Start a Conversation

Unsolved

N

5 Posts

66

January 2nd, 2024 10:04

Issue with sensitive info in Dell iDRAC TSR logs

Hi,

I work in a secure government environment and have an issue with Dell iDRAC TSR logs. Specifically IP addresses and domain names are classified and therefore cannot be sent externally to Dell, normally for logs we run a redaction script that replaces this sort of info but the way the TSR bundle works with the embedded viewer this breaks the ability for the Dell Support tech to view the logs.

I assume there's a hash value or similar recorded somewhere in the TSR bundle and as this changes due to our redaction process it invalidates the log bundle. I've not really looked into it yet though to see if we can work around it somehow, has anyone else come across this and has a workaround?

As I see it the underlying issue is a bug in the TSR generation utility in that if you select "Filter Data" in the Collection Preferences it does NOT remove the source IP and domain name of the user connecting to the iDRAC in the lifecycle log. The domain name isn't such an issue as I can run the TSR as root but the IP I can't do anything about so as it stands we have to refuse Dell Support requests for TSR logs and instead screenshot iDRAC info and redact sensitive info via MS Paint which is a hassle I don't need.

I'm not sure what the best mechanism is though for getting Dell to acknowledge it's a bug and amend the TSR log generation to correctly filter IPs & domain name from the lifecycle log, any ideas? Dell Support don't see to be able to, they just want to deal with the SR relating to actual issues and close them asap rather than also raise a bug report (can't really blame them).

Moderator

 • 

3.5K Posts

January 2nd, 2024 16:34

Hello nf12345,

 

I spoke with one of our engineers and he said he does have customers that developed in house script to remove information they don't want sent. Maybe someone in the community that has done this can share their information.

 

I can submit a feature request for "Filter Data" to remove IP addresses if you would like to send me your service tag in a private message.

 

No Events found!

Top