Skip to content

Commit 0ebdd04

Browse files
addetzachuribooks
andauthored
docs: update secure boot installation and single node DOC-2208 PEM-8537 (#8049)
* docs: update secure boot installation and single node DOC-2208 PEM-8537 * Apply suggestions from code review Co-authored-by: Amanda Churi Filanowski <[email protected]> * docs: update reboot instructions --------- Co-authored-by: Amanda Churi Filanowski <[email protected]>
1 parent 10d830e commit 0ebdd04

File tree

1 file changed

+51
-3
lines changed

1 file changed

+51
-3
lines changed

_partials/self-hosted/management-appliance/_installation-steps-prereqs.mdx

Lines changed: 51 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ partial_name: installation-steps-prereqs
77

88
- Access to the [Artifact Studio](https://artifact-studio.spectrocloud.com/) to download the {props.iso} ISO.
99

10-
- A minimum of three nodes must be provisioned in advance for the Palette installation. We recommended the following
10+
- {props.edition} can be installed on a single node or on three nodes. For production environments, we recommend that three nodes be provisioned in advance for the Palette installation. We recommended the following
1111
resources for each node. Refer to the Palette <PaletteVertexUrlMapper edition={props.edition} text="Size Guidelines" palettePath="/install-palette#size-guidelines" vertexPath="/install-palette-vertex#size-guidelines"/> for additional sizing information.
1212

1313
- 8 CPUs per node.
@@ -45,10 +45,58 @@ partial_name: installation-steps-prereqs
4545
:::warning
4646

4747
- The ISO is only supported on Unified Extensible Firmware Interface (UEFI) systems. Ensure you configure the nodes to boot from the ISO in UEFI mode.
48-
- Palette Management Appliance does not support Secure Boot. Disable it on the nodes before proceeding with the installation.
49-
5048
:::
5149

50+
- Palette Management Appliance supports Secure Boot for Dell servers with UEFI and Hewlett Packard Enterprise iLO5.
51+
Learn how to configure and install Secure Boot for Palette Management Appliance below.
52+
53+
<details>
54+
55+
<summary> How to install Secure Boot on Hewlett Packard Enterprise iLO 5 </summary>
56+
57+
Before you start, ensure that you have the `MOK.der` certificate file on your local computer and that you
58+
have iLO 5 access with privileges to launch the remote console and change BIOS settings.
59+
Reach out to your customer support representative if you do not have the `MOK.der` file.
60+
61+
1. Power on or reboot the server. When prompted during Power-On Self-Test (POST), press **F9** to enter **System Utilities**.
62+
2. Select **System Configuration** and press **ENTER**.
63+
3. Select **BIOS/Platform Configuration (RBSU)** > **Server Security** > **Secure Boot Settings** > **Advanced Secure Boot Options**.
64+
4. Select **DB – Allowed Signatures Database** > **Enroll Signature**. If Secure Boot is currently enabled, the **Enroll Signature** option will be unavailable. Temporarily disable Secure Boot and repeat the process.
65+
5. Drag the `MOK.der` file from your desktop onto the iLO Remote Console window. iLO mounts it as a virtual USB device automatically.
66+
6. Confirm any prompts.
67+
7. Verify that the new entry appears under **DB – Allowed Signatures Database** > **View Signatures**.
68+
8. Press **ESC** to exit the menus until the **Save and Exit** option is available.
69+
9. Save the changes. Exit the menu and confirm to reboot the server.
70+
</details>
71+
72+
<details>
73+
74+
<summary> How to install Secure Boot on Dell servers with UEFI </summary>
75+
76+
Before you start, ensure that you have the `MOK.der` certificate file on your local computer.
77+
Reach out to your customer support representative if you do not have the `MOK.der` file.
78+
79+
1. Power on the server. Execute the following command to create a virtual CD/DVD drive containing an ISO file with the `MOK.der` certificate.
80+
81+
```
82+
mkisofs -output key.iso -volid cidata -joliet -rock MOK.der
83+
```
84+
Alternatively, you can save the file to a FAT32-formatted USB drive.
85+
86+
2. Reboot the server. When the Dell logo appears, press **F2**. The **System Setup** menu opens.
87+
3. Select **System BIOS** > **Boot Settings**.
88+
4. Ensure that the **Boot Mode** is set to **UEFI**.
89+
5. Press **ESC** to return to **Boot Settings**.
90+
6. Select **System Security** > **Secure Boot Settings**.
91+
7. Toggle **Secure Boot** to **Enabled** and **Secure Boot Policy** to **Custom**.
92+
8. Select **Secure Boot Custom Policy Settings** > **Authorized Signature Database (db)**.
93+
9. Select **Import New Entry**. Then, select the virtual CD/DVD drive or USB drive containing the `MOK.der` file.
94+
10. Save the changes. Press **ESC** to return to **Authorized Signature Database (db)**.
95+
11. Select **View Entries**. The `MOK.der` file shows in the database as **DRBD Module Signing**.
96+
12. Save the changes. Exit the menu and confirm to reboot the server.
97+
98+
</details>
99+
52100
- You can choose to use either an internal Zot registry that comes with Palette or an external registry of your choice. If using an external registry, you will need to provide the following information during the Palette installation process.
53101

54102
- The DNS/IP endpoint and port for the external registry.

0 commit comments

Comments
 (0)