Friendship ended with Supermicro, the new H13 boards try and nickel and dime you for HTML5 virtual media...
mini@perfect.moe
replied 29 Jul 2024 11:07 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/8nfLpxTjQ521f3DJH9
@benjojo Same on the new X13 boards - I have an X13SEI that does the same. Java virtual media still works, but... who wants to use Java? :/
benjojo
replied 29 Jul 2024 11:22 +0000
in reply to: https://perfect.moe/users/mini/statuses/112869458505815763
@mini Ah! Good to know the javaws still works, at least I can run that in my bomb proof javaws containment zone if I really need it. In this case the machine was in front of me so I just made a USB stick...
edward@social.sphero..
replied 29 Jul 2024 11:24 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/8nfLpxTjQ521f3DJH9
@benjojo this absolutely boils my piss with Supermicro! They don’t seem to see any issue with it being included in the ancient Java applets that they can’t be bothered to update, but paid for in the HTML5 version of the KVMoIP on the same bloody board!
We’ve been mounting ISO files via SMB in the IPMI instead, but that’s buggy as hell on some boards and only works with SMBv1, which is insecure…
benjojo
replied 29 Jul 2024 11:27 +0000
in reply to: https://social.spheron.one/users/edward/statuses/112869524393963464
@edward I picked Supermicro over the other Tyan/Gigabyte options because in general I didnt think I was going to get dicked around, but clearly they will, so I guess the next box will be the Tyan/etc version. They are slightly cheaper, and also dont come with restrictions over who can build them, and as far as I have observed on others setups, dont have hostile IPMIs (hence why I also dislike the Dell/HPE SKUs as well)
edward@social.sphero..
replied 29 Jul 2024 11:50 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/l1N4K43713Ztt9tn81
@benjojo We've got our first Gigabyte server on order at the moment, so fingers crossed the IPMI doesn't make me want to yeet it into the sun (if it ever arrives from Taiwan...) The Supermicro VAR that we use have moved a lot of their builds to Gigabyte and ASUS due to the ridiculous stuff with Supermicro demanding to pre-build almost everything now.
ledeuns@bsd.network
replied 29 Jul 2024 10:04 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/8nfLpxTjQ521f3DJH9
krono@toot.berlin
replied 29 Jul 2024 10:13 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/8nfLpxTjQ521f3DJH9
@benjojo You're not the first to be enraged…
https://peterkleissner.com/2018/05/27/reverse-engineering-supermicro-ipmi/
feuerrot@chaos.socia..
replied 29 Jul 2024 10:58 +0000
in reply to: https://toot.berlin/users/krono/statuses/112869247047149691
@krono @benjojo sadly that's the old activation method, which IIRC doesn't apply to H13-boards.
The new one uses some sort of signed licence (I didn't reverse the full license check, but found a public cert and some calls to openssl rsa verification - but that was also over a year ago, so I'm not that sure about the details) - so it's probably impossible to generate a key without paying supermicro.
0x47df@duckpon.de
replied 29 Jul 2024 11:39 +0000
in reply to: https://chaos.social/users/feuerrot/statuses/112869423797598081
feuerrot@chaos.socia..
replied 29 Jul 2024 11:56 +0000
in reply to: https://duckpon.de/users/0x47df/statuses/01J3Z4JT60481753C9EK30102M
@0x47df @krono @benjojo I wouldn't be suprised (but also really don't know - I just wanted to find out, why some ldap-auth stuff doesn't work), but I also wouldn't be suprised if there are bugs somewhere which allow arbitrary write access to the fs.
The firmware isn't encrypted, so IIRC binwalk should just give you the rootfs.
sa@chaos.social
replied 29 Jul 2024 12:08 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/8nfLpxTjQ521f3DJH9
@benjojo it's dumb. but at a pinch, cifs mounting isos still works. or the java thing, if you can figure out how to run java in 2024.
karppinen@mastodon.o..
replied 29 Jul 2024 17:33 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/8nfLpxTjQ521f3DJH9
@benjojo it sucks but they're cheap and quick to buy in the Supermicro online store. If that wasn't the case this would be a showstopper for me.