Holger,
Thanks for your suggestions. I am going to set up
the user and try to connect. In te meantime this is
the output with "-C 2" along with the ethereal trace
attached.
Using "-C 0" completes the authentication phase
succesfully, but when executing the ipmi command, BMC
responds with an error, reported as "Error sending
Chassis Status command: Invalid command" by ipmitool.
/Oscar
[***@localhost ipmitool-1.8.1.orig]# ipmitool -I
lanplus -H 10.5.99.135 -P patula chassis status -vvv
-o intelplus -C 2
IPMI LAN host 10.5.99.135 port 623
Post by H***@fujitsu-siemens.comSending IPMI command payload
netfn : 0x06
command : 0x38
data : 0x8e 0x04
BUILDING A v1.5 COMMAND
Post by H***@fujitsu-siemens.comIPMI Request Session Header
Authtype : NONE
Sequence : 0x00000000
Session ID : 0x00000000
IPMI Request Message Header
Rs Addr : 20
NetFn : 06
Rs LUN : 0
Rq Addr : 81
Rq Seq : 00
Rq Lun : 0
Command : 38
sending packet (23 bytes)
06 00 ff 07 00 00 00 00 00 00 00 00 00 09 20 18
c8 81 00 38 8e 04 b5
<< Received data (30 bytes)
06 00 ff 07 00 00 00 00 00 00 00 00 00 10 81 1c
63 20 00 38 00 01 84 0e 03 00 00 00 00 12
<< IPMI Response Session Header
<< Authtype : NONE
<< Payload type : IPMI (0)
<< Session ID : 0x00000000
<< Sequence : 0x00000000
<< IPMI Msg/Payload Length : 16
<< IPMI Response Message Header
<< Rq Addr : 81
<< NetFn : 07
<< Rq LUN : 0
<< Rs Addr : 20
<< Rq Seq : 00
<< Rs Lun : 0
<< Command : 38
<< Compl Code : 0x00
Post by H***@fujitsu-siemens.comSENDING AN OPEN SESSION REQUEST
sending packet (48 bytes)
06 00 ff 07 06 10 00 00 00 00 00 00 00 00 20 00
00 00 00 00 a4 a3 a2 a0 00 00 00 08 01 00 00 00
01 00 00 08 01 00 00 00 02 00 00 08 00 00 00 00
<< Received data (52 bytes)
06 00 ff 07 06 11 00 00 00 00 00 00 00 00 24 00
00 00 00 00 a4 a3 a2 a0 4a 8f 0d 05 00 00 00 08
01 00 00 00 01 00 00 08 01 00 00 00 02 00 00 08
00 00 00 00
<<OPEN SESSION RESPONSE
<< Message tag : 0x00
<< RMCP+ status : no errors
<< Maximum privilege level : Unknown
(0x00)
<< Console Session ID : 0xa0a2a3a4
<< BMC Session ID : 0x050d8f4a
<< Negotiated authenticatin algorithm : hmac_sha1
<< Negotiated integrity algorithm : hmac_sha1_96
<< Negotiated encryption algorithm : none
Post by H***@fujitsu-siemens.comConsole generated random number (16 bytes)
59 f1 8a ea 6b f4 e3 f7 58 dd 6c 83 a4 9e ac 5d
Post by H***@fujitsu-siemens.comSENDING A RAKP 1 MESSAGE
sending packet (44 bytes)
06 00 ff 07 06 12 00 00 00 00 00 00 00 00 1c 00
00 00 00 00 4a 8f 0d 05 59 f1 8a ea 6b f4 e3 f7
58 dd 6c 83 a4 9e ac 5d 14 00 00 00
<< Received data (76 bytes)
06 00 ff 07 06 13 00 00 00 00 00 00 00 00 3c 00
00 00 00 00 a4 a3 a2 a0 11 38 c7 a0 2d 9f 16 ac
11 61 aa eb d7 34 8e dc ff ff ff ff ff ff ff ff
ff ff ff ff ff ff ff ff 9c da e6 05 51 97 a2 b0
3e 29 06 86 f5 f9 d1 13 72 31 18 43
<<RAKP 2 MESSAGE
<< Message tag : 0x00
<< RMCP+ status : no errors
<< Console Session ID : 0xa0a2a3a4
<< BMC random number :
0x1138c7a02d9f16ac1161aaebd7348edc
<< BMC GUID :
0xffffffffffffffffffffffffffffffff
<< Key exchange auth code [sha1] :
0x9cdae6055197a2b03e290686f5f9d11372311843
bmc_rand (16 bytes)
11 38 c7 a0 2d 9f 16 ac 11 61 aa eb d7 34 8e dc
Post by H***@fujitsu-siemens.comrakp2 mac input buffer (58 bytes)
a4 a3 a2 a0 4a 8f 0d 05 59 f1 8a ea 6b f4 e3 f7
58 dd 6c 83 a4 9e ac 5d 11 38 c7 a0 2d 9f 16 ac
11 61 aa eb d7 34 8e dc ff ff ff ff ff ff ff ff
ff ff ff ff ff ff ff ff 14 00
70 61 74 75 6c 61 00 00 00 00 00 00 00 00 00 00
00 00 00 00
Post by H***@fujitsu-siemens.comrakp2 mac as computed by the remote console (20
bytes)
9c da e6 05 51 97 a2 b0 3e 29 06 86 f5 f9 d1 13
72 31 18 43
Post by H***@fujitsu-siemens.comrakp3 mac input buffer (22 bytes)
11 38 c7 a0 2d 9f 16 ac 11 61 aa eb d7 34 8e dc
a4 a3 a2 a0 04 00
70 61 74 75 6c 61 00 00 00 00 00 00 00 00 00 00
00 00 00 00
generated rakp3 mac (20 bytes)
49 62 e5 f4 5c 28 9e 81 32 c7 11 eb 2c dc ef b8
02 3f cb e7
session integrity key input (34 bytes)
59 f1 8a ea 6b f4 e3 f7 58 dd 6c 83 a4 9e ac 5d
11 38 c7 a0 2d 9f 16 ac 11 61 aa eb d7 34 8e dc
14 00
Generated session integrity key (20 bytes)
49 2c ac 02 18 81 95 c5 4e ec 75 f7 3a 69 13 c6
1a a6 7f 39
Generated K1 (20 bytes)
6c 4d 64 2f 75 38 29 32 4f a6 2a 02 d8 01 c4 eb
7a 5e 61 07
Generated K2 (20 bytes)
75 ee 57 5d 85 e2 d6 12 4b 82 ec b7 34 c5 c3 77
3e 48 93 03
Post by H***@fujitsu-siemens.comSENDING A RAKP 3 MESSAGE
sending packet (44 bytes)
06 00 ff 07 06 14 00 00 00 00 00 00 00 00 1c 00
00 00 00 00 4a 8f 0d 05 49 62 e5 f4 5c 28 9e 81
32 c7 11 eb 2c dc ef b8 02 3f cb e7
<< Received data (24 bytes)
06 00 ff 07 06 15 00 00 00 00 00 00 00 00 08 00
00 0f 00 00 a4 a3 a2 a0
<<RAKP 4 MESSAGE
<< Message tag : 0x00
<< RMCP+ status : invalid integrity
check value
<< Console Session ID : 0xa0a2a3a4
<< Key exchange auth code [sha1] :
0x0038c7a02d9f16ac1161aaeb
RAKP 4 message indicates an error : invalid integrity
check value
Error: Unable to establish IPMI v2 / RMCP+ session
Error sending Chassis Status command
Post by H***@fujitsu-siemens.comHello,
It doesn't work, even using "-o intelplus".
Hmmm, that's to bad. I have to verify the current
sources from cvs with
- you are trying to connect without specifying the
username (or you have
omited this from the trace). In case no username is
given, a role lookup
is specified during session handshake and performed
(e.g configured
password for NULL user). The BMC has to support
this, and I never tried
this before with ipmitool.
Also you can try to connect without authentication
during RAKP stage
(e.g. use -C 0). This will turn off Integrity code
and encryption as
well.
Could you also please provide an ethereal sniff with
-C 2 (not
encrypted, but authenticated during RAKP and
integrity) and/or a log
with verbose > 2 (e.g. -vvv)
Thank you,
Holger
P.S. Which BMC version you are using?
-------------------------------------------------------
Post by H***@fujitsu-siemens.comSF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT
Products from real users.
Discover which products truly live up to the hype.
Start reading now.
http://ads.osdn.com/?ad_ide95&alloc_id396&op=click
_______________________________________________
Ipmitool-devel mailing list
https://lists.sourceforge.net/lists/listinfo/ipmitool-devel
__________________________________
Do you Yahoo!?
Yahoo! Small Business - Try our new resources site!
http://smallbusiness.yahoo.com/resources/