HP Integrated Lights-Out User Manual page 117

Integrated lights-out firmware 1.91
Hide thumbs Also See for Integrated Lights-Out:
Table of Contents

Advertisement

iLO requires a secure connection to communicate with the directory service. This requires the installation
of the Microsoft® CA. Refer to the Microsoft® technical reference Knowledge Base Article 321051: How
to Enable LDAP over SSL with a Third-Party Certification Authority.
Directory services preparation for Active Directory
To set up directory services for use with iLO management processors:
Install Active Directory. For more information, refer to Installing Active Directory in the Microsoft®
1.
Windows® 2000 Server Resource Kit.
Install the Microsoft® Admin Pack (the ADMINPAK.MSI file, which is located in the i386
2.
subdirectory of the Windows® 2000 Server or Advance Server CD). For more information, refer to
the Microsoft® Knowledge Base Article 216999.
In Windows® 2000, the safety interlock that prevents accidental writes to the schema must be
3.
temporarily disabled. The schema extender utility can do this if the remote registry service is running
and the user has sufficient rights. This can also be done by setting
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ServicesParameters\Schema
Update Allowed in the registry to a non-zero value (refer to the "Order of Processing When
Extending the Schema" section of Installation of Schema Extensions in the Windows® 2000 Server
Resource Kit) or by the following steps. This step is not necessary if you are using Windows® Server
2003.
IMPORTANT:
recommends creating a back up of any valued data on the computer before making changes
to the registry.
Start MMC.
a.
Install the Active Directory Schema snap-in in MMC.
b.
Right-click Active Directory Schema and select Operations Master.
c.
Select The Schema may be modified on this Domain Controller.
d.
Click OK.
e.
The Active Directory Schema folder might need to be expanded for the checkbox to be available.
Create a certificate or install Certificate Services. This step is necessary to create a certificate or
4.
install Certificate Services because iLO communicates with Active Directory using SSL. Active
Directory must be installed before installing Certificate Services.
To specify that a certificate be issued to the server running active directory:
5.
Launch Microsoft® Management Console on the server and add the default domain policy snap-
a.
in (Group Policy, then browse to Default domain policy object).
Click Computer Configuration>Windows Settings>Security Settings>Public Key Policies.
b.
Right-click Automatic Certificate Requests Settings, and select new>automatic certificate request.
c.
Using the wizard, select the domain controller template, and the certificate authority you want to
d.
use.
Download the Smart Component, which contains the installers for the schema extender and the snap-
6.
ins. The Smart Component can be downloaded from the HP website
(http://www.hp.com/servers/lights-out).
Run the schema installer application to extend the schema, which extends the directory schema with
7.
the proper HP objects.
Incorrectly editing the registry can severely damage your system. HP
Directory services 117

Advertisement

Table of Contents
loading

Table of Contents