- Community Home
- >
- Software
- >
- HPE OneView
- >
- OV 8.70, Gen11 server, PCR Measurements Changed, C...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-11-2024 10:20 AM - last edited on 01-27-2024 06:09 PM by support_s
01-11-2024 10:20 AM - last edited on 01-27-2024 06:09 PM by support_s
OV 8.70, Gen11 server, PCR Measurements Changed, Component Type BIOS PCR Index PCR13
I did setup a few DL380Gen11 server a few weeks ago and did not get this warning. Now I've a few new DL320Gen11 and I've updates OV to v8.70 last week. I've update the firmwares of the server now.
I found this post PCR Measurements Changed, Component Type BIOS PCR ... - Hewlett Packard Enterprise Community (hpe.com)
The warning is triggered after each reboot (maybe power cycle) even without OS installed. What is the ToDo to make clear this permanently ?
PCR Measurements Changed, Component Type BIOS PCR Index PCR13
Configuration change detected in above mentioned component, please verify if firmware version is as expected
Event details
- alertTypeID
Redfish.iLOEvents.6.5.PCRChanged
- correctiveAction
Configuration change detected in above mentioned component, please verify if firmware version is as expected
- eventTimestamp
2024-01-11T17:52:38Z
- ipv4Address
10.24.249.11
- ipv6Address
fe80:0:0:0:5eed:8cff:fead:5466
- lifeCycle
false
- Redfish.EventId
6dd9de92-dbe3-6bae-9c14-350a738d2d86
- Resource
/redfish/v1/Managers/1/SecurityService/
- resourceID
/redfish/v1/Managers/1/SecurityService/
- resourceUri
/rest/server-hardware/37323550-3636-5A43-4A44-303530313250
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-15-2024 10:35 PM
01-15-2024 10:35 PM
Re: OV 8.70, Gen11 server, PCR Measurements Changed, Component Type BIOS PCR Index PCR13
Hello,
Refer to the advisory. Advisory: HPE Integrated Lights-Out 6 (iLO 6) - "PCR Measurements Changed" Critical Error Message Displayed in HPE OneView
This is a known issue and will be resolved in future version of ILO firmware.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-15-2024 11:11 PM - last edited on 01-19-2024 12:50 AM by Sunitha_Mod
01-15-2024 11:11 PM - last edited on 01-19-2024 12:50 AM by Sunitha_Mod
Re: OV 8.70, Gen11 server, PCR Measurements Changed, Component Type BIOS PCR Index PCR13
Ok, thanks. One thing that I still dont understand... according to RBSU Common options | UEFI System Utilities User Guide for HPE ProLiant Gen11 Servers, and HPE Synergy the TpmActivePcrs should be set to "Not Specified". Then why is it set to Sha256Sha384?
TpmActivePcrs Server Security/TPM Options
- Not Specified (default)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-21-2024 05:29 PM
01-21-2024 05:29 PM
Re: OV 8.70, Gen11 server, PCR Measurements Changed, Component Type BIOS PCR Index PCR13
Hello,
- Current TPM 2.0 Active PCRs: When the PCR banks are switched, the algorithm used to compute the hashed values stored in the PCRs during extend operations is changed. Options are:
- SHA1 only
- SHA256 only
- SHA384 only
- SHA1 and SHA256
- SHA256 and SHA384
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-21-2024 11:07 PM - last edited on 01-22-2024 11:36 PM by Sunitha_Mod
01-21-2024 11:07 PM - last edited on 01-22-2024 11:36 PM by Sunitha_Mod
Re: OV 8.70, Gen11 server, PCR Measurements Changed, Component Type BIOS PCR Index PCR13
@Kashyap02 Sorry, but I don't get the context of your answer. My question was:
Then why is it set to Sha256Sha384?
When documentation contains:
TpmActivePcrs Server Security/TPM Options
Not Specified (default)
The first time I check this setting in RBSU it was Sha256Sha384. So is this the default or did it change to that from Not Specified because of some reason?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-26-2024 01:01 AM
01-26-2024 01:01 AM
Re: OV 8.70, Gen11 server, PCR Measurements Changed, Component Type BIOS PCR Index PCR13
Hello.
@Prix
I have verified many servers in our lab. The TPM 2.0 Active PCRs are set to SHA256 and SHA384 on DL320 Gen11 servers.
Looks like this is the default value which is set on these servers.
We do see "Not Specified" option, but that is not selected as default.
Refer to the below screenshots.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-26-2024 01:05 AM
01-26-2024 01:05 AM
Re: OV 8.70, Gen11 server, PCR Measurements Changed, Component Type BIOS PCR Index PCR13
@Kashyap02 yes, I expected that. But then documentation is wrong.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-26-2024 01:10 AM
01-26-2024 01:10 AM
Re: OV 8.70, Gen11 server, PCR Measurements Changed, Component Type BIOS PCR Index PCR13
Thank you for highlighting this.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-15-2024 01:39 PM
03-15-2024 01:39 PM
Re: OV 8.70, Gen11 server, PCR Measurements Changed, Component Type BIOS PCR Index PCR13
So what is the fix for this? I just updated to 1.57 (released end of Feb 2024) on a test machine and I am still getting these errors. Is the fix still in the works for a future iLO firmware update or should be changing the settings in the UEFI to prevent that - if so, then what settings?
Thanks
NJK
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-15-2024 01:41 PM
03-15-2024 01:41 PM
Re: OV 8.70, Gen11 server, PCR Measurements Changed, Component Type BIOS PCR Index PCR13
I did notice that the AlertID changed from "Redfish.iLOEvents.6.5.PCRChanged" (6.5) to "Redfish.iLOEvents.6.6.PCRChanged" (6.6). Not sure if that is circumvententing the previous fix...but figured I would mention it.
NJK