3 Scalability Example Data
3.6 Maintenance Data Results
You can use Intel SCS to perform these maintenance tasks on Intel AMT:
Synchronizing the Clock – The Intel AMT device contains a clock that operates independently from
the clock in the host operating system. For devices configured to use Kerberos authentication, it is
important to synchronize the device clock with the clock of a computer in the network. When the clock is
not synchronized, Kerberos authentication with the device might fail. For Kerberos enabled devices, Intel
recommends to synchronize the clock at two week intervals.
Synchronizing Network Settings – After configuration, the Intel AMT device contains IP and FQDN
settings that management consoles use to connect to the device. Changes in the network environment
or the host operating system might make it necessary to change the settings in the device.
Reissuing Certificates – The certificates configured in Intel AMT (for TLS, EAC, Remote Access, or
802.1x) are only valid for a specified time. These certificates must be reissued before they expire. Intel
recommends that you schedule this maintenance task to run a minimum of 30 days before the
certificate expiration date.
Replacing Active Directory Object Passwords – If an Intel AMT device is configured to use Active
Directory (AD) Integration, an object is created in the AD Organizational Unit specified in the profile. The
object contains a password that is set automatically (not user defined). If the ADOU has a “maximum
password age” password policy defined in AD, the password must be replaced before it expires. Intel
recommends that you schedule this maintenance task to start a minimum of 10 days before the
password is set to expire.
Changing the Default Admin Password – For increased security, it is recommended to change the
password of the default Digest admin user (of Intel AMT) at regular intervals.
Intel SCS includes two different methods for running maintenance tasks on Intel AMT:
Using the CLI – The maintenance request is sent by the Configurator from the system to the RCS.
Using Jobs – This option is available from the Console, but only when the RCS is installed in database
You can use either of these methods to run any of the maintenance tasks separately, or all of the maintenance
tasks together. For more information about maintenance tasks, refer to the “Maintenance Policies for Intel
AMT” section of the Intel(R)_SCS_User_Guide.pdf.
For the scalability testing, we ran three separate tests for each of these maintenance methods. One test was to
perform all maintenance tasks. And the other two tests were to renew the AD password (of the Intel AMT AD
object) and renew the certificates configured in Intel AMT.
The results tables contain results for 1,000 systems. This is because when running maintenance tasks,
most of the values remain more or less the same regardless of the number of systems. For example,
running maintenance on 10,000 or 100, 000 systems does not significantly increase the maximum
amount of RAM used by the RCS. The values that do increase according to the number of systems (total
time, disk usage of RCS log files, and disk usage of the Intel SCS database) increase in almost linear
increments. For these values, simply multiply the value in the table by the number of thousands of systems
(for example, for 10,000 systems, multiply by 10).
Intel® SCS - Scalability Guidelines


