;AmtAcmActivation&quot;</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
  773. <span class="w"> </span><span class="nt">&quot;log&quot;</span><span class="p">:</span><span class="w"> </span><span class="s2">&quot;amtactivation.log&quot;</span><span class="p">,</span>
  774. <span class="w"> </span><span class="nt">&quot;certs&quot;</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
  775. <span class="w"> </span><span class="nt">&quot;myamtcert&quot;</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
  776. <span class="w"> </span><span class="nt">&quot;certpfx&quot;</span><span class="p">:</span><span class="w"> </span><span class="s2">&quot;amtcert.pfx&quot;</span><span class="p">,</span>
  777. <span class="w"> </span><span class="nt">&quot;certpfxpass&quot;</span><span class="p">:</span><span class="w"> </span><span class="s2">&quot;pfxpassword&quot;</span>
  778. <span class="w"> </span><span class="p">}</span>
  779. <span class="w"> </span><span class="p">}</span>
  780. <span class="w"> </span><span class="p">}</span>
  781. <span class="w"> </span><span class="p">}</span>
  782. <span class="p">}</span>
  783. </code></pre></div>
  784. <p>If you have the certificate chain in PEM format as a set of .crt files and a .key file, start by placing all of the certificate files in the “meshcentral-data” folder and setup the certificate chain like this:</p>
  785. <div class="highlight"><pre><span></span><code><span class="p">{</span>
  786. <span class="w"> </span><span class="nt">&quot;settings&quot;</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
  787. <span class="w"> </span><span class="nt">&quot;Cert&quot;</span><span class="p">:</span><span class="w"> </span><span class="s2">&quot;devbox.mesh.meshcentral.com&quot;</span><span class="p">,</span>
  788. <span class="w"> </span><span class="p">},</span>
  789. <span class="w"> </span><span class="nt">&quot;domains&quot;</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
  790. <span class="w"> </span><span class="nt">&quot;&quot;</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
  791. <span class="w"> </span><span class="nt">&quot;title&quot;</span><span class="p">:</span><span class="w"> </span><span class="s2">&quot;My Server&quot;</span><span class="p">,</span>
  792. <span class="w"> </span><span class="nt">&quot;AmtAcmActivation&quot;</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
  793. <span class="w"> </span><span class="nt">&quot;log&quot;</span><span class="p">:</span><span class="w"> </span><span class="s2">&quot;amtactivation.log&quot;</span><span class="p">,</span>
  794. <span class="w"> </span><span class="nt">&quot;certs&quot;</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
  795. <span class="w"> </span><span class="nt">&quot;myvprocert&quot;</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
  796. <span class="w"> </span><span class="nt">&quot;certfiles&quot;</span><span class="p">:</span><span class="w"> </span><span class="p">[</span><span class="w"> </span><span class="s2">&quot;amtacm-vprodemo.crt&quot;</span><span class="p">,</span>
  797. <span class="w"> </span><span class="s2">&quot;amtacm-intermediate1.crt&quot;</span><span class="p">,</span>
  798. <span class="w"> </span><span class="s2">&quot;amtacm-intermediate2.crt&quot;</span><span class="p">,</span>
  799. <span class="w"> </span><span class="s2">&quot;amtacm-root.crt&quot;</span><span class="w"> </span><span class="p">],</span>
  800. <span class="w"> </span><span class="nt">&quot;keyfile&quot;</span><span class="p">:</span><span class="w"> </span><span class="s2">&quot;amtacm-vprodemo.key&quot;</span>
  801. <span class="w"> </span><span class="p">}</span>
  802. <span class="w"> </span><span class="p">}</span>
  803. <span class="w"> </span><span class="p">}</span>
  804. <span class="w"> </span><span class="p">}</span>
  805. <span class="p">}</span>
  806. </code></pre></div>
  807. <p>It’s important that the leaf certificate file be the first file in the “certfiles” array. The order of the other certificates is not important as MeshCentral will figure out and re-order them correctly. </p>
  808. <p>Within the new “AmtAcmActivation” section, there is a “log” entry. This is a log file that will contain every activation attempt including the details of the computer being activation and what Intel AMT administrator password was used for activation. This log file should be kept securely as it will contain Intel AMT credentials. It’s also important to have this file as a backup so that Intel AMT credentials are not lost after activation. If MeshCentral can’t write to this log, the activation will not go forward and will fail.</p>
  809. <p>Once the config.json was modified, restart the server. There will be two indications that the server has the new certificate correctly configured. For “Intel AMT only” groups, a new “Activation” link will show up. Clicking this link will show a command that can be run to perform ACM activation.</p>
  810. <p><img alt="" src="images/2022-05-16-23-14-42.png" /></p>
  811. <p>For device groups that operate with a Mesh Agent, you can edit the group and select the “Simple Admin Control Mode” Intel AMT activation policy. This policy is not available unless a correct Intel AMT ACM activation certificate is configured.</p>
  812. <p><img alt="" src="images/2022-05-16-23-15-04.png" /></p>
  813. <p>Once setup, Intel AMT will not automatically activate to Intel AMT unless the right situation is met. The Intel AMT activation certificate is for a specific domain name suffix, for example “meshcentral.com”. Intel AMT must be in a situation where this domain can be accepted. One of the following must be true:</p>
  814. <ul>
  815. <li>Intel AMT must have a wired Ethernet interface that is connected to a local network with a DHCP server responding with option 15 set to “xxx.meshcentral.com”.</li>
  816. <li>The name “meshcentral.com” by have been set as “Trusted FQDN” in MEBx.</li>
  817. <li>The name “meshcentral.com” must have been set using a USB key with a setup.bin file.</li>
  818. </ul>
  819. <div class="video-wrapper">
  820. <iframe width="320" height="180" src="https://www.youtube.com/embed/mhq0bsWJEOw" frameborder="0" allowfullscreen></iframe>
  821. </div>
  822. <p>Once Intel AMT is in a situation where ACM activation can occur, the activation command line can be run or the Mesh Agent will detect this situation and ask the server to perform activation.</p>
  823. <p><img alt="" src="images/2022-05-16-23-16-05.png" /></p>
  824. <p>The best way to test this feature is to create an “Intel AMT only” device group and run the MeshCMD command on the remote system to perform activation. If there is a problem, this process should clearly display why ACM activation fails.</p>
  825. <div class="admonition note">
  826. <p class="admonition-title">Note</p>
  827. </div>
  828. <p>Activation over wifi has some additional issues.<br>
  829. First you need to add your WiFi access point to that wifi configuration to allow CSME to take over WiFi when OS is not functioning. Then it should work.<br>
  830. Please also make sure you install Intel WiFi driver and Intel LMS package. It should work. You can detach the ethernet and then try connecting to that device using the IP address acquired by WiFi interface.
  831. See <a href="https://www.intel.com/content/www/us/en/developer/topic-technology/edge-5g/tools/open-amt-cloud-toolkit.html">Open AMT Cloud Toolkit</a> project - a close relative to this project. It has an AMT activation component and newer remote provisioning client can activate locally and also can manage Wi-Fi profile.</p>
  832. <h2 id="intel-amt-mei-and-lms">Intel AMT MEI and LMS<a class="headerlink" href="#intel-amt-mei-and-lms" title="Permanent link">&para;</a></h2>
  833. <p>Intel Active Management Technology (Intel AMT) can communicate to the local platform using the Management Engine Interface (MEI). We show how your can use that to get Intel AMT information. For more advanced usages, you need to connect using TCP and TLS which requires Intel Local Manageability Service (LMS). We show how MeshCentral's Mesh Agent and MeshCMD have a small version of LMS built-in and how it works</p>
  834. <div class="video-wrapper">
  835. <iframe width="320" height="180" src="https://www.youtube.com/embed/mStyhe-fSC0" frameborder="0" allowfullscreen></iframe>
  836. </div>
  837. <h2 id="intel-amt-system-defense">Intel AMT System Defense<a class="headerlink" href="#intel-amt-system-defense" title="Permanent link">&para;</a></h2>
  838. <p>As part of Intel AMT there are hardware filters in the network interface you can setup to match and perform actions on packets. This happens at Ethernet speeds with no slow down and independent of the OS.</p>
  839. <div class="video-wrapper">
  840. <iframe width="320" height="180" src="https://www.youtube.com/embed/q7RyboI4uew" frameborder="0" allowfullscreen></iframe>
  841. </div>
  842. </article>
  843. </div>
  844. <script>var target=document.getElementById(location.hash.slice(1));target&&target.name&&(target.checked=target.name.startsWith("__tabbed_"))</script>
  845. </div>
  846. <button type="button" class="md-top md-icon" data-md-component="top" hidden>
  847. <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M13 20h-2V8l-5.5 5.5-1.42-1.42L12 4.16l7.92 7.92-1.42 1.42L13 8z"/></svg>
  848. Back to top
  849. </button>
  850. </main>
  851. <footer class="md-footer">
  852. <div class="md-footer-meta md-typeset">
  853. <div class="md-footer-meta__inner md-grid">
  854. <div class="md-copyright">
  855. </div>
  856. </div>
  857. </div>
  858. </footer>
  859. </div>
  860. <div class="md-dialog" data-md-component="dialog">
  861. <div class="md-dialog__inner md-typeset"></div>
  862. </div>
  863. <script id="__config" type="application/json">{"base": "..", "features": ["navigation.tabs", "navigation.expand", "navigation.top", "navigation.instant"], "search": "../assets/javascripts/workers/search.6ce7567c.min.js", "translations": {"clipboard.copied": "Copied to clipboard", "clipboard.copy": "Copy to clipboard", "search.result.more.one": "1 more on this page", "search.result.more.other": "# more on this page", "search.result.none": "No matching documents", "search.result.one": "1 matching document", "search.result.other": "# matching documents", "search.result.placeholder": "Type to start searching", "search.result.term.missing": "Missing", "select.version": "Select version"}}</script>
  864. <script src="../assets/javascripts/bundle.525ec568.min.js"></script>
  865. </body>
  866. </html>