Intel CSME SW IG
Intel CSME SW IG
June 2022
Revision 1.2
INFORMATION IN THIS DOCUMENT IS PROVIDED IN CONNECTION WITH INTEL PRODUCTS. NO LICENSE, EXPRESS OR IMPLIED,
BY ESTOPPEL OR OTHERWISE, TO ANY INTELLECTUAL PROPERTY RIGHTS IS GRANTED BY THIS DOCUMENT. EXCEPT AS
PROVIDED IN INTEL’S TERMS AND CONDITIONS OF SALE FOR SUCH PRODUCTS, INTEL ASSUMES NO LIABILITY WHATSOEVER
AND INTEL DISCLAIMS ANY EXPRESS OR IMPLIED WARRANTY, RELATING TO SALE AND/OR USE OF INTEL PRODUCTS
INCLUDING LIABILITY OR WARRANTIES RELATING TO FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, OR
INFRINGEMENT OF ANY PATENT, COPYRIGHT OR OTHER INTELLECTUAL PROPERTY RIGHT.
A “Mission Critical Application” is any application in which failure of the Intel Product could result, directly or indirectly, in
personal injury or death. SHOULD YOU PURCHASE OR USE INTEL’S PRODUCTS FOR ANY SUCH MISSION CRITICAL APPLICATION,
YOU SHALL INDEMNIFY AND HOLD INTEL AND ITS SUBSIDIARIES, SUBCONTRACTORS AND AFFILIATES, AND THE DIRECTORS,
OFFICERS, AND EMPLOYEES OF EACH, HARMLESS AGAINST ALL CLAIMS COSTS, DAMAGES, AND EXPENSES AND REASONABLE
ATTORNEYS’ FEES ARISING OUT OF, DIRECTLY OR INDIRECTLY, ANY CLAIM OF PRODUCT LIABILITY, PERSONAL INJURY, OR
DEATH ARISING IN ANY WAY OUT OF SUCH MISSION CRITICAL APPLICATION, WHETHER OR NOT INTEL OR ITS
SUBCONTRACTOR WAS NEGLIGENT IN THE DESIGN, MANUFACTURE, OR WARNING OF THE INTEL PRODUCT OR ANY OF ITS
PARTS.
Intel may make changes to specifications and product descriptions at any time, without notice. Designers must not rely on the
absence or characteristics of any features or instructions marked “reserved” or “undefined”. Intel reserves these for future
definition and shall have no responsibility whatsoever for conflicts or incompatibilities arising from future changes to them. The
information here is subject to change without notice. Do not finalize a design with this information.
The products described in this document may contain design defects or errors known as errata which may cause the product to
deviate from published specifications. Current characterized errata are available on request.
Contact your local Intel sales office or your distributor to obtain the latest specifications and before placing your product order.
Copies of documents which have an order number and are referenced in this document, or other Intel literature, may be obtained
by calling 1-800-548-4725, or go to: http://www.intel.com/design/literature.htm%20
All products, platforms, dates, and figures specified are preliminary based on current expectations, and are subject to change
without notice. All dates specified are target dates, are provided for planning purposes only and are subject to change.
This document contains information on products in the design phase of development. Do not finalize a design with this
information. Revised information will be published when the product is available. Verify with your local sales office that you have
the latest datasheet before finalizing a design.
Intel® Active Management Technology requires activation and a system with a corporate network connection, an Intel® AMT-
enabled chipset, network hardware and software. For notebooks, Intel AMT may be unavailable or limited over a host OS-based
VPN, when connecting wirelessly, on battery power, sleeping, hibernating or powered off. Results dependent upon hardware,
setup and configuration. For more information, visit Intel® Active Management Technology.
No system can provide absolute security under all conditions. Intel® Anti-Theft Technology (Intel® AT) requires an enabled
chipset, BIOS, firmware and software, and a subscription with a capable Service Provider. Consult your system manufacturer and
Service Provider for availability and functionality. Service may not be available in all countries. Intel assumes no liability for lost
or stolen data and/or systems or any other damages resulting thereof. For more information, visit http://www.intel.com/go/anti-
theft.
No system can provide absolute security under all conditions. Requires an Intel® Identity Protection Technology-enabled system,
including a 2nd gen Intel® Core™ processor enabled chipset, firmware and software, and participating website. Consult your
system manufacturer. Intel assumes no liability for lost or stolen data and/or systems or any resulting damages. For more
information, visit http://ipt.intel.com.
Code names featured are used internally within Intel to identify products that are in development and not yet publicly announced
for release. Customers, licensees and other third parties are not authorized by Intel to use code names in advertising, promotion
or marketing of any product or services and any such use of Intel’s internal code names is at the sole risk of the user.
Intel, Core, and the Intel logo are trademarks of Intel Corporation in the U.S. and other countries.
*Other names and brands may be claimed as the property of others.
Copyright © 2022 Intel Corporation. All rights reserved
2
IMPORTANT—READ BEFORE COPYING, INSTALLING OR USING.
Do not use or load this software or any associated materials (collectively, the “Software”) until you have carefully read the
following terms and conditions. By loading or using the Software, you agree to the terms of this Agreement. If you do not wish to
so agree, do not install or use the Software.
LICENSE—Subject to the restrictions below, Intel Corporation (“Intel”) grants you the following limited, revocable, non-exclusive,
non-assignable, royalty-free copyright licenses in the Software.
The Software may contain the software and other property of third party suppliers, some of which may be identified in, and
licensed in accordance with, the “license.txt” file or other text or file in the Software:
DEVELOPER TOOLS—including developer documentation, installation or development utilities, and other materials, including
documentation. You may use, modify and copy them internally for the purposes of using the Software as herein licensed, but you
may not distribute all or any portion of them.
RESTRICTIONS—You will make reasonable efforts to discontinue use of the Software licensed hereunder upon Intel’s release of
an update, upgrade or new version of the Software.
You shall not reverse-assemble, reverse-compile, or otherwise reverse-engineer all or any portion of the Software.
Use of the Software is also subject to the following limitations:
You,
(1) are solely responsible to your customers for any update or support obligation or other liability which may arise from the
distribution of your product(s)
(ii) shall not make any statement that your product is “certified,” or that its performance is guaranteed in any way by Intel
(iii) shall not use Intel’s name or trademarks to market your product without written permission
(iv) shall prohibit disassembly and reverse engineering, and
(v) shall indemnify, hold harmless, and defend Intel and its suppliers from and against any claims or lawsuits, including
attorney’s fees, that arise or result from your distribution of any product.
OWNERSHIP OF SOFTWARE AND COPYRIGHTS—Title to all copies of the Software remains with Intel or its suppliers. The
Software is copyrighted and protected by the laws of the United States and other countries, and international treaty provisions.
You will not remove, alter, deface or obscure any copyright notices in the Software. Intel may make changes to the Software or
to items referenced therein at any time without notice, but is not obligated to support or update the Software. Except as
otherwise expressly provided, Intel grants no express or implied right under Intel patents, copyrights, trademarks, or other
intellectual property rights. You may transfer the Software only if the recipient agrees to be fully bound by these terms and if you
retain no copies of the Software.
LIMITED MEDIA WARRANTY—If the Software has been delivered by Intel on physical media, Intel warrants the media to be free
from material physical defects for a period of ninety (90) days after delivery by Intel. If such a defect is found, return the media
to Intel for replacement or alternate delivery of the Software as Intel may select.
EXCLUSION OF OTHER WARRANTIES—EXCEPT AS PROVIDED ABOVE, THE SOFTWARE IS PROVIDED “AS IS” WITHOUT ANY
EXPRESS OR IMPLIED WARRANTY OF ANY KIND INCLUDING WARRANTIES OF MERCHANTABILITY, NONINFRINGEMENT, OR
FITNESS FOR A PARTICULAR PURPOSE. Intel or its suppliers do not warrant or assume responsibility for the accuracy or
completeness of any information, text, graphics, links or other items contained in the Software.
LIMITATION OF LIABILITY—IN NO EVENT SHALL INTEL OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER
(INCLUDING, WITHOUT LIMITATION, LOST PROFITS, BUSINESS INTERRUPTION, OR LOST INFORMATION) ARISING OUT OF THE
USE OF OR INABILITY TO USE THE SOFTWARE, EVEN IF INTEL HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME JURISDICTIONS PROHIBIT EXCLUSION OR LIMITATION OF LIABILITY FOR IMPLIED WARRANTIES OR CONSEQUENTIAL OR
INCIDENTAL DAMAGES, SO THE ABOVE LIMITATION MAY NOT APPLY TO YOU. YOU MAY ALSO HAVE OTHER LEGAL RIGHTS THAT
VARY FROM JURISDICTION TO JURISDICTION.
3
Revision History
Revision Description Revision Date
Number
4
Contents
1 Introduction ...................................................................................................... 6
2 Software Components Overview .......................................................................... 7
2.1 Intel® Management Engine Interface (Intel® MEI) ....................................... 7
2.2 Intel® Serial Over LAN (SOL) Driver .......................................................... 7
2.3 Intel® Local Manageability Service (Intel® LMS) .......................................... 7
2.4 Intel® CSME WMI Provider ....................................................................... 7
2.5 Intel® Management and Security Status (Intel® MSS) Application ................. 8
2.6 Intel® Dynamic Application Loader (Intel® DAL) .......................................... 8
2.7 Intel® Trusted Connect Service (Intel® TCS).............................................. 9
2.8 Intel® Wireless Manageability (Intel® Wiman)............................................. 9
5
Introduction
1 Introduction
This guide describes how to install, configure and troubleshoot the Intel® Converged
Security and Management Engine (Intel® CSME) software components.
6
Software Components Overview
2 Software Components
Overview
This section lists the software components supplied with the firmware kit and provides
a short overview of each component.
It also provides Intel® CSME with various host operation abilities. For instance, it
enables Intel® CSME technologies to write user notifications to the local host OS event
log for the purpose of notifying end users of predefined events, such as when support
personnel connect remotely to the platform for a healing session. Intel provides
documentation on how ISVs can extract these events from the event log for use in
their applications.
7
Software Components Overview
Intel® MEI operations through WMI. In addition, the provider enables the user to
subscribe to Intel® LMS events and receive them via WMI events.
Following are the main functionalities implemented in the Intel® CSME WMI provider:
• Discovery of Intel® CSME and Intel® AMT related attributes, such as firmware
version and provisioning state.
• Local activation operation, performed as part of Remote Configuration.
• Hardware events.
The Intel® CSME WMI provider is implemented as a DLL (MeProv.dll) and operates as
part of Windows* WMI service.
Intel® CSME WMI Provider has switched to INF installation support. Refer to section
5.1 for more detail of installing method.
When Intel® Management and Security Status application is running on the platform,
an icon is displayed in the notification area. Clicking the icon opens the application.
By default, the icon is loaded and displayed every time Windows* starts. The icon will
be gray if the Intel® LMS is not running or the Intel® MEI driver is disabled or
unavailable.
Note: If the Intel® Management and Security Status application starts automatically
as a result of the user logging on to Windows*, the icon will be loaded to the
notification area only if Intel® AMT, Intel® SBA or Intel® Standard Manageability exists
on the system. If the Intel® Management and Security Status application is started
manually (via the Start menu or file manager), the icon is loaded even if none of
these technologies exists.
Note: The information displayed in the Intel® Management and Security Status
application is refreshed at pre-defined intervals. The application dynamically hides
tabs that are not relevant. For example, on platforms that do not support Intel ® AT,
the Intel® AT tab is hidden.
8
Software Components Overview
them. It will only be installed if the platform is Intel ® Dynamic Application Loader
capable.
Intel® TCS will be not installed by Intel® CSME SW installer and will be no functional if
Intel® CSME FW support On-Die Certificate Authority (ODCA), e.g., Tiger lake platform
running FW 15.0.10.1368 or later. Detail refers to TA#634464.
Note that Intel® Wiman driver is only present and functional on Corporate sku FW
image for coffee lake platform and above.
9
Installer List
3 Installer List
This section describes the installation packages for the Intel® CSME software.
3.1 ME_SW_DCH
This installation program in SW\ME_SW_DCH installs the Intel® CSME software
components required for the platform on which you are installing, and installs only
those components that match your platform’s capabilities.
Note: IMSS application will not be installed by this installer. For installation of IMSS
please refer to section 5.2.
The following table describes the components that are installed for the different
platform capabilities:
Intel® AMT, Intel® SBA, Intel® Intel® MEI driver, Intel® SOL driver,
Standard Manageability Intel® TCS(1), Intel® LMS, Intel® CSME
WMI provider, Intel® Wiman(2) ,
Intel® DAL(3)
Note:
(1) Intel® TCS is not installed by Intel® CSME SW installer and will be no functional if
Intel® CSME FW support On-Die Certificate Authority (ODCA), e.g., Tiger Lake
platform running Intel® CSME FW 15.0.10.1368 or later. Detail refers to
TA#634464.
10
Installer List
(2) Intel® Wiman driver is only installed and functional on Corporate sku FW image
for coffee lake platform and above.
(3) The Installer provides the option to install only Intel® MEI driver and Intel® DAL
service by running the installer with the following flag: setup.exe –meidalonly.
3.2 Drivers
This package includes the INF installers for Intel® CSME software components and
Intel® MSS APPX package.
• Intel® MEI: heci.inf in Drivers\MEI\
• Intel® SOL: mesrl.inf in Drivers\SOL (only applicable for corporate sku)
• Intel® TCS: iclsClient.inf in Drivers\ICLS
• Intel® LMS: LMS.inf in Drivers\LMS (only applicable for corporate sku)
• Intel® DAL: DAL.inf in Drivers\JHI\win10
• Intel® MSS APPX: Drivers\IMSS (only applicable for corporate sku)
• Intel® Wiman driver: Drivers\WiMan (only applicable for corporate sku)
• Intel® Wiman extension: Drivers\wiman_wlan_extension (only applicable for
corporate sku)
• Intel® CSME WMI Provider: MEWMIProv.inf in Drivers\WMIProvider
• Intel® MSS HSA extension: ImssHsaExtension.inf in
Drivers\IMSS_HSA_EXTENSION (only applicable for corporate sku)
• SOL LMS Extension: SOLLMSExtension.inf in Drivers\SOL_LMS_Extension (only
applicable for corporate sku)
11
System Requirements
4 System Requirements
To enable installation and use of the Intel® CSME software components, the following
are required on the platform:
• Windows 10* / Windows 11* / Windows Server 2019*.
• Microsoft* .NET Framework: version 4.8 or above, required if the Intel®
Management and Security Status application is installed on the platform.
• Microsoft* Visual C++ 2015 Redistributable: version 14.0.26905.0 or above,
required if the Intel® Management and Security Status application is installed on
the platform.
12
Installing Intel® CSME Software Components
To install the components, right click on INF file, and click on install.
https://docs.microsoft.com/en-us/windows-hardware/manufacture/desktop/what-is-
dism
SOL LMS Extension is required to be installed along with Intel® SOL device and
installation of Intel® LMS. Intel® LMS will be functional only if Intel® SOL device exists
and SOL LMS extension INF is installed.
The following devices will be shown in the device manager if the according drivers are
installed on compatible devices:
13
Installing Intel® CSME Software Components
The software installer has command line option for specific installing configuration,
under command line mode execute setupME.exe -? will display the available options
as follows:
-?
Displays this help dialog.
14
Installing Intel® CSME Software Components
-b
Reboots the system without prompting after setup is complete, if reboot is
required.
-l <LCID>
Specifies the language of the setup dialogs.
-nodrv
Does not install the driver.
-overwrite
Ignores the overwrite warning.
-p <path>
Changes default directory location for application files.
Warning : User who chooses to use –p flag must make sure the destination
directory is a secure folder (write access by admin). Otherwise it can lead to a
security issue.
-report <path>
Changes the default log path.
-s
Does not display any setup dialogs (silent install).
-ver
Displays driver versions.
-drvonly
Installs drivers only.
-meidalonly
Installs Intel® MEI and Intel® DAL only.
-preinst
Installs all drivers even if hardware is not present.
-nowiman
Does not install Intel® Wiman
-wmionly
Install and register only Intel® CSME WMI Provider.
15
Installing Intel® CSME Software Components
User may download and install Intel® MSS from Microsoft store, or install
IMSS_HSA_EXTENSION INF, which will pull Intel® MSS from Microsoft store and install
Intel® MSS in the background when Intel® SOL device exists.
For the OS without Microsoft Visual C++ 2015 Redistributable 14.0.26905.0 or later
(e.g., fresh OS or pre-install OS without windows* update), the
DependencyPackagePath is required for installing Microsoft Visual C++ 2015
Redistributable along with Intel® MSS APPX.
where c:\test\offline is the folder where you mounted the WIM image
<pre-install kit Folder Path> is the folder where the package is extracted to
16
Installing Intel® CSME Software Components
Note that the installer may return other error codes in cases where an application or
other process called returns one. The error code returned will be passed through.
http://msdn.microsoft.com/en-
us/library/windows/hardware/ff544208%28v=vs.85%29.aspx
http://msdn.microsoft.com/en-US/windows/hardware/br259104
17
Installing Intel® CSME Software Components
o From: Localhost
o To process: jhi_service.exe
o Port: Any
18
Identifying Intel® CSME Software Components
Each Intel® CSME Software Installer package contains a file called the ‘mup.xml’
which can be used to identify the SPV. The mup.xml describes the following
information: Example:
<fullpackageidentifier>
<msis>
<msi componentID="100950">
<identifyingnumber>{1CEAC85D-2590-4760-800F-
8DE5E91F3700}</identifyingnumber>
<upgradecode>{1CEAC85D-2590-4760-800F-8DE5E91F3700}</upgradecode>
<version>yyww.mm.nn.bbbb</version>
</msi>
</msis>
</fullpackageidentifier>
The ‘fullpackageidentifier’ section points out where to look for the package version and
what it should be in order to be the latest. The ‘DisplayVersion’ and {GUID} above are
found Microsoft* Windows* registry in the locations below:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{GU
ID}\DisplayVersion
Intel® LMS: LMS / Intel(R) Management and Security Application Local Management
Service
Intel® DAL: jhi_service / Intel(R) Dynamic Application Loader Host Interface Service
19
Identifying Intel® CSME Software Components
20
Configuring Intel® LMS
LMS.exe is installed along with the other software components. Note the following
installation circumstances:
Note: The following keys are not mandatory and Intel® LMS will function as required
without their existence. All changes to registry keys are noted at Intel® LMS startup
only. To force the changes to be noted, restart Intel® LMS.
Note: Partial Firmware Update is a feature new from Intel® ME 8 that allows update
of specific sections of Intel ME, without requiring a system reset.
Note: Disabling Partial FW Update will eliminate the user's ability to change the user
consent language and to replace the wireless adapter type without affecting Intel®
AMT functionality over wireless LAN.
Note: The path can't point to a network shared folder. It must point to a local folder.
The following Registry keys could be added for configuring which events will be shown
in Event Log. This is a DWORD Value. Setting value to 0 will prevent the event from
appearing, while setting value to 1 will cause the relevant event to appear. Note that
the settings only take effect when Intel® LMS is (re)started.
21
Configuring Intel® LMS
22
Uninstalling Intel® CSME Software and Drivers
If you are installing the inf drivers manually – from the Drivers folder, you should
uninstall them manually from device manager
• Right click the device name in device manger and choose uninstall
Note: If some system dlls have been removed between the installation and
uninstallation of the Intel® CSME software, the uninstallation may fail. This has been
noted, for example, when uninstalling Microsoft* Visual C.
Note: Don’t manually uninstall Intel® CSME software components via device
manager if you are installing CSME software using installer
Intel® WiMan install will add wiman and wiman_extension. Therefore, when
uninstalling manually from device manager it will uninstall only the WiMan. User then
need to uninstall manually the wiman_extension that is shown in device manager as
“Generic Software Component”.
There are 3 different Intel® WiMan’s (WiMan-WiFi for CNL/WHL, WiManH for CML/TGL,
WiManHu for ADL and above). When user use NIC that is relevant for CNL/WHL on
upper platform version he will get the WiMan-WiFi as hidden device in device manager
and it will be as a “zombie”.
23
Troubleshooting Intel® CSME Software Components
The Intel® Management and Security Status application will display the following error
message if no Microsoft* .NETframework is present in the system:
The Intel® Management and Security Status application will display the following error
message if no Microsoft* .NETframework version is not 4.8 or above:
24
Troubleshooting Intel® CSME Software Components
If these happen, install Microsoft* .NET Framework version 4.8 or above and then re-
open the application.
25
Troubleshooting Intel® CSME Software Components
1. Intel® LMS is not running. It can be started through the Services pane in the
Computer Management window. If it is not installed, reinstall the software
components.
2. The network cable is disconnected, or the network connection is not
configured properly.
If the actions above do not resolve the problem, it is recommended to contact your
Information Technology department.
While the Intel® Management and Security Status application is running, the Intel®
Management and Security Status icon is visible in the notification area. This icon will
appear blue if any one of the aforementioned technologies is enabled on the
computer. In any other case, the icon will appear gray.
Note: The icon will also be gray if the LMS service is not running or the Intel ® MEI
driver is disabled or unavailable.
26
Troubleshooting Intel® CSME Software Components
This symptom doesn’t impact the functionality of Intel® TCS, Intel® DAL and Intel®
LMS. If user still wants to remove these duplicate components from device manager,
user may remove oemextension INF via pnputil.
27