Sun Microsystems, Inc.  Oracle System Handbook - ISO 7.0 May 2018 Internal/Partner Edition
   Home | Current Systems | Former STK Products | EOL Systems | Components | General Info | Search | Feedback

Asset ID: 1-71-2341261.1
Update Date:2018-04-10
Keywords:

Solution Type  Technical Instruction Sure

Solution  2341261.1 :   How to fix the OBP firmware password in ilom based system  


Related Items
  • SPARC T4-1
  •  
Related Categories
  • PLA-Support>Sun Systems>SPARC>CMT>SN-SPARC: T4
  •  




In this Document
Goal
Solution
References


Created from <SR 3-13286555501>

Applies to:

SPARC T4-1 - Version Not Applicable to Not Applicable [Release N/A]
Information in this document applies to any platform.

Goal

As part of Solaris hardening, eeprom password has been set for testing.
If the password is forgotten, then user will not be able to go to OBP if the system is powercycled.

Example

====================
NOTICE: Starting additional cpus.
NOTICE: Initializing LDC services.
Note: set-defaults does not change the security fields.
Setting configuration variables to default values.
NOTICE: Probing PCI devices.
NOTICE: Finished PCI probing.

SPARC T4-1, No Keyboard
Copyright (c) 1998, 2016, Oracle and/or its affiliates. All rights reserved.
OpenBoot 4.38.5, 63.5000 GB memory available, Serial #104134906.
Ethernet address 0:10:e0:34:f8:fa, Host ID: 8634f8fa.



Firmware Password:  <<<<<<<<<<<< OBP firmware password is needed to move forward
Sorry. Waiting 10 seconds.
Type boot , go (continue), or login (command mode)

=================
 

Solution

Perform the below steps to fix the problem


 1. Reset the Service Processor to 'factory' settings.
-> set /SP reset_to_defaults=factory
2. Perform AC Power cycle of server by removing the power cords and wait for 5 minutes
3. Re-connect power cords and wait for SP to be active. Login and configure the SP
4. Boot the system to Solaris

Verify the security mode and set to none if password is not needed.
# eeprom security-mode=none

 

Note: Please make sure the ilom connection is established via serial management port.

There is a chance that the ldom config might get erased. Please make sure the LDOM config backup is taken prior this.Refer to doc 1464421.1 for the steps on How-To restore LDom config after loss of (or not saved) configuration.

References

<NOTE:1012605.1> - How to secure the OpenBoot Prom console.
<NOTE:1670564.1> - How to set OBP Variables from the ALOM/ILOM
<NOTE:1007592.1> - Protecting OpenBoot[TM] by Setting Security Parameters
<NOTE:166650.1> - Working Effectively With Oracle Support - Best Practices

Attachments
This solution has no attachment
  Copyright © 2018 Oracle, Inc.  All rights reserved.
 Feedback