My oldest server is an HP ProLiant from the G7 era, which means its lights-out management is iLO 3, whose final firmware shipped in 2020. The chip still does everything a baseboard management controller should: remote console, virtual media, power control, sensor readings. What it no longer does is speak to 2026 software without a fight.
Each fight has a fix. If you run old ProLiant iron, this list is several evenings of your life handed back.
The web UI only speaks TLS 1.0
Every current browser refuses TLS 1.0 by default, so the iLO web page simply does not load, with an error that suggests the device is broken rather than old. It is not broken. In Firefox, about:config, set security.tls.version.min to 1, and the UI appears. I keep one browser profile with that override as the designated old-iron profile, so my daily browser keeps its modern settings.
Do not bother with the embedded System Management Homepage link on the SNMP page, either. It points at a host-side agent that does not exist for modern Linux and never will. Dead surface, ignore it.
SSH requires an archaeology kit
A modern OpenSSH client rejects every algorithm the iLO offers. The connection needs a stanza of legacy allowances in ~/.ssh/config:
KexAlgorithms +diffie-hellman-group1-sha1,diffie-hellman-group14-sha1
HostKeyAlgorithms +ssh-rsa,ssh-dss
PubkeyAcceptedAlgorithms +ssh-rsa,ssh-dss
Ciphers +aes128-cbc,3des-cbc
MACs +hmac-sha1
Scope it to the iLO's host entry only. These algorithms are deprecated for good reasons; the trick is confining the time machine to the one device that needs it.
Key auth: DSA only, and only via a side door
This one cost me a real evening. iLO 3's final firmware accepts exactly one public key type: DSA 1024. RSA 2048, RSA 4096, with comment, without comment, re-wrapped in every plausible format, all return the same unhelpful "invalid input." Generating a DSA key in 2026 requires asking OpenSSH nicely, since it stopped doing so by default years ago.
Then comes uploading it. The web UI's paste box and the official HTTPS upload path both fail from modern machines, because current TLS stacks refuse the iLO's ancient handshake before the upload can even start. The path that works is delightfully sideways: SSH into the iLO with password auth, and tell it to fetch the key file itself over plain HTTP from a little web server you stand up on the same network. The BMC's own HTTP client has no objection to its era's protocols. One fetch, key installed, passwordless ever since.
Changing the IP: the silence after
You can change the iLO's address in-band from the host, no reboot needed. What nobody tells you: iLO 3 ships with gratuitous ARP disabled, so after the change it does not announce its new binding to the network. Everything keeps trying to reach it where it used to be, and the device appears to have died. It has not. Issue a BMC cold reset (from the host: ipmitool mc reset cold), the network stack re-binds and finally speaks up, and the new address works. The gap between "I changed the IP" and "I found the cold reset" is an unpleasant stretch of believing you bricked your only out-of-band path.
The one setting you must never touch
Somewhere in the security pages sits a FIPS mode toggle. On iLO 3, enabling it performs a factory reset as a feature: license key, user accounts, network configuration, identity, time zone, every customization, gone in one click, and the option looks exactly like something a diligent admin would enable while hardening. Do not. On firmware this old, FIPS mode is a self-destruct button wearing a compliance costume. It is the only setting on the device I treat as radioactive, and it has a permanent warning in my runbook.
Worth knowing, not fighting
An Advanced license unlocks virtual media and the full remote console, which is what turns the old BMC from a status page into an actual recovery path; licenses for hardware this old are effectively free on the second-hand market. IPMI over LAN works fine once enabled, and is the cleanest programmatic surface left on the device, with the caveat that its port belongs on a management network you trust, because the protocol's security model predates the modern internet's manners.
Why bother
Every quirk above has the same root cause: the device froze in time and the world kept moving. The fixes are all on our side of the connection, because the iLO's side stopped changing in 2020. That is the actual definition of running end-of-life infrastructure: nothing is broken, but every integration is your job now.
Is it worth it? The server cost less than the drives inside it, the BMC still boots it from an ISO over the network from the couch, and the whole catalog above is one afternoon of configuration once you know it. Knowing it is the hard part. Now you do.

