﻿﻿FILE NAME:    iLO5_233.bin
TITLE:        iLO 5 firmware v2.33

LANGUAGE:  English

DIVISIONS:  Systems

PRODUCTS AFFECTED:
  	HPE ProLiant BL460c Gen10 Server 
	HPE ProLiant DL580 Gen10 Server 
	HPE ProLiant DL560 Gen10 Server 
	HPE ProLiant DL385 Gen10 Plus Server 
	HPE ProLiant DL385 Gen10 Server 
	HPE ProLiant DL380 Gen10 Server 
	HPE ProLiant DL360 Gen10 Server 
	HPE ProLiant DL325 Gen10 Plus Server
	HPE ProLiant DL325 Gen10 Server 
	HPE ProLiant DL180 Gen10 Server 
	HPE ProLiant DL160 Gen10 Server 
	HPE ProLiant DL120 Gen10 Server 
	HPE ProLiant DL20 Gen10 Server 
	HPE ProLiant ML350 Gen10 Server 
	HPE ProLiant ML110 Gen10 Server 
	HPE ProLiant ML30 Gen10 Server 
	HPE ProLiant XL450 Gen10 Server 
	HPE ProLiant XL420 Gen10 Server 
	HPE Proliant XL270d Gen10 Server 
	HPE ProLiant XL230k Gen10 Server 
	HPE ProLiant XL190r Gen10 Server 
	HPE ProLiant XL170r Gen10 Server 
	HPE ProLiant XL675d Gen10 Plus Server
	HPE Apollo XL225n Gen10 Plus
	HPE Apollo r2800 Gen10 24 SFF Flexible Configure-to-order Chassis 
	HPE Apollo r2600 Gen10 24 SFF Premium Configure-to-order Chassis 
	HPE Apollo r2200 Gen10 12 LFF Configure-to-order Chassis 
	HPE Apollo 4510 Gen10 Server 
	HPE Apollo 4200 Gen10 Server
	HPE Apollo 6500 Gen10 Plus Server 
	HPE Synergy 660 Gen10 Compute Module 
   	HPE Synergy 480 Gen10 Compute Module

	
THIS VERSION VALIDATED WITH:
  	Microsoft Windows Server 2019 	
	Microsoft Windows Server 2016 	
	Microsoft Windows Server 2012 R2	
	Red Hat Enterprise Linux 8 Server 	
	Red Hat Enterprise Linux 7 Server 	
	SUSE Linux Enterprise Server 15 	
	SUSE Linux Enterprise Server 12 	
	VMware ESXi 7.0
	VMware ESXi 6.7
	VMware ESXi 6.5



PREREQUISITE:  N/A

BUILD DATE:  	 December 09, 2020
EFFECTIVE DATE:  December 18, 2020

DESCRIPTION:   Firmware for the Hewlett Packard Enterprise
               Integrated Lights-Out 5 Management Controller
			   
LAST RECOMMENDED OR CRITICAL VERSION: 2.31 

PREVIOUS VERSION: 2.31

UPGRADE REQUIREMENTS: CRITICAL 

UPGRADING FROM A PREVIOUS VERSION OF iLO
 
- Upgrading to iLO 5 version 2.33 is supported on servers with iLO 5 1.48 or later installed. 
- On servers with an earlier version of iLO 5 installed, you must first install iLO 5 1.48, 
  and then install iLO 5 2.33. For example, if a server has iLO 5 1.10 installed, install iLO 5 
  1.48, and then install iLO 5 2.33. 

FIRMWARE DEPENDENCY:

  Hewlett Packard Enterprise recommends the following or greater versions of iLO utilities
  for best performance:
  
  - RESTful Interface Tool (iLOREST) 3.0
  - HPQLOCFG v5.2
  - Lights-Out XML Scripting Sample bundle 5.20.0 or later
  - HPONCFG Windows 5.3.0
  - HPONCFG Linux 5.5.0 or later
  - LOCFG v5.20.0 or later
  - HPLOMIG 5.2.0

  NOTE: Updated utilities and system libraries are required to support the iLO 
  High Security, FIPS, and CNSA security states.

KNOWN ISSUES:

 - To connect to the iLO Service Port with a USB Ethernet adapter, you must use a USB 2.0 device 
   that is based on the AX88772 series chipset from ASIX Electronics Corporation. Hewlett
   Packard Enterprise recommends the HPE USB to Ethernet Adapter (part number Q7Y55A).
 - The server must be powered off when you update the Server Platform Services (SPS) Firmware or 
   the Innovation Engine (IE) Firmware. After powering off the server, wait 30 seconds before 
   initiating an SPS or IE firmware update.
 - With the release of iLO 5, some features in the iLO web interface are not supported by RIBCL or 
   the CLI. Instead, HPE recommends the use of the iLO RESTful API, particularly for setting the iLO 
   security state and configuring extended user privileges. The iLO RESTful API is the preferred 
   programmatic interface for Gen10 and later systems. The preferred CLI and scripting tool is the 
   RESTful Interface Tool (iLOREST).
 - Starting with iLO 5 1.20, SNMP settings are not backward compatible with older iLO firmware 
   versions. The SNMP settings are discarded when you downgrade the firmware to an earlier version.
 - When you start the iLO web interface, and then you launch the HTML5 IRC, these interfaces are 
   counted as a single iLO session. This behavior is different from the .NET IRC and the Java IRC, 
   which are separate sessions from the iLO web interface. The Idle Connection Timeout specifies how 
   long a session can be inactive before it ends automatically. If you start a virtual media operation 
   (such as an OS installation), and the Idle Connection Timeout is reached, the HTML5 IRC and the iLO 
   web interface close automatically, and the virtual media operation is interrupted. To avoid this issue, 
   you can set the Idle Connection Timeout to a longer value, use a different remote console, or make sure
   that the session is not idle during the virtual media operation.
 - To support power usage reporting and optimum server thermal fan control on Linux servers with NVIDIA 
   GPU option cards: Blacklist the nouveau video driver, and then load the NVIDIA GPU driver in persistent
   mode by entering the following command: nvidia-smi -pm 1
-  On certain HPE Mellanox adapters that support dual port personality (InfiniBand/Ethernet), the port
   personality gets reset to the default value during an adapter firmware update.

       o        For more information, see the document a00068199en_us on the Hewlett Packard Enterprise Support Center webpage: 
                https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00068199en_us.

       o        The document lists iLO 5 1.48 as the minimum version to install before an adapter firmware update. However, iLO 5 1.48
                or later is required before updating to iLO 5 2.33 or later.



FIXES:
- Error when a user with Read-only role tries to change the password of own account.
- Resetting iLO to default security state i.e. ‘Production’ via hponcfg /reset command fails when iLO is in ‘High Security’ state and ‘Require Host Authentication’ (RHA) is disabled.
- Fixed potential security vulnerability CVE-2020-27337 in network stack. To know more about the Security Vulnerabilities, visit: https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbhf04070en_us

SECURITY FIXES:
 
  For information about the latest security bulletins and vulnerabilities addressed in this version, 
  see the following website: https://support.hpe.com/hpesc/public/home.

Security best practices:

  For the latest information about security best practices, see the HPE Integrated Lights-Out Security 
  Technology Brief at the following website: http://www.hpe.com/support/ilo-docs.


ENHANCEMENTS:
- Added IPMI lan6 commands support
- Added ability to view DIMM serial numbers through iLO GUI and redfish API
- iLO Security logs are now listed in Operating System logs
- Added ability to change serial Interface configuration using standard redfish schema 
- Added iLO hostname as part of redfish event header 
- Enhancement to support Power regulation on AMD servers
- Power meter data shown in GUI and IPMI CLI has been extended for 1 week
- Limiting fan speed decrease rate to reduce fan noise. Supported on DL380 Gen10 platform with System ROM U30 v2.40 (10/26/2020) or later
- Filtering spurious temperature readings for thermal control. Supported on DL380 Gen10 platform with System ROM U30 v2.40 (10/26/2020) or later
- Enhanced to avoid BMC reset during system POST
- Option to delete LDAP CA certificate and import CA Certificate of public key larger than 4096 bits (8192 bits, 16352 bits)
- Banner to be displayed at the SSH login
- Support enabled for the below controllers on DL385 and DL325 Gen10Plus servers
	HPE InfiniBand HDR/Ethernet 200Gb 2-port QSFP56 PCIe4 x16 MCX653106A-HDAT Adapter 
	HPE InfiniBand HDR/Ethernet 200Gb 1-port QSFP56 PCIe4 x16 OCP3 MCX653435A-HDAI Adapter
	HPE InfiniBand HDR/Ethernet 200Gb 2-port QSFP56 PCIe4 x16 OCP3 MCX653436A-HDAI Adapter
- Enabled support of DCi on Open Adapters
- Enabled support for below GPUs: 
	Xilinx Alveo U50 Accelerator 
	Xilinx Alveo U250 Accelerator 
	Support enabled for updating the FPGA, CEC Firmware of NVIDIA A100 HGX x8 GPU Air FIO Baseboard through OOB (Out of Band) mechanism
	Support enabled for disabling write protect for updating GPU, NVSwitch Firmware of NVIDIA A100 HGX x8 GPU Air Cooled Baseboard from host operating system
	Support enabled for updating the RMI-Remote Management Interface Firmware of AMD Instinct MI100 PCIE Accelerator through OOB (Out of Band) mechanism


SUPPORT:

1.  iLO 5 firmware updates and utilities can be found here:

      https://www.hpe.com/support/iLO5

2. IPv6 network communications
     Supported Networking Features
		IPv6 Over Shared Network Port Connections
                IPv6 Static Address Assignment
                IPv6 SLAAC Address Assignment
                IPv6 Static Route Assignment
                IPv6 Static Default Gateway Entry
                DHCPv6 Stateful Address Assignment
                DHCPv6 Stateless DNS, Domain Name, and NTP Configuration
                Integrated Remote Console
                OA Single Sign-On
                HPE Single Sign-On
                Web Server
                SSH Server
                SNTP Client
                DDNS Client
                RIBCL over IPv6
                SNMP
                AlertMail
                Remote Syslog
                WinDBG Support
                HPQLOCFG/HPLOMIG over an IPv6 connection
                URL-based Virtual Media
                CLI/RIBCL Key Import over IPv6
                Authentication using LDAP and Kerberos over IPv6
                iLO Federation
                IPMI
                Embedded remote support
     Networking Features not supported by IPv6 in this release 
                NETBIOS-WINS
                Key managers
                
3. You might encounter a "data inconsistency error" when you use iLO Federation
   Management. This error occurs when an iLO on your network is not 
   responding correctly. Use the data on the Multi-System map page to 
   troubleshoot data inconsistency errors.

DOCUMENTATION -

1.  iLO 5 documentation is available at https://www.hpe.com/support/ilo-docs.

2.  Check the online help for information about how to use iLO. To access the 
    online help, Click the question mark icon in the upper right corner of 
    any iLO web interface page.

HOW TO USE -

1.  Download the iLO 5 Online Firmware Update Component for your
    operating system.

2.  Install the firmware using one of these options:
i
    a) Run the component on the host to be updated.
       The component will update the iLO 5 firmware and reset the iLO processor.

    b) Extract the firmware from the component. This will place the firmware
       image file, iLO5_yyy.bin (where yyy represents the firmware version), in
       the target directory.  You can use the following methods to install firmware:

       i) Login to iLO, navigate to the Flash Firmware page, and update the
          firmware from there.

       ii) Use the iLO RESTful API or ILOREST. For more information, see the 
           following website: http://www.hpe.com/support/restfulinterface/docs.

       iii) Use the Lights-Out Configuration Utility (HPQLOCFG) and RIBCL/XML
            scripts to update iLO 5 across the network.

       iv) Use the Online Lights-Out Configuration utility (HPONCFG) and
           RIBCL/XML scripts to update iLO 5 from the supported host OS.

3.  iLO automatically resets after a successful update.
    There is no need to manually reset iLO.

Copyright 2002,2021 Hewlett Packard Enterprise Development, LP
