Skip to main content
Rotate the password of a local account on HP Integrated Lights-Out (iLO), the management interface of HP servers, on a schedule. Infisical generates a new password, sets it on the iLO, and stores the account’s username and password in the Infisical secrets you choose. The rotation works with either of two app connections: an HPE iLO connection, which changes the password through the iLO’s Redfish API over HTTPS, or an SSH connection, which runs iLO commands over SSH. To decide which one to use, see Choose an app connection.
Rotation Type: Single-PhaseThis rotation updates one set of credentials in place, so the previous password stops working as soon as the rotation finishes. Clients that still use the previous password can’t sign in until they read the new password from Infisical. An iLO account has only one password, so Infisical can’t keep the previous password valid during a rotation.
iLO password lengthHP iLO accepts passwords of at most 39 characters. The default password requirements for this rotation (39 characters, no symbols) fit that limit. If you change the password requirements, keep Password Length at 39 or lower.

Choose an app connection

If your server has iLO 7, use an HPE iLO connection, because Infisical can’t rotate iLO 7 passwords over SSH.
Infisical signs in to the iLO over SSH and runs the iLO command that sets the target account’s password. Rotation Method decides which account signs in:
  • Login As Root: Infisical signs in with the SSH connection’s credentials and changes the target account’s password
  • Login As Target: Infisical signs in as the target account with the account’s current password, and the account changes its own password
After the change, Infisical signs in over SSH as the target account with the new password to check that the password works, then saves the username and password to the mapped secrets.

Prerequisites

  • A project with secrets configured
  • An iLO local account for the app connection, separate from the account you rotate
  • Permission for the app connection’s account to change the rotated account’s password (not needed if you use an SSH connection with Login As Target)
  • Network access from Infisical to the iLO, directly or through a Gateway, if network restrictions apply: HTTPS for an HPE iLO connection, or SSH for an SSH connection

Create an HP iLO local account rotation

1
In your Secrets Manager project, open the dashboard and select Add Secret Rotation from the actions dropdown.Add Secret RotationThen, select the HP iLO Local Account option.Select HP iLO Local Account
2
Under Configuration, choose the app connection and when the rotation runs:
  • Environment: The project environment the rotated secrets are stored in
  • Connection: The HPE iLO connection or SSH connection the rotation uses (the dropdown groups the connections by type)
  • Rotation Interval (In Days): The number of days between rotations
  • Rotate At (Local Time): The time of day the rotation runs
  • Auto-Rotation Enabled: When enabled, the password rotates on the schedule; turn it off to rotate manually only
To create a new connection, select Create HPE iLO Connection or Create SSH Connection in the Connection dropdown, then fill in the form as described in HPE iLO connection or SSH connection. Infisical returns you to the rotation form with the new connection selected.Rotation Configuration
Because this rotation changes a single password, an automatic rotation can interrupt clients that use the previous password. If you need to avoid interruptions, turn off Auto-Rotation Enabled and rotate manually.
Then select Continue.
3
Under Parameters, choose the iLO account to rotate. The fields depend on the type of connection you selected:
  • Target Username: The iLO username of the account whose password Infisical rotates Rotation Parameters for an HPE iLO connection
Under Password Requirements, set the rules for generated passwords:
  • Password Length: The length of the generated password (39 at most)
  • Digit Count: The minimum number of digits
  • Lowercase Character Count: The minimum number of lowercase characters
  • Uppercase Character Count: The minimum number of uppercase characters
  • Symbol Count: The minimum number of symbols
  • Allowed Symbols: The symbols a generated password can contain
Then select Continue.
4
Under Mappings, choose the names of the Infisical secrets that hold the rotated values:
  • Username: The name of the secret that holds the iLO username
  • Password: The name of the secret that holds the rotated password Secret Mapping
Then select Continue.
5
Give the rotation a Name and an optional Description. The name must be slug-friendly.Rotation DetailsThen select Continue.
6
Review your HP iLO Local Account Rotation configuration, then select Create secret rotation.Review and Create
The rotated credentials are now available through the mapped secrets. If auto-rotation is enabled, the password rotates on your configured schedule.
Rotation Created

Recover after an outside password change

If a rotation uses an SSH connection with Login As Target and someone changes the target account’s password outside Infisical, the next rotation can’t sign in as the target account. To get the rotation working again, reconcile it:
1
In your project’s dashboard, select Reconcile Secret on the rotation.Reconcile Option
2
In the confirmation dialog, select Reconcile.Reconcile Confirmation
Infisical signs in with the SSH connection’s credentials, sets a new password on the target account, and saves the password to the mapped secrets. A rotation that uses an HPE iLO connection or Login As Root always signs in with the connection’s account, so a password change outside Infisical doesn’t stop the next rotation.

Next steps

HPE iLO

Create an HPE iLO connection for Redfish-based rotations.

Overview

Learn how secret rotation schedules and rotation types work.