| 1 | { |
| 2 | "scriptText": "##### Starting Block #####\nprint \"Script Started\"\n\n##### Block: Remote - Remove Trigger #####\nHighlightBlock __t 0\njsonparse hMapPolicies \"%7B%220%22:%20%22User%20Initiated%22,%09%221%22:%20%22Alert%22,%20%222%22:%20%22Periodic%22%7D\"\nsplit policiesArr \"0,1,2\" \",\"\nlength policiesArrLen policiesArr\nset i 0\n:loop-0\nset curPolicy hMapPolicies.{policiesArr.{i}}\njsonparse ws_args \"%7B%22PolicyRuleName%22:%22{curPolicy}%22%7D\"\nwsdelete \"AMT_RemoteAccessPolicyRule\" ws_args\nadd i i 1\njump :loop-0 i \"<\" policiesArrLen\nprint \"Policies removed successfully\"\nset PullRemoteAccess 1\nset AMT_RemoteAccessPolicyRule\nset curPolicy\nset hMapPolicies\nset i\nset policiesArr\nset policiesArrLen\nset ws_args\nset wsman_result\n\n##### Block: Remote - Remove All MPS #####\nHighlightBlock __t 1\nsplit ws_general_query \"AMT_ManagementPresenceRemoteSAP\" ,\nwsbatchenum \"wsman_answer\" ws_general_query\nset i 0\nset arr wsman_answer.AMT_ManagementPresenceRemoteSAP.responses\nLength arr_len arr\njump :end-%%%~%%% arr_len \"=\" 0\n:loop-1\nset instanceName wsman_answer.AMT_ManagementPresenceRemoteSAP.responses.{i}.Name\nset selector \"%3Cw:SelectorSet%3E%3Cw:Selector%20Name=%22Name%22%3E{instanceName}%3C/w:Selector%3E%3C/w:SelectorSet%3E\"\nwsdelete \"AMT_ManagementPresenceRemoteSAP\" selector\nadd i i 1\njump :loop-1 i \"<\" arr_len\n:end-1\nset AMT_ManagementPresenceRemoteSAP\nset arr\nset i\nset instanceName\nset selector\nset ws_general_query\nset wsman_answer\nset wsman_result\nset wsman_result_str\nset arr_len\nset PullRemoteAccess 1\n\n\n##### Block: Network - Clear Environment Detection #####\nHighlightBlock __t 2\nsplit ws_general_query \"*AMT_EnvironmentDetectionSettingData\" \",\"\nwsbatchenum \"wsman_answer\" ws_general_query\nset envDetectionInstance wsman_answer.AMT_EnvironmentDetectionSettingData.response\nset envDetectionInstance.DetectionStrings undefined\nwsput \"AMT_EnvironmentDetectionSettingData\" envDetectionInstance\njump :error-2 wsman_result \"==\" 200\nprint \"Cleared environment detection\"\njump :end-2\n:error-2\nprint \"ERROR: WSMAN call failed: {wsman_result_str}\"\njump :end-2\n:end-2\nset envDetectionInstance\nset ws_general_query\nset AMT_EnvironmentDetectionSettingData\nset PullRemoteAccess \"1\"\nset wsman_answer \nset wsman_result\n\n\n##### Ending Block #####\n:end\njump :SkipPullSystemStatus PullSystemStatus \"!=\" 1\nPullSystemStatus\n:SkipPullSystemStatus\njump :SkipPullEventLog PullEventLog \"!=\" 1\nPullEventLog\n:SkipPullEventLog\njump :SkipPullAuditLog PullAuditLog \"!=\" 1\nPullAuditLog\n:SkipPullAuditLog\njump :SkipPullCertificates PullCertificates \"!=\" 1\nPullCertificates\n:SkipPullCertificates\njump :SkipPullWatchdog PullWatchdog \"!=\" 1\nPullWatchdog\n:SkipPullWatchdog\njump :SkipPullSystemDefense PullSystemDefense \"!=\" 1\nPullSystemDefense\n:SkipPullSystemDefense\njump :SkipPullHardware PullHardware \"!=\" 1\nPullHardware\n:SkipPullHardware\njump :SkipPullUserInfo PullUserInfo \"!=\" 1\nPullUserInfo\n:SkipPullUserInfo\njump :SkipPullRemoteAccess PullRemoteAccess \"!=\" 1\nPullRemoteAccess\n:SkipPullRemoteAccess\nprint \"Script Completed\"\nHighlightBlock\n", |
| 3 | "mescript": "JH0pRQABAAMAFwABAA8BU2NyaXB0IFN0YXJ0ZWROKQATAAIABABfX3QABQIAAAAAAAsAdgACAA0AaE1hcFBvbGljaWVzAF8BJTdCJTIyMCUyMjolMjAlMjJVc2VyJTIwSW5pdGlhdGVkJTIyLCUwOSUyMjElMjI6JTIwJTIyQWxlcnQlMjIsJTIwJTIyMiUyMjolMjAlMjJQZXJpb2RpYyUyMiU3RAAIACAAAwAMAHBvbGljaWVzQXJyAAYBMCwxLDIAAgEsAAoAJQACAA8AcG9saWNpZXNBcnJMZW4ADABwb2xpY2llc0FycgACABEAAgACAGkABQIAAAAAAAIAMwACAAoAY3VyUG9saWN5AB8AaE1hcFBvbGljaWVzLntwb2xpY2llc0Fyci57aX19AAsAPwACAAgAd3NfYXJncwAtASU3QiUyMlBvbGljeVJ1bGVOYW1lJTIyOiUyMntjdXJQb2xpY3l9JTIyJTdEABMALQACABsBQU1UX1JlbW90ZUFjY2Vzc1BvbGljeVJ1bGUACAB3c19hcmdzAA0AFQADAAIAaQACAGkABQIAAAABAAEAJgAEAAUDAAAA9gACAGkAAgE8AA8AcG9saWNpZXNBcnJMZW4AAwAsAAEAJAFJTkZPOiBQb2xpY2llcyByZW1vdmVkIHN1Y2Nlc3NmdWxseQACACAAAgARAFB1bGxSZW1vdGVBY2Nlc3MABQIAAAABAAIAIwABABsAQU1UX1JlbW90ZUFjY2Vzc1BvbGljeVJ1bGUAAgASAAEACgBjdXJQb2xpY3kAAgAVAAEADQBoTWFwUG9saWNpZXMAAgAKAAEAAgBpAAIAFAABAAwAcG9saWNpZXNBcnIAAgAXAAEADwBwb2xpY2llc0FyckxlbgACABAAAQAIAHdzX2FyZ3MAAgAVAAEADQB3c21hbl9yZXN1bHROKQATAAIABABfX3QABQIAAAABAAgAPwADABEAd3NfZ2VuZXJhbF9xdWVyeQAgAUFNVF9NYW5hZ2VtZW50UHJlc2VuY2VSZW1vdGVTQVAAAgAsABAAKAACAA0Bd3NtYW5fYW5zd2VyABEAd3NfZ2VuZXJhbF9xdWVyeQACABEAAgACAGkABQIAAAAAAAIARQACAAQAYXJyADcAd3NtYW5fYW5zd2VyLkFNVF9NYW5hZ2VtZW50UHJlc2VuY2VSZW1vdGVTQVAucmVzcG9uc2VzAAoAFgACAAgAYXJyX2xlbgAEAGFycgACAFcAAgANAGluc3RhbmNlTmFtZQBAAHdzbWFuX2Fuc3dlci5BTVRfTWFuYWdlbWVudFByZXNlbmNlUmVtb3RlU0FQLnJlc3BvbnNlcy57aX0uTmFtZQACAHwAAgAJAHNlbGVjdG9yAGkBJTNDdzpTZWxlY3RvclNldCUzRSUzQ3c6U2VsZWN0b3IlMjBOYW1lPSUyMk5hbWUlMjIlM0V7aW5zdGFuY2VOYW1lfSUzQy93OlNlbGVjdG9yJTNFJTNDL3c6U2VsZWN0b3JTZXQlM0UAEwAzAAIAIAFBTVRfTWFuYWdlbWVudFByZXNlbmNlUmVtb3RlU0FQAAkAc2VsZWN0b3IADQAVAAMAAgBpAAIAaQAFAgAAAAEAAQAfAAQABQMAAAOmAAIAaQACATwACABhcnJfbGVuAAIAKAABACAAQU1UX01hbmFnZW1lbnRQcmVzZW5jZVJlbW90ZVNBUAACAAwAAQAEAGFycgACAAoAAQACAGkAAgAVAAEADQBpbnN0YW5jZU5hbWUAAgARAAEACQBzZWxlY3RvcgACABkAAQARAHdzX2dlbmVyYWxfcXVlcnkAAgAVAAEADQB3c21hbl9hbnN3ZXIAAgAVAAEADQB3c21hbl9yZXN1bHQAAgAZAAEAEQB3c21hbl9yZXN1bHRfc3RyAAIAEAABAAgAYXJyX2xlbgACACAAAgARAFB1bGxSZW1vdGVBY2Nlc3MABQIAAAABTikAEwACAAQAX190AAUCAAAAAgAIAEQAAwARAHdzX2dlbmVyYWxfcXVlcnkAJQEqQU1UX0Vudmlyb25tZW50RGV0ZWN0aW9uU2V0dGluZ0RhdGEAAgEsABAAKAACAA0Bd3NtYW5fYW5zd2VyABEAd3NfZ2VuZXJhbF9xdWVyeQACAFkAAgAVAGVudkRldGVjdGlvbkluc3RhbmNlADoAd3NtYW5fYW5zd2VyLkFNVF9FbnZpcm9ubWVudERldGVjdGlvblNldHRpbmdEYXRhLnJlc3BvbnNlAAIAOgACACYAZW52RGV0ZWN0aW9uSW5zdGFuY2UuRGV0ZWN0aW9uU3RyaW5ncwAKAHVuZGVmaW5lZAARAEMAAgAkAUFNVF9FbnZpcm9ubWVudERldGVjdGlvblNldHRpbmdEYXRhABUAZW52RGV0ZWN0aW9uSW5zdGFuY2UAAQAoAAQABQMAAAeAAA0Ad3NtYW5fcmVzdWx0AAMBPT0ABQIAAADIAAMAJgABAB4BQ2xlYXJlZCBlbnZpcm9ubWVudCBkZXRlY3Rpb24AAQANAAEABQMAAAfCAAMANQABAC0BRVJST1I6IFdTTUFOIGNhbGwgZmFpbGVkOiB7d3NtYW5fcmVzdWx0X3N0cn0AAQANAAEABQMAAAfCAAIAHQABABUAZW52RGV0ZWN0aW9uSW5zdGFuY2UAAgAZAAEAEQB3c19nZW5lcmFsX3F1ZXJ5AAIALAABACQAQU1UX0Vudmlyb25tZW50RGV0ZWN0aW9uU2V0dGluZ0RhdGEAAgAdAAIAEQBQdWxsUmVtb3RlQWNjZXNzAAIBMQACABUAAQANAHdzbWFuX2Fuc3dlcgACABUAAQANAHdzbWFuX3Jlc3VsdAABACwABAAFAwAACJ0AEQBQdWxsU3lzdGVtU3RhdHVzAAMBIT0ABQIAAAABTiAABgAAAAEAKAAEAAUDAAAIywANAFB1bGxFdmVudExvZwADASE9AAUCAAAAAU4hAAYAAAABACgABAAFAwAACPkADQBQdWxsQXVkaXRMb2cAAwEhPQAFAgAAAAFOIgAGAAAAAQAsAAQABQMAAAkrABEAUHVsbENlcnRpZmljYXRlcwADASE9AAUCAAAAAU4jAAYAAAABACgABAAFAwAACVkADQBQdWxsV2F0Y2hkb2cAAwEhPQAFAgAAAAFOJAAGAAAAAQAtAAQABQMAAAmMABIAUHVsbFN5c3RlbURlZmVuc2UAAwEhPQAFAgAAAAFOJQAGAAAAAQAoAAQABQMAAAm6AA0AUHVsbEhhcmR3YXJlAAMBIT0ABQIAAAABTiYABgAAAAEAKAAEAAUDAAAJ6AANAFB1bGxVc2VySW5mbwADASE9AAUCAAAAAU4nAAYAAAABACwABAAFAwAAChoAEQBQdWxsUmVtb3RlQWNjZXNzAAMBIT0ABQIAAAABTigABgAAAAMAGQABABEBU2NyaXB0IENvbXBsZXRlZE4pAAYAAA==", |
| 4 | "blocks": { |
| 5 | "_start": { |
| 6 | "name": "Start", |
| 7 | "desc": "Starting Block", |
| 8 | "code": "print \"Script Started\"" |
| 9 | }, |
| 10 | "_end": { |
| 11 | "name": "End", |
| 12 | "desc": "Ending Block", |
| 13 | "code": ":end\r\njump :SkipPullSystemStatus PullSystemStatus \"!=\" 1\r\nPullSystemStatus\r\n:SkipPullSystemStatus\r\njump :SkipPullEventLog PullEventLog \"!=\" 1\r\nPullEventLog\r\n:SkipPullEventLog\r\njump :SkipPullAuditLog PullAuditLog \"!=\" 1\r\nPullAuditLog\r\n:SkipPullAuditLog\r\njump :SkipPullCertificates PullCertificates \"!=\" 1\r\nPullCertificates\r\n:SkipPullCertificates\r\njump :SkipPullWatchdog PullWatchdog \"!=\" 1\r\nPullWatchdog\r\n:SkipPullWatchdog\r\njump :SkipPullSystemDefense PullSystemDefense \"!=\" 1\r\nPullSystemDefense\r\n:SkipPullSystemDefense\r\njump :SkipPullHardware PullHardware \"!=\" 1\r\nPullHardware\r\n:SkipPullHardware\r\njump :SkipPullUserInfo PullUserInfo \"!=\" 1\r\nPullUserInfo\r\n:SkipPullUserInfo\r\njump :SkipPullRemoteAccess PullRemoteAccess \"!=\" 1\r\nPullRemoteAccess\r\n:SkipPullRemoteAccess\r\nprint \"Script Completed\"" |
| 14 | }, |
| 15 | "AMT-Accounts-AddDigestUser": { |
| 16 | "name": "Accounts - Add Digest User", |
| 17 | "desc": "Add a new digest user account to Intel AMT", |
| 18 | "code": "# Get the DigestRealm\r\njump :SkipDigestRealm-%%%~%%% DigestRealm \"!=\"\r\nprint \"Fetching digest realm...\"\r\nsplit ws_general_query \"*AMT_GeneralSettings\" ,\r\nwsbatchenum \"wsman_answer\" ws_general_query\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset DigestRealm wsman_answer.AMT_GeneralSettings.response.DigestRealm\r\n:SkipDigestRealm-%%%~%%%\r\n\r\n# Create account\r\nset AccountName \"%%%name%%%\"\r\nset AccountPass \"%%%password%%%\"\r\nset digest \"{AccountName}:{DigestRealm}:{AccountPass}\"\r\nmd5 digestmd5 digest\r\nbtoa digestmd5 digestmd5\r\njsonparse wsargs \"%7B %22DigestUsername%22:%22{AccountName}%22, %22DigestPassword%22:%22{digestmd5}%22, %22AccessPermission%22:%%%accessPermission%%%, %22Realms%22:[%%%realms%%%] %7D\"\r\nwsexec \"AMT_AuthorizationService\" \"AddUserAclEntryEx\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nprint \"Account {AccountName} create: {AMT_AuthorizationService.Body.ReturnValueStr}\"\r\n\r\nset PullUserInfo 1\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"Call failed: {wsman_result_str}\"\r\n:end-%%%~%%%", |
| 19 | "vars": { |
| 20 | "name": { |
| 21 | "name": "Name", |
| 22 | "desc": "Name of the user account to create", |
| 23 | "type": 1, |
| 24 | "maxlength": 30, |
| 25 | "value": "" |
| 26 | }, |
| 27 | "password": { |
| 28 | "name": "Password", |
| 29 | "desc": "Password of the user account to create", |
| 30 | "type": 4, |
| 31 | "maxlength": 30, |
| 32 | "value": "" |
| 33 | }, |
| 34 | "accessPermission": { |
| 35 | "name": "Access Permission", |
| 36 | "desc": "Set account to be local, remote or both", |
| 37 | "type": 3, |
| 38 | "values": { |
| 39 | "0": "Local only", |
| 40 | "1": "Network only", |
| 41 | "2": "All (Local & Network)" |
| 42 | }, |
| 43 | "value": "2" |
| 44 | }, |
| 45 | "realms": { |
| 46 | "name": "Realms", |
| 47 | "desc": "Set account permissions", |
| 48 | "type": 5, |
| 49 | "values": { |
| 50 | "2": "Redirection", |
| 51 | "3": "PT Administration", |
| 52 | "4": "Hardware Asset", |
| 53 | "5": "Remote Control", |
| 54 | "6": "Storage", |
| 55 | "7": "Event Manager", |
| 56 | "8": "Storage Admin", |
| 57 | "9": "Agent Presence Local", |
| 58 | "10": "Agent Presence Remote", |
| 59 | "11": "Circuit Breaker", |
| 60 | "12": "Network Time", |
| 61 | "13": "General Information", |
| 62 | "14": "Firmware Update", |
| 63 | "15": "EIT", |
| 64 | "16": "LocalUN", |
| 65 | "17": "Endpoint Access Control", |
| 66 | "18": "Endpoint Access Control Admin", |
| 67 | "19": "Event Log Reader", |
| 68 | "20": "Audit Log", |
| 69 | "21": "ACL Realm", |
| 70 | "24": "Local System" |
| 71 | }, |
| 72 | "value": [ |
| 73 | "3" |
| 74 | ] |
| 75 | } |
| 76 | } |
| 77 | }, |
| 78 | "AMT-Accounts-RemoveDigestUser": { |
| 79 | "name": "Accounts - Remove Digest User", |
| 80 | "desc": "Remove a digest user account from Intel AMT", |
| 81 | "code": "set ToggleAccount \"%%%name%%%\"\r\n\r\n# Fetch all of the account handles\r\nprint \"Fetching account handles...\"\r\njsonparse wsargs \"%7B %22StartIndex%22:1 %7D\"\r\nwsexec \"AMT_AuthorizationService\" \"EnumerateUserAclEntries\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset AccountHandles AMT_AuthorizationService.Body.Handles\r\nset wsargs\r\nset AMT_AuthorizationService\r\nset wsman_result\r\nset wsman_result_str\r\nlength AccountHandlesCount AccountHandles\r\n\r\n# Get all of the account information\r\nprint \"Fetching all account information...\"\r\nset i 0\r\n:fetchAccountLoop-%%%~%%%\r\nset fetchHandle AccountHandles.{i}\r\njsonparse wsargs \"%7B %22Handle%22:{fetchHandle} %7D\"\r\nwsexec \"AMT_AuthorizationService\" \"GetAclEnabledState\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset AccountEnabled{i} AMT_AuthorizationService.Body.Enabled\r\nwsexec \"AMT_AuthorizationService\" \"GetUserAclEntryEx\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset AccountName{i} AMT_AuthorizationService.Body.DigestUsername\r\nset AccountAccess{i} AMT_AuthorizationService.Body.AccessPermission\r\nset AccountRealms{i} AMT_AuthorizationService.Body.Realms\r\nadd i i 1\r\njump :fetchAccountLoop-%%%~%%% i \"<\" AccountHandlesCount\r\nset AMT_AuthorizationService\r\nset fetchHandle\r\nset wsargs\r\n\r\n# Search for a matching account\r\nprint \"Searching accounts...\"\r\nset i 0\r\n:searchAccountLoop-%%%~%%%\r\nset searchHandle AccountHandles.{i}\r\njump :foundAccount AccountName{i} \"=\" ToggleAccount\r\nadd i i 1\r\njump :searchAccountLoop-%%%~%%% i \"<\" AccountHandlesCount\r\njump :end-%%%~%%%\r\n\r\n# Account found, delete it\r\n:foundAccount\r\nprint \"Account {ToggleAccount} found at index {i}, deleting it...\"\r\nset deleteHandle AccountHandles.{i}\r\njsonparse wsargs \"%7B %22Handle%22:{deleteHandle} %7D\"\r\nwsexec \"AMT_AuthorizationService\" \"RemoveUserAclEntry\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nprint \"Done, account {ToggleAccount} deleted.\"\r\nset PullUserInfo 1\r\njump :end\r\n\r\n# End of script\r\njump :end\r\n:error-%%%~%%%\r\nprint \"Call failed: {wsman_result_str}\"\r\n:end-%%%~%%%", |
| 82 | "vars": { |
| 83 | "name": { |
| 84 | "name": "Name", |
| 85 | "desc": "Name of the user account to remove", |
| 86 | "type": 1, |
| 87 | "maxlength": 30, |
| 88 | "value": "" |
| 89 | } |
| 90 | } |
| 91 | }, |
| 92 | "AMT-Accounts-AddKerberosUser": { |
| 93 | "name": "Accounts - Add Kerberos User", |
| 94 | "desc": "Add a new kerberos user account to Intel AMT", |
| 95 | "code": "# Set kerberos sid value as a byte array string\r\nset KerberosUserString \"%%%sid%%%\"\r\nGetSidByteArray x KerberosUserString\r\nbtoa KerberosUserSid x\r\njsonparse wsargs \"%7B%22KerberosUserSid%22:%22{KerberosUserSid}%22,%22AccessPermission%22:%%%accessPermission%%%,%22Realms%22:[%%%realms%%%]%7D\"\r\nwsexec \"AMT_AuthorizationService\" \"AddUserAclEntryEx\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nprint \"Account {KerberosUserString} return value: {AMT_AuthorizationService.Body.ReturnValueStr}\"\r\n\r\nset PullUserInfo 1\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"Call failed: {wsman_result_str}\"\r\n:end-%%%~%%%", |
| 96 | "vars": { |
| 97 | "sid": { |
| 98 | "name": "Sid", |
| 99 | "desc": "The Security ID (SID) of the user account to create", |
| 100 | "type": 1, |
| 101 | "maxlength": 45, |
| 102 | "value": "" |
| 103 | }, |
| 104 | "accessPermission": { |
| 105 | "name": "Access Permission", |
| 106 | "desc": "Set account to be local, remote or both", |
| 107 | "type": 3, |
| 108 | "values": { |
| 109 | "0": "Local only", |
| 110 | "1": "Network only", |
| 111 | "2": "All (Local & Network)" |
| 112 | }, |
| 113 | "value": "2" |
| 114 | }, |
| 115 | "realms": { |
| 116 | "name": "Realms", |
| 117 | "desc": "Set account permissions", |
| 118 | "type": 5, |
| 119 | "values": { |
| 120 | "2": "Redirection", |
| 121 | "3": "PT Administration", |
| 122 | "4": "Hardware Asset", |
| 123 | "5": "Remote Control", |
| 124 | "6": "Storage", |
| 125 | "7": "Event Manager", |
| 126 | "8": "Storage Admin", |
| 127 | "9": "Agent Presence Local", |
| 128 | "10": "Agent Presence Remote", |
| 129 | "11": "Circuit Breaker", |
| 130 | "12": "Network Time", |
| 131 | "13": "General Information", |
| 132 | "14": "Firmware Update", |
| 133 | "15": "EIT", |
| 134 | "16": "LocalUN", |
| 135 | "17": "Endpoint Access Control", |
| 136 | "18": "Endpoint Access Control Admin", |
| 137 | "19": "Event Log Reader", |
| 138 | "20": "Audit Log", |
| 139 | "21": "ACL Realm", |
| 140 | "24": "Local System" |
| 141 | }, |
| 142 | "value": [ |
| 143 | "3" |
| 144 | ] |
| 145 | } |
| 146 | } |
| 147 | }, |
| 148 | "AMT-Accounts-RemoveKerberosUser": { |
| 149 | "name": "Accounts - Remove Kerberos User", |
| 150 | "desc": "Remove a digest user account from Intel AMT", |
| 151 | "code": "GetSidByteArray ToggleAccount \"%%%sid%%%\"\r\nbtoa ToggleAccount ToggleAccount\r\n# Fetch all of the account handles\r\nprint \"Fetching account handles...\"\r\njsonparse wsargs \"%7B %22StartIndex%22:1 %7D\"\r\nwsexec \"AMT_AuthorizationService\" \"EnumerateUserAclEntries\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset AccountHandles AMT_AuthorizationService.Body.Handles\r\nset wsargs\r\nset AMT_AuthorizationService\r\nset wsman_result\r\nset wsman_result_str\r\nlength AccountHandlesCount AccountHandles\r\n\r\n# Get all of the account information\r\nprint \"Fetching all account information...\"\r\nset i 0\r\n:fetchAccountLoop-%%%~%%%\r\nset fetchHandle AccountHandles.{i}\r\njsonparse wsargs \"%7B %22Handle%22:{fetchHandle} %7D\"\r\nwsexec \"AMT_AuthorizationService\" \"GetAclEnabledState\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset AccountEnabled{i} AMT_AuthorizationService.Body.Enabled\r\nwsexec \"AMT_AuthorizationService\" \"GetUserAclEntryEx\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset AccountName{i} AMT_AuthorizationService.Body.KerberosUserSid\r\nset AccountAccess{i} AMT_AuthorizationService.Body.AccessPermission\r\nset AccountRealms{i} AMT_AuthorizationService.Body.Realms\r\nadd i i 1\r\njump :fetchAccountLoop-%%%~%%% i \"<\" AccountHandlesCount\r\nset AMT_AuthorizationService\r\nset fetchHandle\r\nset wsargs\r\n\r\n# Search for a matching account\r\nprint \"Searching accounts...\"\r\nset i 0\r\n:searchAccountLoop-%%%~%%%\r\nset searchHandle AccountHandles.{i}\r\njump :foundAccount AccountName{i} \"=\" ToggleAccount\r\nadd i i 1\r\njump :searchAccountLoop-%%%~%%% i \"<\" AccountHandlesCount\r\njump :end-%%%~%%%\r\n\r\n# Account found, delete it\r\n:foundAccount\r\nprint \"Account %%%sid%%% found at index {i}, deleting it...\"\r\nset deleteHandle AccountHandles.{i}\r\njsonparse wsargs \"%7B %22Handle%22:{deleteHandle} %7D\"\r\nwsexec \"AMT_AuthorizationService\" \"RemoveUserAclEntry\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nprint \"Done, account %%%sid%%% deleted.\"\r\nset PullUserInfo 1\r\njump :end\r\n\r\n# End of script\r\njump :end\r\n:error-%%%~%%%\r\nprint \"Call failed: {wsman_result_str}\"\r\n:end-%%%~%%%", |
| 152 | "vars": { |
| 153 | "sid": { |
| 154 | "name": "Sid", |
| 155 | "desc": "Sid of the user account to remove", |
| 156 | "type": 1, |
| 157 | "maxlength": 45, |
| 158 | "value": "" |
| 159 | } |
| 160 | } |
| 161 | }, |
| 162 | "AMT-Accounts-PrintAll": { |
| 163 | "name": "Accounts - Print Users", |
| 164 | "desc": "Display all digest user accounts from Intel AMT", |
| 165 | "code": "# Fetch all of the account handles\r\nprint \"Fetching account handles...\"\r\njsonparse wsargs \"%7B %22StartIndex%22:1 %7D\"\r\nwsexec \"AMT_AuthorizationService\" \"EnumerateUserAclEntries\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset AccountHandles AMT_AuthorizationService.Body.Handles\r\nset wsargs\r\nset AMT_AuthorizationService\r\nset wsman_result\r\nset wsman_result_str\r\nlength AccountHandlesCount AccountHandles\r\n\r\n# Get all of the account information\r\nprint \"Fetching all account information...\"\r\nset i 0\r\n:fetchAccountLoop-%%%~%%%\r\nset fetchHandle AccountHandles.{i}\r\njsonparse wsargs \"%7B %22Handle%22:{fetchHandle} %7D\"\r\nwsexec \"AMT_AuthorizationService\" \"GetAclEnabledState\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset AccountEnabled{i} AMT_AuthorizationService.Body.Enabled\r\nwsexec \"AMT_AuthorizationService\" \"GetUserAclEntryEx\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nprint \"AMT-ACCOUNT: {AMT_AuthorizationService.Body.DigestUsername}, {AMT_AuthorizationService.Body.AccessPermission}, [{AMT_AuthorizationService.Body.Realms}]\"\r\nadd i i 1\r\njump :fetchAccountLoop-%%%~%%% i \"<\" AccountHandlesCount\r\nset AMT_AuthorizationService\r\nset fetchHandle\r\nset wsargs\r\n\r\n# End of script\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"Call failed: {wsman_result_str}\"\r\n:end-%%%~%%%" |
| 166 | }, |
| 167 | "Basic-Add": { |
| 168 | "name": "Basic - Add", |
| 169 | "desc": "Add a value to a given variable", |
| 170 | "code": "add %%%var%%% %%%var%%% %%%value%%%", |
| 171 | "vars": { |
| 172 | "var": { |
| 173 | "name": "Name", |
| 174 | "desc": "Name of the variable to add to", |
| 175 | "type": 1, |
| 176 | "maxlength": 20, |
| 177 | "value": "SampleVariable" |
| 178 | }, |
| 179 | "value": { |
| 180 | "name": "Value", |
| 181 | "desc": "Value to add to the variable", |
| 182 | "type": 1, |
| 183 | "value": "1" |
| 184 | } |
| 185 | } |
| 186 | }, |
| 187 | "Basic-Disconnect": { |
| 188 | "name": "Basic - Disconnect", |
| 189 | "desc": "Disconnect from Intel AMT", |
| 190 | "code": "Disconnect" |
| 191 | }, |
| 192 | "Basic-JumpLabel": { |
| 193 | "name": "Basic - Jump Target", |
| 194 | "desc": "Set a jump label. Other blocks can jump here.", |
| 195 | "code": ":%%%label%%%", |
| 196 | "vars": { |
| 197 | "label": { |
| 198 | "name": "Label", |
| 199 | "desc": "Name of the jump target label", |
| 200 | "type": 1, |
| 201 | "maxlength": 50, |
| 202 | "value": "SampleLabel" |
| 203 | } |
| 204 | } |
| 205 | }, |
| 206 | "Basic-Jump": { |
| 207 | "name": "Basic - Jump", |
| 208 | "desc": "Jump to a given label", |
| 209 | "code": "jump :%%%label%%%", |
| 210 | "vars": { |
| 211 | "label": { |
| 212 | "name": "Label", |
| 213 | "desc": "Name of the jump target label", |
| 214 | "type": 1, |
| 215 | "maxlength": 50, |
| 216 | "value": "SampleLabel" |
| 217 | } |
| 218 | } |
| 219 | }, |
| 220 | "Basic-JumpIf": { |
| 221 | "name": "Basic - Jump if", |
| 222 | "desc": "Jump to a given label if the condition is met", |
| 223 | "code": "jump :%%%label%%% %%%arg1%%% \"%%%comparator%%%\" %%%arg2%%%", |
| 224 | "vars": { |
| 225 | "label": { |
| 226 | "name": "Label", |
| 227 | "desc": "Name of the jump target label", |
| 228 | "type": 1, |
| 229 | "maxlength": 50, |
| 230 | "value": "SampleLabel" |
| 231 | }, |
| 232 | "arg1": { |
| 233 | "name": "arg1", |
| 234 | "desc": "First variable to compare, use \"x\" for a string", |
| 235 | "type": 1, |
| 236 | "value": "" |
| 237 | }, |
| 238 | "comparator": { |
| 239 | "name": "Comparator", |
| 240 | "desc": "How to compare both arguments", |
| 241 | "type": 3, |
| 242 | "values": { |
| 243 | "=": "=", |
| 244 | "!=": "!=", |
| 245 | "<": "<", |
| 246 | ">": ">", |
| 247 | "<=": "<=", |
| 248 | ">=": ">=" |
| 249 | }, |
| 250 | "value": "=" |
| 251 | }, |
| 252 | "arg2": { |
| 253 | "name": "arg2", |
| 254 | "desc": "Second variable to compare, use \"x\" for a string", |
| 255 | "type": 1, |
| 256 | "value": "" |
| 257 | } |
| 258 | } |
| 259 | }, |
| 260 | "Basic-Print": { |
| 261 | "name": "Basic - Print", |
| 262 | "desc": "Print a string to the console", |
| 263 | "code": "print \"%%%printstring%%%\"", |
| 264 | "vars": { |
| 265 | "printstring": { |
| 266 | "name": "Value", |
| 267 | "desc": "String that will be printed to console, use urlescaping for special chars and use {x} to print variable x.", |
| 268 | "type": 1, |
| 269 | "value": "Sample String" |
| 270 | } |
| 271 | } |
| 272 | }, |
| 273 | "Basic-ScriptSpeed": { |
| 274 | "name": "Basic - Script Speed", |
| 275 | "desc": "Set the speed of the script", |
| 276 | "code": "scriptspeed %%%delay%%%", |
| 277 | "vars": { |
| 278 | "delay": { |
| 279 | "name": "Delay", |
| 280 | "desc": "The delay in millisecond between execution of each script step. 200ms is 5 steps per second.", |
| 281 | "type": 2, |
| 282 | "maxlength": 4, |
| 283 | "value": 200 |
| 284 | } |
| 285 | } |
| 286 | }, |
| 287 | "Basic-Set": { |
| 288 | "name": "Basic - Set", |
| 289 | "desc": "Set a variable to a given value", |
| 290 | "code": "set %%%var%%% %%%value%%%", |
| 291 | "vars": { |
| 292 | "var": { |
| 293 | "name": "Name", |
| 294 | "desc": "Name of the variable to set", |
| 295 | "type": 1, |
| 296 | "maxlength": 20, |
| 297 | "value": "SampleVariable" |
| 298 | }, |
| 299 | "value": { |
| 300 | "name": "Value", |
| 301 | "desc": "The new value to set to the variable", |
| 302 | "type": 1, |
| 303 | "value": "0" |
| 304 | } |
| 305 | } |
| 306 | }, |
| 307 | "AMT-General-SetUserConsent": { |
| 308 | "name": "General - Set User Consent", |
| 309 | "desc": "Set the Intel AMT user consent mode", |
| 310 | "code": "split ws_optIn_query \"*IPS_OptInService\" ,\r\nwsbatchenum \"wsman_answer\" ws_optIn_query\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset wsman_answer.IPS_OptInService.response.OptInRequired %%%consentMode%%%\r\nwsput \"IPS_OptInService\" wsman_answer.IPS_OptInService.response\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset PullSystemStatus 1\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"Call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\n", |
| 311 | "vars": { |
| 312 | "consentMode": { |
| 313 | "name": "Consent Mode", |
| 314 | "desc": "Intel AMT user consent mode", |
| 315 | "type": 3, |
| 316 | "values": { |
| 317 | "0": "Not Required", |
| 318 | "1": "Required for KVM only", |
| 319 | "0xFFFFFFFF": "Always Required" |
| 320 | }, |
| 321 | "value": "0" |
| 322 | } |
| 323 | } |
| 324 | }, |
| 325 | "AMT-General-ActiveFeatures": { |
| 326 | "name": "General - Set Active Features", |
| 327 | "desc": "Set the Intel AMT active features", |
| 328 | "code": "split ws_optIn_query \"*AMT_RedirectionService\" ,\r\nwsbatchenum \"wsman_answer\" ws_optIn_query\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset wsman_answer.AMT_RedirectionService.response.ListenerEnabled \"%%%listenerEnabled%%%\"\r\nset wsman_answer.AMT_RedirectionService.response.EnabledState \"%%%enabledState%%%\"\r\njsonparse wsargs \"%7B %22RequestedState%22:%22%%%enabledState%%%%22 %7D\"\r\nwsexec \"AMT_RedirectionService\" \"RequestStateChange\" wsargs\r\nwsput \"AMT_RedirectionService\" wsman_answer.AMT_RedirectionService.response\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset PullSystemStatus \"1\"\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"Call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\n", |
| 329 | "vars": { |
| 330 | "listenerEnabled": { |
| 331 | "name": "Redirection Port", |
| 332 | "desc": "Enable or disable the Intel AMT redirection port (TCP:16993/16995)", |
| 333 | "type": 3, |
| 334 | "values": { |
| 335 | "true": "Enabled", |
| 336 | "false": "Disabled" |
| 337 | }, |
| 338 | "value": "true" |
| 339 | }, |
| 340 | "enabledState": { |
| 341 | "name": "SOL/IDER Feature", |
| 342 | "desc": "Enable or disable the Intel AMT Serial-over-LAN and IDER features", |
| 343 | "type": 3, |
| 344 | "values": { |
| 345 | "32768": "Disabled", |
| 346 | "32769": "IDER only", |
| 347 | "32770": "Serial-over-LAN only", |
| 348 | "32771": "IDER & SOL enabled" |
| 349 | }, |
| 350 | "value": "32771" |
| 351 | } |
| 352 | } |
| 353 | }, |
| 354 | "AMT-General-GetCoreVersion": { |
| 355 | "name": "General - Get Version", |
| 356 | "desc": "Retrieves the Intel AMT release version, prints it to the console and stores it in variable AmtCoreVersion", |
| 357 | "code": "split ws_general_query \"CIM_SoftwareIdentity\"\r\nwsbatchenum \"wsman_answer\" ws_general_query\r\nset i 0\r\nset arr wsman_answer.CIM_SoftwareIdentity.responses\r\nlength arr_len arr\r\n:loop-%%%~%%%\r\nset curInstanceId arr.{i}.InstanceID\r\njump :AmtCoreVersionFound-%%%~%%% curInstanceId \"=\" \"AMT FW Core Version\"\r\nadd i i 1\r\njump :loop-%%%~%%% i \"<\" arr_len\r\nprint \"Error: Intel AMT version was not found\"\r\njump :end-%%%~%%%\r\n:AmtCoreVersionFound-%%%~%%%\r\nset AmtCoreVersion arr.{i}.VersionString\r\nprint \"Intel AMT version: {AmtCoreVersion}\"\r\n:end-%%%~%%%\r\nset arr\r\nset arr_len\r\nset curInstanceId\r\nset i\r\nset ws_general_query\r\nset wsman_answer\r\nset wsman_result" |
| 358 | }, |
| 359 | "AMT-General-GetPlatformType": { |
| 360 | "name": "General - Get Platform Type", |
| 361 | "desc": "Retrieves the platfrom type of the target, prints it to the console and stores it in variable PlatformType", |
| 362 | "code": "jsonparse sysTypeHmap \"%7B%2232%22:%22Desktop%22,%2233%22:%22Notebook%22%7D\"\r\nsplit ws_general_query \"CIM_ComputerSystem\"\r\nwsbatchenum \"wsman_answer\" ws_general_query\r\nset i -1\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\ngetitem i wsman_answer.CIM_ComputerSystem.responses \"ElementName\" \"Managed System\"\r\njump :amtCoreError-%%%~%%% i \"<\" 0\r\nset i wsman_answer.CIM_ComputerSystem.responses.{i}.Dedicated\r\nset PlatformType sysTypeHmap.{i}\r\nprint \"Platform Type: {PlatformType}\"\r\njump :end-%%%~%%%\r\n:amtCoreError-%%%~%%%\r\nprint \"Error: couldn't find CIM_ComputerSystem.ElementName = %22Managed System%22\"\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"WSMAN call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\nset i\r\nset ws_general_query\r\nset wsman_answer\r\nset wsman_result\r\nset wsman_result_str\r\nset sysTypeHmap" |
| 363 | }, |
| 364 | "AMT-General-GetProvState": { |
| 365 | "name": "General - Get Provisisoning State", |
| 366 | "desc": "Retrieves the current Provisioning State of Intel AMT, prints it to the console and stores it in variable AmtProvState", |
| 367 | "code": "jsonparse provStateHmap \"%7B%220%22:%22Pre%22,%221%22:%22In%22,%222%22:%22Post%22%7D\"\r\nsplit ws_general_query \"*AMT_SetupAndConfigurationService\"\r\nwsbatchenum \"wsman_answer\" ws_general_query\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset key wsman_answer.AMT_SetupAndConfigurationService.response.ProvisioningState\r\nset AmtProvState provStateHmap.{key}\r\nadd AmtProvState AmtProvState \"-Provisioning\"\r\nprint \"Intel AMT Provisioning State: {AmtProvState}\"\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"WSMAN call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\nset ws_general_query\r\nset wsman_answer\r\nset wsman_result\r\nset wsman_result_str\r\nset provStateHmap\r\nset key" |
| 368 | }, |
| 369 | "AMT-General-GetProvMode": { |
| 370 | "name": "General - Get Provisisoning Mode", |
| 371 | "desc": "Retrieves the current Provisioning Mode of Intel AMT, prints it to the console and stores it in variable AmtProvMode", |
| 372 | "code": "jsonparse provModeHmap \"%7B%221%22:%22Admin%20Control%20Mode%20(ACM)%22,%222%22:%22Reserved1%22,%223%22:%22Client%20Control%20Mode%20(CCM)%22,%224%22:%22Reserved2%22%7D\"\r\nsplit ws_general_query \"*AMT_SetupAndConfigurationService\"\r\nwsbatchenum \"wsman_answer\" ws_general_query\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset key wsman_answer.AMT_SetupAndConfigurationService.response.ProvisioningMode\r\nset AmtProvMode provModeHmap.{key}\r\nprint \"Intel AMT Provisioning Mode: {AmtProvMode}\"\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"WSMAN call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\nset ws_general_query\r\nset wsman_answer\r\nset wsman_result\r\nset wsman_result_str\r\nset provModeHmap\r\nset key" |
| 373 | }, |
| 374 | "AMT-General-PrintUserConsent": { |
| 375 | "name": "General - Print User Consent", |
| 376 | "desc": "Display the Intel AMT user consent mode", |
| 377 | "code": "jsonparse OptInStateEnum \"%7B%220%22:%22Not Required%22,%221%22:%22Required for KVM only%22,%224294967295%22:%22Always Required%22%7D\"\r\nsplit ws_optIn_query \"*IPS_OptInService\" ,\r\nwsbatchenum \"wsman_answer\" ws_optIn_query\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nprint \"User Consent mode: {OptInStateEnum.{wsman_answer.IPS_OptInService.response.OptInRequired}}\"\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"Call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\n" |
| 378 | }, |
| 379 | "AMT-General-SetHostname": { |
| 380 | "name": "General - Set Hostname", |
| 381 | "desc": "Set the Intel AMT KVM feature to enabled or disabled", |
| 382 | "code": "split ws_general_query \"*AMT_GeneralSettings\" ,\r\nwsbatchenum \"wsman_answer\" ws_general_query\r\njump :error-2 wsman_result \"!=\" 200\r\nset wsman_answer.AMT_GeneralSettings.response.HostName \"%%%hostname%%%\"\r\nset wsman_answer.AMT_GeneralSettings.response.DomainName \"%%%domainname%%%\"\r\nwsput \"AMT_GeneralSettings\" wsman_answer.AMT_GeneralSettings.response\r\njump :error-2 wsman_result \"!=\" 200\r\nset PullSystemStatus \"1\"\r\njump :end-2\r\n:error-2\r\nprint \"Call failed: {wsman_result_str}\"\r\n:end-2\r\n", |
| 383 | "vars": { |
| 384 | "hostname": { |
| 385 | "name": "Hostname", |
| 386 | "desc": "The hostname Intel AMT will use while in Sx state", |
| 387 | "type": 1, |
| 388 | "maxlength": 30, |
| 389 | "value": "" |
| 390 | }, |
| 391 | "domainname": { |
| 392 | "name": "Domain", |
| 393 | "desc": "The domain name Intel AMT will use while in Sx state", |
| 394 | "type": 1, |
| 395 | "maxlength": 30, |
| 396 | "value": "" |
| 397 | } |
| 398 | } |
| 399 | }, |
| 400 | "AMT-General-SetPingResponse": { |
| 401 | "name": "General - Set Ping Response", |
| 402 | "desc": "Set the Intel AMT response to ICMP and RMCP ping requests", |
| 403 | "code": "split ws_general_query \"*AMT_GeneralSettings\" ,\r\nwsbatchenum \"wsman_answer\" ws_general_query\r\njump :error-2 wsman_result \"!=\" 200\r\nset wsman_answer.AMT_GeneralSettings.response.PingResponseEnabled \"%%%icmpPingResponse%%%\"\r\nset wsman_answer.AMT_GeneralSettings.response.RmcpPingResponseEnabled \"%%%rmcpPingResponse%%%\"\r\nwsput \"AMT_GeneralSettings\" wsman_answer.AMT_GeneralSettings.response\r\njump :error-2 wsman_result \"!=\" 200\r\nset PullSystemStatus \"1\"\r\njump :end-2\r\n:error-2\r\nprint \"Call failed: {wsman_result_str}\"\r\n:end-2\r\n", |
| 404 | "vars": { |
| 405 | "icmpPingResponse": { |
| 406 | "name": "ICMP Ping", |
| 407 | "desc": "Enable or disable the Intel AMT response to ICMP ping", |
| 408 | "type": 3, |
| 409 | "values": { |
| 410 | "true": "Enabled", |
| 411 | "false": "Disabled" |
| 412 | }, |
| 413 | "value": "true" |
| 414 | }, |
| 415 | "rmcpPingResponse": { |
| 416 | "name": "RMCP Ping", |
| 417 | "desc": "Enable or disable the Intel AMT response to RMCP ping", |
| 418 | "type": 3, |
| 419 | "values": { |
| 420 | "true": "Enabled", |
| 421 | "false": "Disabled" |
| 422 | }, |
| 423 | "value": "true" |
| 424 | } |
| 425 | } |
| 426 | }, |
| 427 | "AMT-General-GetAmtUuid": { |
| 428 | "name": "General - Get UUID", |
| 429 | "desc": "Retrieves the Intel AMT UUID, prints it to the console and stores it in variable AmtUuid", |
| 430 | "code": "split ws_general_query \"CIM_ComputerSystem\"\r\nwsbatchenum \"wsman_answer\" ws_general_query\r\nset i -1\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\ngetitem i wsman_answer.CIM_ComputerSystem.responses \"ElementName\" \"Managed System\"\r\njump :amtCoreError-%%%~%%% i \"<\" 0\r\nset AmtUuid wsman_answer.CIM_ComputerSystem.responses.{i}.OtherIdentifyingInfo\r\nprint \"Intel AMT UUID: {AmtUuid}\"\r\njump :end-%%%~%%%\r\n:amtCoreError-%%%~%%%\r\nprint \"Error: couldn't find CIM_ComputerSystem.ElementName = %22Managed System%22\"\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"WSMAN call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\nset i\r\nset ws_general_query\r\nset wsman_answer\r\nset wsman_result" |
| 431 | }, |
| 432 | "AMT-KVM-SetState": { |
| 433 | "name": "KVM - Set State", |
| 434 | "desc": "Set the Intel AMT KVM feature to enabled or disabled", |
| 435 | "code": "jsonparse wsargs \"%7B %22RequestedState%22:%22%%%kvmEnabled%%%%22 %7D\"\r\nwsexec \"CIM_KVMRedirectionSAP\" \"RequestStateChange\" wsargs\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset PullSystemStatus \"1\"\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"Call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\n", |
| 436 | "vars": { |
| 437 | "kvmEnabled": { |
| 438 | "name": "KVM State", |
| 439 | "desc": "Enable or disable the Intel AMT KVM feature", |
| 440 | "type": 3, |
| 441 | "values": { |
| 442 | "2": "Enabled", |
| 443 | "3": "Disabled" |
| 444 | }, |
| 445 | "value": "2" |
| 446 | } |
| 447 | } |
| 448 | }, |
| 449 | "AMT-KVM-SetSessionTimeout": { |
| 450 | "name": "KVM - Set Session Timeout", |
| 451 | "desc": "Set the Intel AMT KVM session timeout", |
| 452 | "vars": { |
| 453 | "kvmTimeout": { |
| 454 | "name": "KVM Timeout", |
| 455 | "desc": "Intel AMT KVM session timeout in minutes", |
| 456 | "type": "2", |
| 457 | "value": "4" |
| 458 | } |
| 459 | }, |
| 460 | "code": "split ws_general_query \"*IPS_KVMRedirectionSettingData\" ,\nwsbatchenum \"wsman_answer\" ws_general_query\njump :error-%%%~%%% wsman_result \"!=\" 200\nset wsman_answer.IPS_KVMRedirectionSettingData.response.SessionTimeout \"%%%kvmTimeout%%%\"\nwsput \"IPS_KVMRedirectionSettingData\" wsman_answer.IPS_KVMRedirectionSettingData.response\njump :error-%%%~%%% wsman_result \"!=\" 200\nset PullSystemStatus \"1\"\njump :end-%%%~%%%\n:error-%%%~%%%\nprint \"Call failed: {wsman_result_str}\"\n:end-%%%~%%%\n\n" |
| 461 | }, |
| 462 | "AMT-Network-DetectWiredNic": { |
| 463 | "name": "Network - Wired NIC", |
| 464 | "desc": "Detects if the platfrom has a wired Intel AMT network interface controller (NIC), logs to the console and stores the result in WiredAmtNic", |
| 465 | "code": "split ws_general_query \"CIM_EthernetPort\"\r\nwsbatchenum \"wsman_answer\" ws_general_query\r\nset i -1\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\ngetitem i wsman_answer.CIM_EthernetPort.responses \"DeviceID\" \"Intel(r) AMT Ethernet Port 0\"\r\njump :amtCoreError-%%%~%%% i \"<\" 0\r\nset WiredAmtNic \"true\"\r\nprint \"Wired AMT NIC found: true\"\r\njump :end-%%%~%%%\r\n:amtCoreError-%%%~%%%\r\nprint \"Wired AMT NIC found: false\"\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"WSMAN call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\nset i\r\nset ws_general_query\r\nset wsman_answer\r\nset wsman_result" |
| 466 | }, |
| 467 | "AMT-Network-DetectWifiNic": { |
| 468 | "name": "Network - Wireless NIC", |
| 469 | "desc": "Detects if the platfrom has a WiFi interface, logs to the console and stores the result in WiFiAmtNic", |
| 470 | "code": "split ws_general_query \"CIM_EthernetPort\"\r\nwsbatchenum \"wsman_answer\" ws_general_query\r\nset i -1\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\ngetitem i wsman_answer.CIM_EthernetPort.responses \"DeviceID\" \"Intel(r) AMT Ethernet Port 1\"\r\njump :amtCoreError-%%%~%%% i \"<\" 0\r\nset WiFiAmtNic \"true\"\r\nprint \"WiFi AMT NIC found: true\"\r\njump :end-%%%~%%%\r\n:amtCoreError-%%%~%%%\r\nprint \"Wifi AMT NIC found: false\"\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"WSMAN call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\nset i\r\nset ws_general_query\r\nset wsman_answer\r\nset wsman_result" |
| 471 | }, |
| 472 | "AMT-Network-GetAmtFqdn": { |
| 473 | "name": "Network - Get FQDN", |
| 474 | "desc": "Retrieves the FQDN of Intel AMT, prints it to the console and stores it in variable AmtFqdn", |
| 475 | "code": "split ws_general_query \"*AMT_GeneralSettings\"\r\nwsbatchenum \"wsman_answer\" ws_general_query\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset AmtFqdn wsman_answer.AMT_GeneralSettings.response.HostName\r\nadd AmtFqdn AmtFqdn \".\"\r\nadd AmtFqdn AmtFqdn wsman_answer.AMT_GeneralSettings.response.DomainName\r\nprint \"Intel AMT FQDN: {AmtFqdn}\"\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"WSMAN call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\nset ws_general_query\r\nset wsman_answer\r\nset wsman_result" |
| 476 | }, |
| 477 | "AMT-Network-AddEnvDetection": { |
| 478 | "name": "Network - Set Environment Detection", |
| 479 | "desc": "Configures the DNS information that will be used by Intel AMT to dynamically determine the network it is operating in", |
| 480 | "code": "# *** Validate user input ***\r\nprint \"Parsing block parameters\"\r\njump :EMPTY_DETECTIONSTR-%%%~%%% \"%%%DetectionStrings%%%\" \"=\" \"\"\r\nsplit arrDetectionStrings \"%%%DetectionStrings%%%\" \",\"\r\nsplit arrDetectionIPv6LocalPrefixes \"%%%DetectionIPv6LocalPrefixes%%%\" \",\"\r\nprint \"Setting Environment Detection\"\r\nsplit ws_general_query \"*AMT_EnvironmentDetectionSettingData\" \",\"\r\nwsbatchenum \"wsman_answer\" ws_general_query\r\nset envDetectionInstance wsman_answer.AMT_EnvironmentDetectionSettingData.response\r\njump :DetectionStringsDefined-%%%~%%% envDetectionInstance.DetectionStrings \"!=\"\r\nset envDetectionInstance.DetectionStrings arrDetectionStrings\r\njump :SET_IPV6_PREFIX-%%%~%%%\r\n:DetectionStringsDefined-%%%~%%%\r\nadd arrDetectionStrings \",\" arrDetectionStrings\r\nadd envDetectionInstance.DetectionStrings envDetectionInstance.DetectionStrings arrDetectionStrings\r\nmaketoarray envDetectionInstance.DetectionStrings envDetectionInstance.DetectionStrings\r\nlength arrDetectionStringsLen envDetectionInstance.DetectionStrings\r\njump :INVALID_LEN_DetectionStrings-%%%~%%% arrDetectionStringsLen \">\" \"5\"\r\n:SET_IPV6_PREFIX-%%%~%%%\r\njump :IPv6StringsDefined-%%%~%%% envDetectionInstance.DetectionIPv6LocalPrefixes \"!=\"\r\njump :EMPTY_IPV6PRFX \"%%%DetectionIPv6LocalPrefixes%%%\" \"=\" \"\" \r\nset envDetectionInstance.DetectionIPv6LocalPrefixes arrDetectionIPv6LocalPrefixes\r\njump :CALL_WSPUT-%%%~%%%\r\n:IPv6StringsDefined-%%%~%%%\r\nadd arrDetectionIPv6LocalPrefixes \",\" arrDetectionIPv6LocalPrefixes\r\nadd envDetectionInstance.DetectionIPv6LocalPrefixes envDetectionInstance.DetectionIPv6LocalPrefixes arrDetectionIPv6LocalPrefixes\r\nmaketoarray envDetectionInstance.DetectionIPv6LocalPrefixes envDetectionInstance.DetectionIPv6LocalPrefixes\r\n:EMPTY_IPV6PRFX\r\nlength arrDetectionIPv6LocalPrefixesLen envDetectionInstance.DetectionIPv6LocalPrefixes\r\njump :INVALID_LEN_DetectionIPv6LocalPrefixes-%%%~%%% arrDetectionIPv6LocalPrefixesLen \">\" \"5\"\r\n:CALL_WSPUT-%%%~%%%\r\nwsput \"AMT_EnvironmentDetectionSettingData\" envDetectionInstance\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nprint \"Environment Detection set successfully\"\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"ERROR: WSMAN call failed: {wsman_result_str}\"\r\njump :end-%%%~%%%\r\n:INVALID_LEN_DetectionStrings-%%%~%%%\r\nprint \"ERROR: detection strings count must be at most 5\"\r\njump :end-%%%~%%%\r\n:INVALID_LEN_DetectionIPv6LocalPrefixes-%%%~%%%\r\nprint \"ERROR: IPv6 prefixes count must be at most 5\"\r\njump :end-%%%~%%%\r\n:EMPTY_DETECTIONSTR-%%%~%%%\r\nprint \"ERROR: %22Detection Strings%22 field cannot be empty, aborting operation...\"\r\n:end-%%%~%%%\r\n set PullRemoteAccess \"1\"\r\nset AMT_EnvironmentDetectionSettingData\r\nset arrDetectionIPv6LocalPrefixes\r\nset arrDetectionStrings\r\nset envDetectionInstance\r\nset ws_general_query\r\nset wsman_answer \r\nset wsman_result", |
| 481 | "vars": { |
| 482 | "DetectionStrings": { |
| 483 | "name": "Detection Strings", |
| 484 | "desc": "A comma separated list of up to 4 strings to use in the environment detection algorithm (e.g. intel.com,contoso.com)", |
| 485 | "type": 1, |
| 486 | "maxlength": 255, |
| 487 | "value": "" |
| 488 | }, |
| 489 | "DetectionIPv6LocalPrefixes": { |
| 490 | "name": "IPv6 Local Prefixes", |
| 491 | "desc": "A comma separated list of IPv6 local prefixes (strings) to use independently of or in conjunction with Detection Strings. (e.g. 1234::/64,4321::/46)", |
| 492 | "type": 1, |
| 493 | "maxlength": 255, |
| 494 | "value": "" |
| 495 | } |
| 496 | } |
| 497 | }, |
| 498 | "AMT-Network-ClearEnvDetection": { |
| 499 | "name": "Network - Clear Environment Detection", |
| 500 | "desc": "Clears the DNS information that is used by Intel AMT to dynamically determine the network it is operating in", |
| 501 | "vars": {}, |
| 502 | "code": "split ws_general_query \"*AMT_EnvironmentDetectionSettingData\" \",\"\nwsbatchenum \"wsman_answer\" ws_general_query\nset envDetectionInstance wsman_answer.AMT_EnvironmentDetectionSettingData.response\nset envDetectionInstance.DetectionStrings undefined\nwsput \"AMT_EnvironmentDetectionSettingData\" envDetectionInstance\njump :error-%%%~%%% wsman_result \"==\" 200\nprint \"Cleared environment detection\"\njump :end-%%%~%%%\n:error-%%%~%%%\nprint \"ERROR: WSMAN call failed: {wsman_result_str}\"\njump :end-%%%~%%%\n:end-%%%~%%%\nset envDetectionInstance\nset ws_general_query\nset AMT_EnvironmentDetectionSettingData\nset PullRemoteAccess \"1\"\nset wsman_answer \nset wsman_result\n" |
| 503 | }, |
| 504 | "AMT-Power-PowerAction": { |
| 505 | "name": "Power - Power Action", |
| 506 | "desc": "Perform an Intel AMT power action", |
| 507 | "code": "set ManagedElementXml \"%3CAddress xmlns=\\%22http://schemas.xmlsoap.org/ws/2004/08/addressing\\%22%3Ehttp://schemas.xmlsoap.org/ws/2004/08/addressing%3C/Address%3E%3CReferenceParameters xmlns=\\%22http://schemas.xmlsoap.org/ws/2004/08/addressing\\%22%3E%3CResourceURI xmlns=\\%22http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd\\%22%3Ehttp://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/CIM_ComputerSystem%3C/ResourceURI%3E%3CSelectorSet xmlns=\\%22http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd\\%22%3E%3CSelector Name=\\%22CreationClassName\\%22%3ECIM_ComputerSystem%3C/Selector%3E%3CSelector Name=\\%22Name\\%22%3EManagedSystem%3C/Selector%3E%3C/SelectorSet%3E%3C/ReferenceParameters%3E\"\r\njsonparse wsargs \"%7B %22PowerState%22:%22%%%powerAction%%%%22, %22ManagedElement%22:%22{ManagedElementXml}%22 %7D\"\r\nset ManagedElementXml\r\nwsexec \"CIM_PowerManagementService\" \"RequestPowerStateChange\" wsargs\r\nset wsargs\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nset PullSystemStatus \"1\"\r\nprint \"Power action completed\"\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"Call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\n", |
| 508 | "vars": { |
| 509 | "powerAction": { |
| 510 | "name": "Power Action", |
| 511 | "desc": "Indicate the power action to perform", |
| 512 | "type": 3, |
| 513 | "values": { |
| 514 | "2": "Power on", |
| 515 | "5": "Power cycle", |
| 516 | "8": "Power down", |
| 517 | "10": "Reset" |
| 518 | }, |
| 519 | "value": "2" |
| 520 | } |
| 521 | } |
| 522 | }, |
| 523 | "AMT-RemoteAccess-AddMpsServerFqdnCert": { |
| 524 | "name": "Remote - Add MPS FQDN/Cert", |
| 525 | "desc": "Add a new CIRA server (MPS) using the server's hostname and authentication using certificate", |
| 526 | "code": "# Get the input from user for the CN to look for\r\n# Get available certificates\r\nsplit ws_general_query \"AMT_PublicKeyCertificate\" ,\r\nwsbatchenum \"wsman_answer\" ws_general_query\r\nlength wsman_ans_length wsman_answer.AMT_PublicKeyCertificate.responses\r\nset i 0\r\n:loop_ans-%%%~%%%\r\n# Get the current subject name\r\nset curSubject wsman_answer.AMT_PublicKeyCertificate.responses.{i}.Subject\r\nIndexOf pos curSubject \"CN=%%%CN%%%\" \r\njump :cnFound-%%%~%%% pos \">=\" 0\r\nadd i i 1\r\njump :loop_ans-%%%~%%% i \"<\" wsman_ans_length\r\njump :cnNotFound-%%%~%%%\r\n:cnFound-%%%~%%%\r\n# Set the reference to the certificate\r\nset certInstanceId wsman_answer.AMT_PublicKeyCertificate.responses.{i}.InstanceID\r\nset certHandle \"%3CAddress%20xmlns=%22http://schemas.xmlsoap.org/ws/2004/08/addressing%22%3Ehttp://schemas.xmlsoap.org/ws/2004/08/addressing%3C/Address%3E%3CReferenceParameters%20xmlns=%22http://schemas.xmlsoap.org/ws/2004/08/addressing%22%3E%3CResourceURI%20xmlns=%22http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd%22%3Ehttp://intel.com/wbem/wscim/1/amt-schema/1/AMT_PublicKeyCertificate%3C/ResourceURI%3E%3CSelectorSet%20xmlns=%22http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd%22%3E%3CSelector%20Name=%22InstanceID%22%3E{certInstanceId}%3C/Selector%3E%3C/SelectorSet%3E%3C/ReferenceParameters%3E\"\r\n# Set method parameters\r\njsonparse wsargs \"%7B%22AccessInfo%22:%22%%%FQDN%%%%22,%22InfoFormat%22:%22201%22,%22Port%22:%%%Port%%%,%22AuthMethod%22:%221%22%7D\"\r\nset wsargs.Certificate certHandle\r\n# Execute call to AddMpServer\r\nwsexec \"AMT_RemoteAccessService\" \"AddMpServer\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nprint \"Management Presence Server (MPS) successfully added\"\r\nset PullRemoteAccess 1\r\njump :end-%%%~%%%\r\n:cnNotFound-%%%~%%%\r\nprint \"Couldn't find a certificate matching the value of CN=%%%CN%%%\"\r\n:error-%%%~%%%\r\nprint \"Call failed with error {wsman_result}\"\r\n:end-%%%~%%%\r\nset AMT_RemoteAccessService\r\nset certHandle\r\nset curSubject\r\nset i\r\nset pos\r\nset ws_general_query\r\nset wsargs\r\nset wsman_answer\r\nset wsman_result\r\nset wsman_result_str\r\nset certInstanceId\r\nset wsman_ans_length", |
| 527 | "vars": { |
| 528 | "FQDN": { |
| 529 | "name": "MPS Hostname", |
| 530 | "desc": "The Fully Qualified Domain Name of the MPS to add", |
| 531 | "type": 1, |
| 532 | "maxlength": 255, |
| 533 | "value": "" |
| 534 | }, |
| 535 | "Port": { |
| 536 | "name": "Port Number", |
| 537 | "desc": "The MPS server port number", |
| 538 | "type": 2, |
| 539 | "maxlength": 5, |
| 540 | "value": "" |
| 541 | }, |
| 542 | "CN": { |
| 543 | "name": "Certificate CN", |
| 544 | "desc": "The common name of the authentication certificate", |
| 545 | "type": 1, |
| 546 | "maxlength": 100, |
| 547 | "value": "" |
| 548 | } |
| 549 | } |
| 550 | }, |
| 551 | "AMT-RemoteAccess-AddMpsServerFqdnUpa": { |
| 552 | "name": "Remote - Add MPS FQDN/User", |
| 553 | "desc": "Add a new CIRA server (MPS) using the server's hostname authentication using username/password", |
| 554 | "code": "# Set method parameters\r\njsonparse wsargs \"%7B%22AccessInfo%22:%22%%%FQDN%%%%22,%22InfoFormat%22:201,%22Port%22:%%%Port%%%,%22AuthMethod%22:2,%22Username%22:%22%%%username%%%%22,%22Password%22:%22%%%password%%%%22%7D\"\r\n# Execute call to AddMpServer\r\nwsexec \"AMT_RemoteAccessService\" \"AddMpServer\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nprint \"Management Presence Server (MPS) successfully added\"\r\nset PullRemoteAccess 1\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"Call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\nset AMT_RemoteAccessService\r\nset certHandle\r\nset curSubject\r\nset i\r\nset pos\r\nset ws_general_query\r\nset wsargs\r\nset wsman_answer\r\nset wsman_result\r\nset wsman_result_str\r\nset certInstanceId\r\nset wsman_ans_length", |
| 555 | "vars": { |
| 556 | "FQDN": { |
| 557 | "name": "MPS Hostname", |
| 558 | "desc": "The Fully Qualified Domain Name of the MPS to add", |
| 559 | "type": 1, |
| 560 | "maxlength": 255, |
| 561 | "value": "" |
| 562 | }, |
| 563 | "Port": { |
| 564 | "name": "Port Number", |
| 565 | "desc": "The MPS server port number", |
| 566 | "type": 2, |
| 567 | "maxlength": 5, |
| 568 | "value": "" |
| 569 | }, |
| 570 | "username": { |
| 571 | "name": "Username", |
| 572 | "desc": "A Username to be used for the connection with the MPS", |
| 573 | "type": 1, |
| 574 | "maxlength": 16, |
| 575 | "value": "" |
| 576 | }, |
| 577 | "password": { |
| 578 | "name": "Password", |
| 579 | "desc": "The Password matching the username above", |
| 580 | "type": 4, |
| 581 | "maxlength": 16, |
| 582 | "value": "" |
| 583 | } |
| 584 | } |
| 585 | }, |
| 586 | "AMT-RemoteAccess-AddMpsIpCertServer": { |
| 587 | "name": "Remote - Add MPS IP/Cert", |
| 588 | "desc": "Add a new CIRA server (MPS) using the server's IP address and authentication using certificate", |
| 589 | "code": "# Get the input from user for the CN to look for\r\n# Get available certificates\r\nsplit ws_general_query \"AMT_PublicKeyCertificate\" ,\r\nwsbatchenum \"wsman_answer\" ws_general_query\r\nlength wsman_ans_length wsman_answer.AMT_PublicKeyCertificate.responses\r\nset i 0\r\n:loop_ans-%%%~%%%\r\n# Get the current subject name\r\nset curSubject wsman_answer.AMT_PublicKeyCertificate.responses.{i}.Subject\r\nIndexOf pos curSubject \"CN=%%%CN%%%\" \r\njump :cnFound-%%%~%%% pos \">=\" 0\r\nadd i i 1\r\njump :loop_ans-%%%~%%% i \"<\" wsman_ans_length\r\njump :cnNotFound-%%%~%%%\r\n:cnFound-%%%~%%%\r\n# Set the reference to the certificate\r\nset certInstanceId wsman_answer.AMT_PublicKeyCertificate.responses.{i}.InstanceID\r\nset certHandle \"%3CAddress%20xmlns=%22http://schemas.xmlsoap.org/ws/2004/08/addressing%22%3Ehttp://schemas.xmlsoap.org/ws/2004/08/addressing%3C/Address%3E%3CReferenceParameters%20xmlns=%22http://schemas.xmlsoap.org/ws/2004/08/addressing%22%3E%3CResourceURI%20xmlns=%22http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd%22%3Ehttp://intel.com/wbem/wscim/1/amt-schema/1/AMT_PublicKeyCertificate%3C/ResourceURI%3E%3CSelectorSet%20xmlns=%22http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd%22%3E%3CSelector%20Name=%22InstanceID%22%3E{certInstanceId}%3C/Selector%3E%3C/SelectorSet%3E%3C/ReferenceParameters%3E\"\r\n# Set method parameters\r\njsonparse wsargs \"%7B%22AccessInfo%22:%22%%%IP%%%%22,%22InfoFormat%22:%223%22,%22Port%22:%%%Port%%%,%22AuthMethod%22:%221%22%7D\"\r\nset wsargs.Certificate certHandle\r\nset wsargs.CN \"%%%ServerName%%%\"\r\n# Execute call to AddMpServer\r\nwsexec \"AMT_RemoteAccessService\" \"AddMpServer\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nprint \"Management Presence Server (MPS) successfully added\"\r\nset PullRemoteAccess 1\r\njump :end-%%%~%%%\r\n:cnNotFound-%%%~%%%\r\nprint \"Couldn't find a certificate matching the value of CN=%%%CN%%%\"\r\n:error-%%%~%%%\r\nprint \"Call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\nset AMT_RemoteAccessService\r\nset certHandle\r\nset curSubject\r\nset i\r\nset pos\r\nset ws_general_query\r\nset wsargs\r\nset wsman_answer\r\nset wsman_result\r\nset wsman_result_str\r\nset certInstanceId\r\nset wsman_ans_length", |
| 590 | "vars": { |
| 591 | "IP": { |
| 592 | "name": "IPv4 Address", |
| 593 | "desc": "The IPv4 address of the MPS server", |
| 594 | "type": 1, |
| 595 | "maxlength": 255, |
| 596 | "value": "" |
| 597 | }, |
| 598 | "Port": { |
| 599 | "name": "Port Number", |
| 600 | "desc": "The MPS server port number", |
| 601 | "type": 2, |
| 602 | "maxlength": 5, |
| 603 | "value": "" |
| 604 | }, |
| 605 | "ServerName": { |
| 606 | "name": "Server Name", |
| 607 | "desc": "The server name, this must be the exact Common Name in the MPS server certificate", |
| 608 | "type": 1, |
| 609 | "maxlength": 255, |
| 610 | "value": "" |
| 611 | }, |
| 612 | "CN": { |
| 613 | "name": "Certificate CN", |
| 614 | "desc": "The common name of the authentication certificate", |
| 615 | "type": 1, |
| 616 | "maxlength": 100, |
| 617 | "value": "" |
| 618 | } |
| 619 | } |
| 620 | }, |
| 621 | "AMT-RemoteAccess-AddMpsIpUpa": { |
| 622 | "name": "Remote - Add MPS IP/User", |
| 623 | "desc": "Add a new CIRA server (MPS) using the servers IP address and authenticating using a username/password", |
| 624 | "code": "# Set method parameters\r\njsonparse wsargs \"%7B%22AccessInfo%22:%22%%%IP%%%%22,%22InfoFormat%22:%223%22,%22Port%22:%%%Port%%%,%22AuthMethod%22:%222%22,%22Username%22:%22%%%username%%%%22,%22Password%22:%22%%%password%%%%22%7D\"\r\nset wsargs.CN \"%%%ServerName%%%\"\r\n# Execute call to AddMpServer\r\nwsexec \"AMT_RemoteAccessService\" \"AddMpServer\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nprint \"Management Presence Server (MPS) successfully added\"\r\nset PullRemoteAccess 1\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"Call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\nset AMT_RemoteAccessService\r\nset wsargs\r\nset wsman_answer\r\nset wsman_result\r\nset wsman_result_str\r\nset wsman_ans_length", |
| 625 | "vars": { |
| 626 | "IP": { |
| 627 | "name": "IPv4 Address", |
| 628 | "desc": "The IPv4 address of the MPS server", |
| 629 | "type": 1, |
| 630 | "maxlength": 255, |
| 631 | "value": "" |
| 632 | }, |
| 633 | "Port": { |
| 634 | "name": "Port Number", |
| 635 | "desc": "The MPS server port number", |
| 636 | "type": 2, |
| 637 | "maxlength": 5, |
| 638 | "value": "" |
| 639 | }, |
| 640 | "ServerName": { |
| 641 | "name": "Server Name", |
| 642 | "desc": "The server name, this must be the exact Common Name in the MPS server certificate", |
| 643 | "type": 1, |
| 644 | "maxlength": 255, |
| 645 | "value": "" |
| 646 | }, |
| 647 | "username": { |
| 648 | "name": "Username", |
| 649 | "desc": "A Username to be used for the connection with the MPS", |
| 650 | "type": 1, |
| 651 | "maxlength": 16, |
| 652 | "value": "" |
| 653 | }, |
| 654 | "password": { |
| 655 | "name": "Password", |
| 656 | "desc": "The Password matching the username above", |
| 657 | "type": 4, |
| 658 | "maxlength": 16, |
| 659 | "value": "" |
| 660 | } |
| 661 | } |
| 662 | }, |
| 663 | "AMT-RemoteAccess-Remove-MPS": { |
| 664 | "name": "Remote - Remove MPS", |
| 665 | "desc": "Remove MPS identified by its IP/FQDN and port", |
| 666 | "code": "split ws_general_query \"AMT_ManagementPresenceRemoteSAP\" ,\r\nwsbatchenum \"wsman_answer\" ws_general_query\r\nset i 0\r\nset arr wsman_answer.AMT_ManagementPresenceRemoteSAP.responses\r\nLength arr_len arr\r\n:loop-%%%~%%%\r\nset curAccessInfo arr.{i}.AccessInfo\r\nadd curAccessInfo curAccessInfo \":\"\r\nadd curAccessInfo curAccessInfo arr.{i}.Port\r\njump :mpsFound-%%%~%%% curAccessInfo \"=\" \"%%%AccessInfo%%%:%%%Port%%%\"\r\nadd i i 1\r\njump :loop-%%%~%%% i \"<\" arr_len\r\nprint \"No MPS was found matching the input parameters\"\r\njump :end-%%%~%%%\r\n:mpsFound-%%%~%%%\r\nprint \"Found matching MPS, starting removal process\"\r\nset instanceName wsman_answer.AMT_ManagementPresenceRemoteSAP.responses.{i}.Name\r\nset selector \"%3Cw:SelectorSet%3E%3Cw:Selector%20Name=%22Name%22%3E{instanceName}%3C/w:Selector%3E%3C/w:SelectorSet%3E\"\r\nwsdelete \"AMT_ManagementPresenceRemoteSAP\" selector\r\n:end-%%%~%%%\r\nset AMT_ManagementPresenceRemoteSAP\r\nset arr\r\nset curAccessInfo\r\nset i\r\nset instanceName\r\nset selector\r\nset ws_general_query\r\nset wsman_answer\r\nset wsman_result\r\nset wsman_result_str\r\nset arr_len\r\nset PullRemoteAccess 1", |
| 667 | "vars": { |
| 668 | "AccessInfo": { |
| 669 | "name": "FQDN/Address", |
| 670 | "desc": "The FQDN/IPv4 address of the MPS server to be deleted", |
| 671 | "type": 1, |
| 672 | "maxlength": 255, |
| 673 | "value": "" |
| 674 | }, |
| 675 | "Port": { |
| 676 | "name": "Port Number", |
| 677 | "desc": "The MPS server port number", |
| 678 | "type": 2, |
| 679 | "maxlength": 5, |
| 680 | "value": "" |
| 681 | } |
| 682 | } |
| 683 | }, |
| 684 | "AMT-RemoteAccess-RemoveAll-MPS": { |
| 685 | "name": "Remote - Remove All MPS", |
| 686 | "desc": "Remove all MPS", |
| 687 | "vars": { }, |
| 688 | "code": "split ws_general_query \"AMT_ManagementPresenceRemoteSAP\" ,\nwsbatchenum \"wsman_answer\" ws_general_query\nset i 0\nset arr wsman_answer.AMT_ManagementPresenceRemoteSAP.responses\nLength arr_len arr\njump :end-%%%~%%% arr_len \"=\" 0\n:loop-%%%~%%%\nset instanceName wsman_answer.AMT_ManagementPresenceRemoteSAP.responses.{i}.Name\nset selector \"%3Cw:SelectorSet%3E%3Cw:Selector%20Name=%22Name%22%3E{instanceName}%3C/w:Selector%3E%3C/w:SelectorSet%3E\"\nwsdelete \"AMT_ManagementPresenceRemoteSAP\" selector\nadd i i 1\njump :loop-%%%~%%% i \"<\" arr_len\n:end-%%%~%%%\nset AMT_ManagementPresenceRemoteSAP\nset arr\nset i\nset instanceName\nset selector\nset ws_general_query\nset wsman_answer\nset wsman_result\nset wsman_result_str\nset arr_len\nset PullRemoteAccess 1\n\n" |
| 689 | }, |
| 690 | "AMT-RemoteAccess-AddRemoteAccessPolicyRule": { |
| 691 | "name": "Remote - Add Trigger (User / Alert)", |
| 692 | "desc": "Set a remote access trigger policy, used to establish a secure tunnel between a management console and the Intel AMT platform.", |
| 693 | "code": "# *** Prepare arguments for AMT_RemoteAccessService.AddRemoteAccessPolicyRule ***\r\njsonparse ws_args \"%7B%22Trigger%22:%220%22,%22TunnelLifeTime%22:%22%%%tLifeTime%%%%22%7D\"\r\n# *** Verify valid input ***\r\njump :VALID_INPUT \"%%%AccessInfo1%%%\" \"!=\" \"\"\r\nprint \"ERROR: Field %22AccessInfo1%22 must not be empty, aborting operation...\"\r\njump :end-%%%~%%%\r\n:VALID_INPUT\r\n# *** Set a EPR selector matching user input ***\r\nsplit ws_general_query \"AMT_ManagementPresenceRemoteSAP\" ,\r\nwsbatchenum \"wsman_answer\" ws_general_query\r\nset i 0\r\nset arr wsman_answer.AMT_ManagementPresenceRemoteSAP.responses\r\nLength arr_len arr\r\nset mpsEpr1 \"*\"\r\nset mpsEpr2 \"*\"\r\n:loop-%%%~%%%\r\nset curAccessInfo arr.{i}.AccessInfo\r\nadd curAccessInfo curAccessInfo \":\"\r\nadd curAccessInfo curAccessInfo arr.{i}.Port\r\njump :MPS1_NO_MATCH curAccessInfo \"!=\" \"%%%AccessInfo1%%%\"\r\nset mpsEpr1 wsman_answer.AMT_ManagementPresenceRemoteSAP.responses.{i}.Name\r\nprint \"Found matching (primary) mps: {mpsEpr1}\"\r\njump :MPS2_NOTSET \"%%%AccessInfo2%%%\" \"=\" \"\"\r\n:MPS1_NO_MATCH\r\njump :MPS2_NO_MATCH curAccessInfo \"!=\" \"%%%AccessInfo2%%%\"\r\nset mpsEpr2 wsman_answer.AMT_ManagementPresenceRemoteSAP.responses.{i}.Name\r\nprint \"Found matching (secondary) mps: {mpsEpr2}\"\r\n:MPS2_NO_MATCH\r\nadd i i 1\r\njump :loop-%%%~%%% i \"<\" arr_len\r\n:MPS2_NOTSET\r\njump :MPS1_FOUND mpsEpr1 \"!=\" \"*\"\r\nprint \"ERROR: MPS server: %22%%%AccessInfo1%%%%22 could not be found, aborting operation...\"\r\njump :end-%%%~%%%\r\n:MPS1_FOUND\r\njump :MPS2_FOUND \"%%%AccessInfo2%%%\" \"=\" \"\"\r\njump :MPS2_FOUND mpsEpr2 \"!=\" \"*\"\r\nprint \"ERROR: MPS server: %22%%%AccessInfo2%%%%22 could not be found, aborting operation...\"\r\njump :end-%%%~%%%\r\n:MPS2_FOUND\r\nprint \"Setting policy...\"\r\njsonparse ws_args.MpServer \"%7B%7D\"\r\nset MpServer \"%3CAddress%20xmlns=%22http://schemas.xmlsoap.org/ws/2004/08/addressing%22%3Ehttp://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous%3C/Address%3E%3CReferenceParameters%20xmlns=%22http://schemas.xmlsoap.org/ws/2004/08/addressing%22%3E%3CResourceURI%20xmlns=%22http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd%22%3Ehttp://intel.com/wbem/wscim/1/amt-schema/1/AMT_ManagementPresenceRemoteSAP%3C/ResourceURI%3E%3CSelectorSet%20xmlns=%22http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd%22%3E%3CSelector%20Name=%22Name%22%3E{mpsEpr1}%3C/Selector%3E%3C/SelectorSet%3E%3C/ReferenceParameters%3E\"\r\njump :SKIP_ADD_MPS2 \"%%%AccessInfo2%%%\" \"=\" \"\"\r\nadd MpServer MpServer \"|%3CAddress%20xmlns=%22http://schemas.xmlsoap.org/ws/2004/08/addressing%22%3Ehttp://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous%3C/Address%3E%3CReferenceParameters%20xmlns=%22http://schemas.xmlsoap.org/ws/2004/08/addressing%22%3E%3CResourceURI%20xmlns=%22http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd%22%3Ehttp://intel.com/wbem/wscim/1/amt-schema/1/AMT_ManagementPresenceRemoteSAP%3C/ResourceURI%3E%3CSelectorSet%20xmlns=%22http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd%22%3E%3CSelector%20Name=%22Name%22%3E{mpsEpr2}%3C/Selector%3E%3C/SelectorSet%3E%3C/ReferenceParameters%3E\"\r\n:SKIP_ADD_MPS2\r\nsplit ws_args.MpServer MpServer \"|\"\r\n# *** Call AMT_RemoteAccessService.AddRemoteAccessPolicyRule with policy details. ***\r\nwsexec \"AMT_RemoteAccessService\" \"AddRemoteAccessPolicyRule\" ws_args selector\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nprint \"Policy added successfully\"\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"WSMAN call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\nset PullRemoteAccess 1\r\nset mpsEpr1\r\nset mpsEpr2\r\nset i\r\nset curAccessInfo\r\nset arr_len\r\nset MpServer\r\nset arr\r\nset AMT_RemoteAccessService\r\nset wsman_result\r\nset wsman_result_str\r\nset ws_args\r\nset ws_general_query\r\nset wsman_answer", |
| 694 | "vars": { |
| 695 | "AccessInfo1": { |
| 696 | "name": "MPS 1 Address", |
| 697 | "desc": "The FQDN/IPv4 & Port of the MPS targeted for this policy. (e.g. mps1.mydomain.com:1234, 1.2.3.4:2233)", |
| 698 | "type": 1, |
| 699 | "maxlength": 255, |
| 700 | "value": "" |
| 701 | }, |
| 702 | "AccessInfo2": { |
| 703 | "name": "MPS 2 Address", |
| 704 | "desc": "Optional, leave empty value if not applicable. Sames as above. In case you wish to apply this policy to 2 (two) mps instances", |
| 705 | "type": 1, |
| 706 | "maxlength": 255, |
| 707 | "value": "" |
| 708 | }, |
| 709 | "Trigger": { |
| 710 | "name": "Trigger", |
| 711 | "desc": "The event that will trigger the establishment of the remote connection to the MPS.", |
| 712 | "type": 3, |
| 713 | "values": { |
| 714 | "0": "User Initiated", |
| 715 | "1": "Alert" |
| 716 | }, |
| 717 | "value": "0" |
| 718 | }, |
| 719 | "tLifeTime": { |
| 720 | "name": "Tunnel Lifetime", |
| 721 | "desc": "Defines the tunnel�s lifetime in seconds. A value of 0 means that the tunnel should stay open until it is closed by the server, the CloseRemoteAccessConnection method or when a different policy with a higher priority needs to be processed.", |
| 722 | "type": 2, |
| 723 | "maxlength": 5, |
| 724 | "value": "0" |
| 725 | } |
| 726 | } |
| 727 | }, |
| 728 | "AMT-RemoteAccess-AddRemoteAccessPolicyRule2": { |
| 729 | "name": "Remote - Add Trigger (Periodic)", |
| 730 | "desc": "Set a remote access trigger policy, used to establish a secure tunnel between a management console and the Intel AMT platform.", |
| 731 | "code": "# *** Verify valid input ***\r\nsplit period_arr \"%%%Period%%%\" \":\"\r\nlength period_arr_len period_arr\r\njump :INVALID_ARG_AccessInfo1 \"%%%AccessInfo1%%%\" \"=\" \"\"\r\njump :DailyPeriod \"%%%PeriodType%%%\" \"!=\" \"0\"\r\njump :INVALID_PeriodType \"%%%PeriodType%%%\" \"!=\" \"0\"\r\njump :INVALID_ARG_Period period_arr.0 \"<=\" \"0\"\r\njump :INVALID_ARG_Period period_arr.0 \">\" \"4294967295\"\r\nIntToStr extendedData \"0\"\r\nIntToStr bPeriod period_arr.0\r\nadd extendedData extendedData bPeriod\r\njump :SET_PERIOD\r\n:DailyPeriod\r\njump :INVALID_PeriodType period_arr_len \"!=\" \"2\"\r\njump :INVALID_ARG_PeriodDaily period_arr.0 \"<=\" \"0\"\r\njump :INVALID_ARG_PeriodDaily period_arr.0 \">\" \"23\"\r\njump :INVALID_ARG_PeriodDaily period_arr.1 \">\" \"59\"\r\njump :INVALID_ARG_PeriodDaily period_arr.1 \"<=\" \"0\"\r\nIntToStr extendedData \"1\"\r\nIntToStr bPeriodHour period_arr.0\r\nIntToStr bPeriodMinute period_arr.1\r\nadd extendedData extendedData bPeriodHour\r\nadd extendedData extendedData bPeriodMinute\r\njump :SET_PERIOD\r\n:INVALID_PeriodType\r\nprint \"ERROR: The period type and value must correspond, aborting operation...\"\r\njump :end-%%%~%%%\r\n:INVALID_ARG_PeriodDaily\r\nprint \"ERROR: Field %22Period%22 must be a value HH:MM 0<=HH<24 && 0<=MM<60, aborting operation...\"\r\njump :end-%%%~%%%\r\n:INVALID_ARG_AccessInfo1\r\nprint \"ERROR: Field %22AccessInfo1%22 must not be empty, aborting operation...\"\r\njump :end-%%%~%%%\r\n:INVALID_ARG_Period\r\nprint \"ERROR: Field %22Period%22 must be a value 0<=t<MAX_INT, aborting operation...\"\r\njump :end-%%%~%%%\r\n:SET_PERIOD\r\n# *** Prepare arguments for AMT_RemoteAccessService.AddRemoteAccessPolicyRule ***\r\njsonparse ws_args \"%7B%22Trigger%22:%222%22,%22TunnelLifeTime%22:%22%%%tLifeTime%%%%22%7D\"\r\nbtoa extendedData extendedData\r\nset ws_args.ExtendedData extendedData\r\n# *** Set a EPR selector matching user input ***\r\nsplit ws_general_query \"AMT_ManagementPresenceRemoteSAP\" ,\r\nwsbatchenum \"wsman_answer\" ws_general_query\r\nset i 0\r\nset arr wsman_answer.AMT_ManagementPresenceRemoteSAP.responses\r\nLength arr_len arr\r\nset mpsEpr1 \"*\"\r\nset mpsEpr2 \"*\"\r\n:loop-%%%~%%%\r\nset curAccessInfo arr.{i}.AccessInfo\r\nadd curAccessInfo curAccessInfo \":\"\r\nadd curAccessInfo curAccessInfo arr.{i}.Port\r\njump :MPS1_NO_MATCH curAccessInfo \"!=\" \"%%%AccessInfo1%%%\"\r\nset mpsEpr1 wsman_answer.AMT_ManagementPresenceRemoteSAP.responses.{i}.Name\r\nprint \"Found matching (primary) mps: {mpsEpr1}\"\r\njump :MPS2_NOTSET \"%%%AccessInfo2%%%\" \"=\" \"\"\r\n:MPS1_NO_MATCH\r\njump :MPS2_NO_MATCH curAccessInfo \"!=\" \"%%%AccessInfo2%%%\"\r\nset mpsEpr2 wsman_answer.AMT_ManagementPresenceRemoteSAP.responses.{i}.Name\r\nprint \"Found matching (secondary) mps: {mpsEpr2}\"\r\n:MPS2_NO_MATCH\r\nadd i i 1\r\njump :loop-%%%~%%% i \"<\" arr_len\r\n:MPS2_NOTSET\r\njump :MPS1_FOUND mpsEpr1 \"!=\" \"*\"\r\nprint \"ERROR: MPS server: %22%%%AccessInfo1%%%%22 could not be found, aborting operation...\"\r\njump :end-%%%~%%%\r\n:MPS1_FOUND\r\njump :MPS2_FOUND \"%%%AccessInfo2%%%\" \"=\" \"\"\r\njump :MPS2_FOUND mpsEpr2 \"!=\" \"*\"\r\nprint \"ERROR: MPS server: %22%%%AccessInfo2%%%%22 could not be found, aborting operation...\"\r\njump :end-%%%~%%%\r\n:MPS2_FOUND\r\nprint \"Setting policy...\"\r\njsonparse ws_args.MpServer \"%7B%7D\"\r\nset MpServer \"%3CAddress%20xmlns=%22http://schemas.xmlsoap.org/ws/2004/08/addressing%22%3Ehttp://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous%3C/Address%3E%3CReferenceParameters%20xmlns=%22http://schemas.xmlsoap.org/ws/2004/08/addressing%22%3E%3CResourceURI%20xmlns=%22http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd%22%3Ehttp://intel.com/wbem/wscim/1/amt-schema/1/AMT_ManagementPresenceRemoteSAP%3C/ResourceURI%3E%3CSelectorSet%20xmlns=%22http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd%22%3E%3CSelector%20Name=%22Name%22%3E{mpsEpr1}%3C/Selector%3E%3C/SelectorSet%3E%3C/ReferenceParameters%3E\"\r\njump :SKIP_ADD_MPS2 \"%%%AccessInfo2%%%\" \"=\" \"\"\r\nadd MpServer MpServer \"|%3CAddress%20xmlns=%22http://schemas.xmlsoap.org/ws/2004/08/addressing%22%3Ehttp://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous%3C/Address%3E%3CReferenceParameters%20xmlns=%22http://schemas.xmlsoap.org/ws/2004/08/addressing%22%3E%3CResourceURI%20xmlns=%22http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd%22%3Ehttp://intel.com/wbem/wscim/1/amt-schema/1/AMT_ManagementPresenceRemoteSAP%3C/ResourceURI%3E%3CSelectorSet%20xmlns=%22http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd%22%3E%3CSelector%20Name=%22Name%22%3E{mpsEpr2}%3C/Selector%3E%3C/SelectorSet%3E%3C/ReferenceParameters%3E\"\r\n:SKIP_ADD_MPS2\r\nsplit ws_args.MpServer MpServer \"|\"\r\n# *** Call AMT_RemoteAccessService.AddRemoteAccessPolicyRule with policy details. ***\r\nwsexec \"AMT_RemoteAccessService\" \"AddRemoteAccessPolicyRule\" ws_args selector\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nprint \"Policy added successfully\"\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"WSMAN call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\nset PullRemoteAccess 1\r\nset mpsEpr1\r\nset mpsEpr2\r\nset i\r\nset curAccessInfo\r\nset arr_len\r\nset MpServer\r\nset arr\r\nset AMT_RemoteAccessService\r\nset wsman_result\r\nset wsman_result_str\r\nset ws_args\r\nset ws_general_query\r\nset wsman_answer\r\nset bPeriod\r\nset extendedData\r\nset period_arr\r\nset period_arr_len\r\nset bPeriodHour\r\nset bPeriodMinute", |
| 732 | "vars": { |
| 733 | "AccessInfo1": { |
| 734 | "name": "MPS 1 Address", |
| 735 | "desc": "The FQDN/IPv4 & Port of the MPS targeted for this policy. (e.g. mps1.mydomain.com:1234, 1.2.3.4:2233)", |
| 736 | "type": 1, |
| 737 | "maxlength": 255, |
| 738 | "value": "" |
| 739 | }, |
| 740 | "AccessInfo2": { |
| 741 | "name": "MPS 2 Address", |
| 742 | "desc": "Optional, leave empty if not applicable. Sames as above. In case you wish to apply this policy to 2 (two) mps instances", |
| 743 | "type": 1, |
| 744 | "maxlength": 255, |
| 745 | "value": "" |
| 746 | }, |
| 747 | "PeriodType": { |
| 748 | "name": "Interval Type", |
| 749 | "desc": "Defines the idle periods of the connection. Data can be in one of two formats: periodic interval (seconds) or daily interval (HH:MM).", |
| 750 | "type": 3, |
| 751 | "values": { |
| 752 | "0": "Periodic (Seconds)", |
| 753 | "1": "Daily (HH:MM)" |
| 754 | }, |
| 755 | "value": "0" |
| 756 | }, |
| 757 | "Period": { |
| 758 | "name": "Interval Value", |
| 759 | "desc": "Set the interval to an integer value (0 <= t < MAX_INT in seconds) or a time format (HH:MM s.t 0 <= HH < 24, 0 <= MM < 60) depending on the selection above", |
| 760 | "type": 1, |
| 761 | "maxlength": 11, |
| 762 | "value": "" |
| 763 | }, |
| 764 | "tLifeTime": { |
| 765 | "name": "Tunnel Lifetime", |
| 766 | "desc": "Defines the tunnel�s lifetime in seconds. A value of 0 means that the tunnel should stay open until it is closed by the CloseRemoteAccessConnection method or when a different policy with a higher priority needs to be processed.", |
| 767 | "type": 2, |
| 768 | "maxlength": 5, |
| 769 | "value": "0" |
| 770 | } |
| 771 | } |
| 772 | }, |
| 773 | "AMT-RemoteAccess-RemoveAccessPolicyRule": { |
| 774 | "name": "Remote - Remove Trigger", |
| 775 | "desc": "Removes the remote access trigger policies", |
| 776 | "code": "jsonparse hMapPolicies \"%7B%220%22:%20%22User%20Initiated%22,%09%221%22:%20%22Alert%22,%20%222%22:%20%22Periodic%22%7D\"\r\nsplit policiesArr \"%%%policies%%%\" \",\"\r\nlength policiesArrLen policiesArr\r\nset i 0\r\n:loop-%%%~%%%\r\nset curPolicy hMapPolicies.{policiesArr.{i}}\r\njsonparse ws_args \"%7B%22PolicyRuleName%22:%22{curPolicy}%22%7D\"\r\nwsdelete \"AMT_RemoteAccessPolicyRule\" ws_args\r\nadd i i 1\r\njump :loop-%%%~%%% i \"<\" policiesArrLen\r\nprint \"Policies removed successfully\"\r\nset PullRemoteAccess 1\r\nset AMT_RemoteAccessPolicyRule\r\nset curPolicy\r\nset hMapPolicies\r\nset i\r\nset policiesArr\r\nset policiesArrLen\r\nset ws_args\r\nset wsman_result", |
| 777 | "vars": { |
| 778 | "policies": { |
| 779 | "name": "Policies", |
| 780 | "desc": "Set policies to be removed", |
| 781 | "type": 5, |
| 782 | "values": { |
| 783 | "0": "User Initiated", |
| 784 | "1": "Alert", |
| 785 | "2": "Periodic" |
| 786 | }, |
| 787 | "value": [ |
| 788 | "" |
| 789 | ] |
| 790 | } |
| 791 | } |
| 792 | }, |
| 793 | "AMT-RemoteAccess-SetUserInterface": { |
| 794 | "name": "Remote - Set User Initiation", |
| 795 | "desc": "A local or user or application may initiation the Intel AMT Client Initiation Remote Access (CIRA) connection to the server. Use this script block to enabled or disable this feature.", |
| 796 | "code": "# Set method parameters\r\njsonparse wsargs \"%7B%22RequestedState%22:%22%%%ReqState%%%%22%7D\"\r\njsonparse EnumState \"%7B%2232768%22:%22Disabled%22,%2232769%22:%22BIOS Enabled%22,%2232770%22:%22OS enable%22,%2232771%22:%22BIOS & OS Enabed%22%7D\"\r\n# Execute call to change the state\r\nwsexec \"AMT_UserInitiatedConnectionService\" \"RequestStateChange\" wsargs \"\"\r\njump :error-%%%~%%% wsman_result \"!=\" 200\r\nprint \"SUCCESS: Remote Access user interfaces set to: {EnumState.%%%ReqState%%%}\"\r\n\r\nset PullRemoteAccess 1\r\njump :end-%%%~%%%\r\n:error-%%%~%%%\r\nprint \"Call failed: {wsman_result_str}\"\r\n:end-%%%~%%%\r\nset wsargs\r\nset wsman_result\r\nset wsman_result_str\r\nset EnumState\r\nset AMT_UserInitiatedConnectionService", |
| 797 | "vars": { |
| 798 | "ReqState": { |
| 799 | "name": "User Initiation", |
| 800 | "desc": "Select the configuration to be set for Remote Access user initiated interface", |
| 801 | "type": 3, |
| 802 | "values": { |
| 803 | "32768": "Disabled", |
| 804 | "32769": "BIOS only", |
| 805 | "32770": "OS only", |
| 806 | "32771": "BIOS & OS" |
| 807 | }, |
| 808 | "value": "32771" |
| 809 | } |
| 810 | } |
| 811 | }, |
| 812 | "AMT-Security-AddCertificate": { |
| 813 | "name": "Security - Add Certificate", |
| 814 | "desc": "Add a trusted or chain certificate to Intel AMT certificate store.", |
| 815 | "code": "jsonparse wsargs \"%7B%7D\"\r\nset wsargs.CertificateBlob \"%%%CertBin%%%\"\r\njump :certroot %%%CertType%%% \"=\" 1\r\nprint \"Adding certificate...\"\r\nwsexec \"AMT_PublicKeyManagementService\" \"AddCertificate\" wsargs\r\njump :certdone\r\n:certroot\r\nprint \"Adding root certificate...\"\r\nwsexec \"AMT_PublicKeyManagementService\" \"AddTrustedRootCertificate\" wsargs\r\n:certdone\r\nset wsargs\r\nset AMT_PublicKeyManagementService\r\nset PullCertificates 1\r\n", |
| 816 | "vars": { |
| 817 | "CertType": { |
| 818 | "name": "Certificate Type", |
| 819 | "desc": "Select if this is a certificate that should be used by Intel AMT as trusted root.", |
| 820 | "type": 3, |
| 821 | "values": { |
| 822 | "0": "Chain Certificate", |
| 823 | "1": "Trusted Root Certificate" |
| 824 | }, |
| 825 | "value": "0" |
| 826 | }, |
| 827 | "CertBin": { |
| 828 | "name": "Certificate", |
| 829 | "desc": "A .cer file, this is the certificate that will be uploaded to Intel AMT.", |
| 830 | "type": 6 |
| 831 | } |
| 832 | } |
| 833 | }, |
| 834 | "AMT-Security-IssueUntrustedCertificate": { |
| 835 | "name": "Security - Issue Untrusted Certificate", |
| 836 | "desc": "Create a run Intel AMT certificate with private key that is signed by an untrusted dummy root.", |
| 837 | "code": "jump :certificateSupport-%%%~%%% _certificates \"=\" 1\nprint \"ERROR: No certificate support, this script block can't run in thei environment\"\njump :end2-%%%~%%%\n:certificateSupport-%%%~%%%\n\nset CommonName \"%%%CommonName%%%\"\"\nlength x CommonName \njump :skipSetCommonName-%%%~%%% x \"!=\" 0\n\nsplit ws_general_query \"*AMT_GeneralSettings\" ,\nwsbatchenum \"wsman_answer\" ws_general_query\njump :error-%%%~%%% wsman_result \"!=\" 200\nset CommonName \"{wsman_answer.AMT_GeneralSettings.response.HostName}\"\nlength x CommonName \njump :skipSetDomainName-%%%~%%% x \"=\" 0\nset CommonName \"{wsman_answer.AMT_GeneralSettings.response.HostName}.{wsman_answer.AMT_GeneralSettings.response.DomainName}\"\n:skipSetDomainName-%%%~%%%\n:skipSetCommonName-%%%~%%%\n\njsonparse certattributes \"%7B %22CN%22:%22{CommonName}%22, %22O%22:%22%%%Organization%%%%22, %22ST%22:%22%%%StateProvince%%%%22, %22C%22:%22%%%Country%%%%22 %7D\"\njsonparse wsargs \"%7B %22KeyAlgorithm%22:%220%22, %22KeyLength%22:%222048%22 %7D\"\nwsexec \"AMT_PublicKeyManagementService\" \"GenerateKeyPair\" wsargs\njump :error-%%%~%%% wsman_result \"!=\" 200\nset selector AMT_PublicKeyManagementService.Body.KeyPair.ReferenceParameters.SelectorSet.Selector.Value\nsplit ws_query \"AMT_PublicPrivateKeyPair\" ,\nwsbatchenum \"wsman_answer\" ws_query\njump :error-%%%~%%% wsman_result \"!=\" 200\ngetitem i wsman_answer.AMT_PublicPrivateKeyPair.responses \"InstanceID\" selector\nset DERKey wsman_answer.AMT_PublicPrivateKeyPair.responses.{i}.DERKey\nsignwithdummyca DERKey certattributes\njsonparse wsargs \"%7B %22CertificateBlob%22:%22{signed_cert}%22 %7D\"\nwsexec \"AMT_PublicKeyManagementService\" \"AddCertificate\" wsargs\njump :error-%%%~%%% wsman_result \"!=\" 200\njump :end-%%%~%%%\n:error-%%%~%%%\nprint \"Call failed: {wsman_result_str}\"\n:end-%%%~%%%\nset PullCertificates 1\n:end2-%%%~%%%\n\nset i\nset x\nset wsman_answer\nset selector\nset AMT_PublicKeyManagementService\nset ws_query\nset AMT_PublicKeyManagementService\nset DERKey\nset wsargs\n", |
| 838 | "vars": { |
| 839 | "CommonName": { |
| 840 | "name": "Common Name", |
| 841 | "desc": "Common name of the certificate, leave blank to use the Intel AMT host and domain name", |
| 842 | "type": 1, |
| 843 | "maxlength": 255, |
| 844 | "value": "" |
| 845 | }, |
| 846 | "Organization": { |
| 847 | "name": "Organization", |
| 848 | "desc": "Certificate organization name", |
| 849 | "type": 1, |
| 850 | "maxlength": 255, |
| 851 | "value": "" |
| 852 | }, |
| 853 | "StateProvince": { |
| 854 | "name": "State/Province", |
| 855 | "desc": "Certificate state or province name", |
| 856 | "type": 1, |
| 857 | "maxlength": 255, |
| 858 | "value": "" |
| 859 | }, |
| 860 | "Country": { |
| 861 | "name": "Country", |
| 862 | "desc": "Certificate country name", |
| 863 | "type": 1, |
| 864 | "maxlength": 255, |
| 865 | "value": "" |
| 866 | } |
| 867 | } |
| 868 | } |
| 869 | }, |
| 870 | "scriptBlocks": [ |
| 871 | { |
| 872 | "name": "Remote - Remove Trigger", |
| 873 | "desc": "Removes the remote access trigger policies", |
| 874 | "code": "jsonparse hMapPolicies \"%7B%220%22:%20%22User%20Initiated%22,%09%221%22:%20%22Alert%22,%20%222%22:%20%22Periodic%22%7D\"\r\nsplit policiesArr \"%%%policies%%%\" \",\"\r\nlength policiesArrLen policiesArr\r\nset i 0\r\n:loop-%%%~%%%\r\nset curPolicy hMapPolicies.{policiesArr.{i}}\r\njsonparse ws_args \"%7B%22PolicyRuleName%22:%22{curPolicy}%22%7D\"\r\nwsdelete \"AMT_RemoteAccessPolicyRule\" ws_args\r\nadd i i 1\r\njump :loop-%%%~%%% i \"<\" policiesArrLen\r\nprint \"Policies removed successfully\"\r\nset PullRemoteAccess 1\r\nset AMT_RemoteAccessPolicyRule\r\nset curPolicy\r\nset hMapPolicies\r\nset i\r\nset policiesArr\r\nset policiesArrLen\r\nset ws_args\r\nset wsman_result", |
| 875 | "vars": { |
| 876 | "policies": { |
| 877 | "name": "Policies", |
| 878 | "desc": "Set policies to be removed", |
| 879 | "type": 5, |
| 880 | "values": { |
| 881 | "0": "User Initiated", |
| 882 | "1": "Alert", |
| 883 | "2": "Periodic" |
| 884 | }, |
| 885 | "value": [ |
| 886 | "0", |
| 887 | "1", |
| 888 | "2" |
| 889 | ] |
| 890 | } |
| 891 | }, |
| 892 | "id": 0.568683385848999, |
| 893 | "xname": "AMT-RemoteAccess-RemoveAccessPolicyRule" |
| 894 | }, |
| 895 | { |
| 896 | "name": "Remote - Remove All MPS", |
| 897 | "desc": "Remove all MPS", |
| 898 | "vars": {}, |
| 899 | "code": "split ws_general_query \"AMT_ManagementPresenceRemoteSAP\" ,\nwsbatchenum \"wsman_answer\" ws_general_query\nset i 0\nset arr wsman_answer.AMT_ManagementPresenceRemoteSAP.responses\nLength arr_len arr\njump :end-%%%~%%% arr_len \"=\" 0\n:loop-%%%~%%%\nset instanceName wsman_answer.AMT_ManagementPresenceRemoteSAP.responses.{i}.Name\nset selector \"%3Cw:SelectorSet%3E%3Cw:Selector%20Name=%22Name%22%3E{instanceName}%3C/w:Selector%3E%3C/w:SelectorSet%3E\"\nwsdelete \"AMT_ManagementPresenceRemoteSAP\" selector\nadd i i 1\njump :loop-%%%~%%% i \"<\" arr_len\n:end-%%%~%%%\nset AMT_ManagementPresenceRemoteSAP\nset arr\nset i\nset instanceName\nset selector\nset ws_general_query\nset wsman_answer\nset wsman_result\nset wsman_result_str\nset arr_len\nset PullRemoteAccess 1\n", |
| 900 | "id": 0.2631003668066114, |
| 901 | "xname": "AMT-RemoteAccess-RemoveAll-MPS" |
| 902 | }, |
| 903 | { |
| 904 | "name": "Network - Clear Environment Detection", |
| 905 | "desc": "Clears the DNS information that is used by Intel AMT to dynamically determine the network it is operating in", |
| 906 | "vars": {}, |
| 907 | "code": "split ws_general_query \"*AMT_EnvironmentDetectionSettingData\" \",\"\nwsbatchenum \"wsman_answer\" ws_general_query\nset envDetectionInstance wsman_answer.AMT_EnvironmentDetectionSettingData.response\nset envDetectionInstance.DetectionStrings undefined\nwsput \"AMT_EnvironmentDetectionSettingData\" envDetectionInstance\njump :error-%%%~%%% wsman_result \"==\" 200\nprint \"Cleared environment detection\"\njump :end-%%%~%%%\n:error-%%%~%%%\nprint \"ERROR: WSMAN call failed: {wsman_result_str}\"\njump :end-%%%~%%%\n:end-%%%~%%%\nset envDetectionInstance\nset ws_general_query\nset AMT_EnvironmentDetectionSettingData\nset PullRemoteAccess \"1\"\nset wsman_answer \nset wsman_result\n", |
| 908 | "id": 0.5554483488667756, |
| 909 | "xname": "AMT-Network-ClearEnvDetection" |
| 910 | } |
| 911 | ] |
| 912 | } |