Prerequisites For Using Schema-Free Directory Integration - HP HPE iLO 5 User Manual

Table of Contents

Advertisement

Disadvantage of schema-free directory integration
Group privileges are administered on each iLO system. This disadvantage has minimal impact because
group privileges rarely change, and the task of changing group membership is administered in the
directory and not on each iLO system. Hewlett Packard Enterprise provides tools that enable you to
configure many iLO systems at the same time.
Schema-free configuration options
The schema-free setup options are the same, regardless of the method you use to configure the directory.
You can configure the directory settings for minimum login flexibility, better login flexibility, or maximum
login flexibility.
Minimum login flexibility
With this configuration, you can log in to iLO by entering your full DN and password. You must be a
member of a group that iLO recognizes.
To use this configuration, enter the following settings:
The directory server DNS name or IP address and LDAP port. Typically, the LDAP port for an SSL
connection is 636.
The DN for at least one group. This group can be a security group (for example,
CN=Administrators,CN=Builtin,DC=HPE,DC=com for Active Directory, or
UID=username,ou=People,dc=hpe,dc=com for OpenLDAP) or any other group, as long as
the intended iLO users are group members.
Better login flexibility
With this configuration, you can log in to iLO by entering your login name and password. You must be
a member of a group that iLO recognizes. At login time, the login name and user context are
combined to make the user DN.
To use this configuration, enter the minimum login flexibility settings and at least one directory user
context.
For example, if a user logs in as JOHN.SMITH, and the user context CN=USERS,DC=HPE,DC=COM, is
configured, iLO uses the following DN: CN=JOHN.SMITH,CN=USERS,DC=HPE,DC=COM.
Maximum login flexibility
With this configuration, you can log in to iLO by using your full DN and password, your name as it
appears in the directory, the NetBIOS format (domain\login_name), or the email format
(login_name@domain).
To use this configuration, configure the directory server address in iLO by entering the directory DNS
name instead of the IP address. The DNS name must be resolvable to an IP address from both iLO
and the client system.

Prerequisites for using schema-free directory integration

Procedure
1. Install Active Directory and DNS.
2. Install the root CA to enable SSL. iLO communicates with the directory only over a secure SSL
connection.
For information about using Certificate Services with Active Directory, see the Microsoft
documentation.
314
Prerequisites for using schema-free directory integration

Advertisement

Table of Contents
loading

Table of Contents