Setup For Schema-Free Directory Integration; Integration" On - HP Integrated Lights-Out User Manual

Integrated lights-out firmware 1.91
Hide thumbs Also See for Integrated Lights-Out:
Table of Contents

Advertisement

Advantages of using HP schema directory integration:
Greater flexibility controlling access. For example, you can limit access to a time of day, or from
o
a certain range of IP addresses.
Groups and permissions are maintained in the directory, not on each iLO, and HP provides the
o
snap-ins required for managing HP groups and targets for Active Directory Users and Computers,
and eDirectory ConsoleOne.
Integration with eDirectory
o
Disadvantages of HP schema directory integration
The directory schema must be extended. However, this task is minimized because HP provides the
.kdf file and a wizard to extend the schema, and later versions of Active Directory enable you to
undo schema changes.
For information on how to extend the schema and configuration of directory settings information, see
"Integrating HP ProLiant Lights-Out processors with Microsoft® Active Directory
(http://h20000.www2.hp.com/bc/docs/support/SupportManual/c00190541/c00190541.pdf)."
Certificate requirements
iLO must communicate with the directory using LDAP over SSL. This communication requires the
directory server to have a certificate. Installing the certificate for the domain replicates it throughout
the domain controllers in the domain. For information about installing the certificate, refer to the
Customer Advisory available on the HP website
(http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=PSD_EM030604_
CW01&locale=en_US).
Failover options
To enable failover (redundancy), use the domain name as the directory server name when
configuring iLO. Most DNS servers resolve a domain name to a working directory server (domain
controller).
Login format
NetBIOS, UPN, and distinguished name formats are accepted for login names. The login script for
iLO calls down to the operating system of the client system and attempts to translate the login name
into a directory distinguished name. For the login script to do this, the directory name must be a
DNS name, not an IP address. Also, both the client and iLO must be able to access the directory
server using the same name. Both the client and iLO must be in the same DNS domain.
Multiple targets
You do not need to use multiple targets in the directory. HP schema directory integration only
requires one hpqTarget object, which can represent many LOM devices.

Setup for Schema-free directory integration

Before setting up the Schema-free option, your system must meet all the prerequisites outlined in the
"Active Directory Preparation (on page 108)" section.
You can set up iLO for directories in three ways:
Manually using a browser
Using a script
Using HPLOMIG
("Schema-free browser-based
("Schema-free scripted
setup" on page 109).
("Schema-free HPLOMIG-based
setup" on page 109).
setup" on page 110).
Directory services 107

Advertisement

Table of Contents
loading

Table of Contents