Unsolved
27 Posts
0
1741
September 27th, 2020 21:00
R630 & R620 - Intel Management Engine (ME) questions
We would like to obtain more information about operation and purpose of Intel ME on R630 and R620 servers. There is no documentation or specific drivers for Intel ME interfaces publicly present for those models, which imply various questions regarding its presence on the system.
1. Is Intel ME operable on those models?
2. In case it's operable, what is its exact purpose on those models? As far as I know, iDRAC is a completely independent platform and they don't depend on each other nor share anything in common. CPU power management does not require Intel ME. Dell BIOS does not require Intel ME.
We weren't able to make publicly available Intel ME drivers to work on Windows 2012 R2 on both models in order to communicate with Intel ME via the Intel ME System Tools toolset, trying its every version from 7 to 11.
There are Intel C600/X79 Series Chipset and Intel C610 Series Chipset drivers that make Intel Management Interface devices to appear in Windows Device Manager, but their versions are reported as 0.0.0.1 and they appear as hidden devices. A tool 'MEInfo' is not able to communicate with Intel ME through those interfaces using the driver included in the chipset package, which means it's inoperable or it's operable but has configured to drop the OS communication channel after leaving Non-production Mode.
C:\Intel ME System Tools v9.5 r6\MEInfo\WIN64> MEInfoWin64.exe
Intel(R) MEInfo Version: 9.5.35.1850 Copyright(C) 2005 - 2014, Intel Corporation. All rights reserved. Error 9256: Communication error between application and Intel(R) ME module (FW U pdate client) Error 9256: Communication error between application and Intel(R) ME module (FW U pdate client) Error 9256: Communication error between application and Intel(R) ME module (FW U pdate client) Error 9256: Communication error between application and Intel(R) ME module (FW U pdate client) Error 9459: Internal error (Could not determine FW features information) C:\Intel ME System Tools v9.5 r6\MEInfo\WIN64>


Dell-Stephane T
11 Legend
•
3.7K Posts
0
September 28th, 2020 01:00
Hello,
I don't know this Intel Me tool at all. So I let the community answer your post by sharing their experience.
If you want to monitor your servers I can only advise you to use Openmanage Enterprise. I am at your disposal if you need more information/documentation on this subject.
Regards,
timsxv
27 Posts
0
September 28th, 2020 04:00
Thanks for a reply, but please note that I am not asking about a particular tool, nor seeking any advice about managing the servers.
This serves exclusively for a security assessment part of our project due to Intel ME security concerns and related vulnerabilities, so we would like to hear from someone in Dell who has information on chipset manufacturing stages of those servers (because the Intel ME subsystem is a part of the chipset) so we can make some conclusions for our project, thus in the first place would be excellent to have these 2 basic questions answered at least:
1. Is Intel ME operable on those models?
2. In case it's operable, what is its exact purpose on those models?
Dell-Stephane T
11 Legend
•
3.7K Posts
0
September 28th, 2020 04:00
Ok, I'll check if any internal specialist could provide me an answer.
Have a good day.
Dell-Stephane T
11 Legend
•
3.7K Posts
0
September 30th, 2020 07:00
Hi,
Here is the reply from my specialist :
Here is the link to the Intel community : https://community.intel.com/?profile.language=en
Best regards,
timsxv
27 Posts
0
September 30th, 2020 08:00
Thank you, but unfortunately none of the answers is a direct response to any of my questions.
1. Please note that I am involved in publicly known research projects about Intel ME and have advanced understanding on how it works, that's why I wasn't asking about what is Intel ME. The definition provided by your specialist is quite misleading, because Intel ME is not on the CPU nor it can be called a "feature". Intel ME is an independent subsystem (Unix-based operating system) that is a part of the chipset, depending on the model. A more precise description can be found on wikipedia, because Intel usually don't provide good description or specific information for Intel ME publicly:
2. This is obviously the irrelevant information as well. I was asking about the purpose of it on the particular Dell server models and not its features completely unrelated to this server. The features described in the Intel document are more relevant to the Dell laptops.
- Intel ME does not provide OOB on the R630 and R620 because it is done by iDRAC.
- There is no Anti-Theft protection on R620 & R630, nor PAVP nor CLS. These features are mainly used and enabled on laptops with vPro.
- All the essential Intel ME functions are executed by iDRAC on PowerEdge servers, not by Intel ME.
- Each Intel ME configuration depends on the OEM, not Intel. Dell has confidential documents and a configurable Intel ME firmware that was provided to them during the manufacturing stage by Intel, which is fully modificable uring the manufacturing mode, where numerous Intel ME features can be disabled or enabled.
3. The vendor of these tools (Intel) is not responsible for how the OEM has configured MEI, because the end configuration is fully made by the OEM and not by Intel.
I hope you are aware that Intel ME can be configured in a way of preventing to be accessed from the OS, which is done during the OEM manufacturing stage as well. I can provide you with Intel ME confidential documents that provide more technical information for OEMs and their options, in case you are unaware of how Dell manages Intel ME.
If you can't reach someone who could provide technical information on the Intel ME on those models please let me know so we can try contacting Dell directly via official channels. We don't think this is the information Dell should keep in secret from its customers because of the privacy and security concerns, because security through obscurity is the worst way of deploying solutions.
Dell-Stephane T
11 Legend
•
3.7K Posts
0
October 5th, 2020 02:00
Hi Tim,
Thank you for explaining more about the information you are looking for.
Technical support does not have access to such detailed technical information and it cannot be released publicly on Dell EMC Community Forum.
We’d like to discuss this further via Private Message so that we can explain what you can do to request such information.
We’ll be in touch shortly.
Kind regards,