Unsolved

27 Posts

1741

September 27th, 2020 21:00

R630 & R620 - Intel Management Engine (ME) questions

We would like to obtain more information about operation and purpose of Intel ME on R630 and R620 servers. There is no documentation or specific drivers for Intel ME interfaces publicly present for those models, which imply various questions regarding its presence on the system.

1. Is Intel ME operable on those models?

2. In case it's operable, what is its exact purpose on those models? As far as I know, iDRAC is a completely independent platform and they don't depend on each other nor share anything in common. CPU power management does not require Intel ME. Dell BIOS does not require Intel ME.

We weren't able to make publicly available Intel ME drivers to work on Windows 2012 R2 on both models in order to communicate with Intel ME via the Intel ME System Tools toolset, trying its every version from 7 to 11.

There are Intel C600/X79 Series Chipset and Intel C610 Series Chipset drivers that make Intel Management Interface devices to appear in Windows Device Manager, but their versions are reported as 0.0.0.1 and they appear as hidden devices. A tool 'MEInfo' is not able to communicate with Intel ME through those interfaces using the driver included in the chipset package, which means it's inoperable or it's operable but has configured to drop the OS communication channel after leaving Non-production Mode.

C:\Intel ME System Tools v9.5 r6\MEInfo\WIN64> MEInfoWin64.exe
Intel(R) MEInfo Version: 9.5.35.1850 Copyright(C) 2005 - 2014, Intel Corporation. All rights reserved. Error 9256: Communication error between application and Intel(R) ME module (FW U pdate client) Error 9256: Communication error between application and Intel(R) ME module (FW U pdate client) Error 9256: Communication error between application and Intel(R) ME module (FW U pdate client) Error 9256: Communication error between application and Intel(R) ME module (FW U pdate client) Error 9459: Internal error (Could not determine FW features information) C:\Intel ME System Tools v9.5 r6\MEInfo\WIN64>

11 Legend

 • 

3.7K Posts

September 28th, 2020 01:00

Hello,

 

I don't know this Intel Me tool at all. So I let the community answer your post by sharing their experience.
If you want to monitor your servers I can only advise you to use Openmanage Enterprise. I am at your disposal if you need more information/documentation on this subject.

 

Regards,

27 Posts

September 28th, 2020 04:00

Thanks for a reply, but please note that I am not asking about a particular tool, nor seeking any advice about managing the servers.

This serves exclusively for a security assessment part of our project due to Intel ME  security concerns and related vulnerabilities, so we would like to hear from someone in Dell who has information on chipset manufacturing stages of those servers (because the Intel ME subsystem is a part of the chipset) so we can make some conclusions for our project, thus in the first place would be excellent to have these 2 basic questions answered at least:

1. Is Intel ME operable on those models?

2. In case it's operable, what is its exact purpose on those models? 

11 Legend

 • 

3.7K Posts

September 28th, 2020 04:00

Ok, I'll check if any internal specialist could provide me an answer.

 

Have a good day.

11 Legend

 • 

3.7K Posts

September 30th, 2020 07:00

Hi,

 

Here is the reply from my specialist :

 

  1. Intel ME is on the cpu and not on the server model. It is a feature that us built into the cpu and has been on almost all chips from intel since 2008. This would not be limited to the server model that the cpu is installed in.

  2. This is the purpose of the Intel ME- https://www.intel.com/content/www/us/en/support/articles/000008927/software/chipset-software.html   
             
  3. IIf you are attempting to use the Intel ME System Tools toolset and is having issues it would be recommended that he reach out to the vendor for these tools.

Here is the link to the Intel community : https://community.intel.com/?profile.language=en

 

Best regards,

27 Posts

September 30th, 2020 08:00

Thank you, but unfortunately none of the answers is a direct response to any of my questions.

1. Please note that I am involved in publicly known research projects about Intel ME and have advanced understanding on how it works, that's why I wasn't asking about what is Intel ME. The definition provided by your specialist is quite misleading, because Intel ME is not on the CPU nor it can be called a "feature". Intel ME is an independent subsystem (Unix-based operating system) that is a part of the chipset, depending on the model. A more precise description can be found on wikipedia, because Intel usually don't provide good description or specific information for Intel ME publicly:

The Intel Management Engine (ME), also known as the Intel Manageability Engine, is an autonomous subsystem that has been incorporated in virtually all of Intel's processor chipsets since 2008. 
It is located in the Platform Controller Hub of modern Intel motherboards.

2. This is obviously the irrelevant information as well. I was asking about the purpose of it on the particular Dell server models and not its features completely unrelated to this server. The features described in the Intel document are more relevant to the Dell laptops.

- Intel ME does not provide OOB on the R630 and R620 because it is done by iDRAC.

- There is no Anti-Theft protection on R620 & R630, nor PAVP nor CLS. These features are mainly used and enabled on laptops with vPro.

- All the essential Intel ME functions are executed by iDRAC on PowerEdge servers, not by Intel ME.

- Each Intel ME configuration depends on the OEM, not Intel. Dell has confidential documents and a configurable Intel ME firmware that was provided to them during the manufacturing stage by Intel, which is fully modificable uring the manufacturing mode, where numerous Intel ME features can be disabled or enabled.

3. The vendor of these tools (Intel) is not responsible for how the OEM has configured MEI, because the end configuration is fully made by the OEM and not by Intel.

I hope you are aware that Intel ME can be configured in a way of preventing to be accessed from the OS, which is done during the OEM manufacturing stage as well. I can provide you with Intel ME confidential documents that provide more technical information for OEMs and their options, in case you are unaware of how Dell manages Intel ME.

If you can't reach someone who could provide technical information on the Intel ME on those models please let me know so we can try contacting Dell directly via official channels. We don't think this is the information Dell should keep in secret from its customers because of the privacy and security concerns, because security through obscurity is the worst way of deploying solutions.

11 Legend

 • 

3.7K Posts

October 5th, 2020 02:00

Hi Tim,

 

Thank you for explaining more about the information you are looking for.

Technical support does not have access to such detailed technical information and it cannot be released publicly on Dell EMC Community Forum.

 

We’d like to discuss this further via Private Message so that we can explain what you can do to request such information.

 

We’ll be in touch shortly.

 

Kind regards,

No Events found!

Top