Setting up HP schema directory integration
When using the HP schema directory integration, iLO 2 supports both Active Directory and eDirectory.
However, these directory services require the schema being extended.
Features supported by HP schema directory integration
iLO 2 Directory Services functionality enables you to:
•
Authenticate users from a shared, consolidated, scalable user database.
•
Control user privileges (authorization) using the directory service.
•
Use roles in the directory service for group-level administration of iLO 2 management processors and
iLO 2 users.
Extending the schema must be completed by a Schema Administrator. The local user database is
retained. You can decide not to use directories, to use a combination of directories and local accounts, or
to use directories exclusively for authentication.
NOTE:
You can log in using a local account only.
Setting up directory services
To successfully enable directory-enabled management on any Lights-Out management processor:
Plan
1.
Review the following sections:
"Directory services (on page 134)"
o
"Directory services schema (on page 213)"
o
"Directory-enabled remote management (on page 166)"
o
Install
2.
Download the HP Lights-Out Directory Package containing the schema installer, the management
a.
snap-in installer, and the migrations utilities from the HP website
(http://www.hp.com/servers/lights-out).
Run the schema installer (on page 144) once to extend the schema.
b.
Run the management snap-in installer (on page 147), and install the appropriate snap-in for your
c.
directory service on one or more management workstations.
Update
3.
Flash the ROM on the Lights-Out management processor with the directory-enabled firmware.
a.
Set directory server settings and the distinguished name of the management processor objects on
b.
the Directory Settings (on page 51) page in the iLO 2 GUI.
Manage
4.
Create a management device object and a role object
a.
152) using the snap-in.
Assign rights to the role object, as necessary, and associate the role with the management device
b.
object.
When connected through the Diagnostics Port, the directory server is not available.
("Directory services
objects" on page
Directory services 142