Two-Factor Authentication User Certificates - HP Integrated Lights-Out User Manual

Integrated lights-out firmware 1.91
Hide thumbs Also See for Integrated Lights-Out:
Table of Contents

Advertisement

After you have selected a certificate, if the certificate is protected with a password or if the certificate is
stored on a smart card, a second window appears prompting you to enter the PIN or password
associated with the chosen certificate.
The certificate is examined by iLO to ensure is was issued by the trusted CA by checking the signature
against the CA certificate configured in iLO. iLO will determine if the certificate has been revoked and if it
maps to a user in the iLO local user database. If all of these tests pass, then the normal iLO user interface
appears.
If the user credential authentication fails, the Login Failed page displays. If login fails, you will be
instructed to close the browser, open a new browser window, and try connecting again. If directory
authentication is enabled, and local user authentication fails, iLO displays a login screen with the
directory user name field populated with either the User Principal Name from the certificate or the
Distinguished name (derived from the subject of the certificate). iLO requests the password for this user
account. After providing the password, the user is authenticated.
For this release iLO does not address passing two-factor authentication through the Remote Console.
Instead relies on smart card device support within RDP to provide access to systems that require smart
card authentication for the remote operating system. iLO provides access to RDP with the Terminal
Services pass-through function. Smart card authentication is only required for a remote server if an
operating system is up and running. Support for smart cards in RDP requires that the operating system of
the remote server be a version of Microsoft® Windows® Server 2003. Refer to the "Terminal Services
Pass-Through option (on page 36)" section for additional information.

Two-factor authentication user certificates

To have a user authenticated through the two-factor authentication locally on iLO, a certificate must be
associated with the user's local user name. On the Administration>Modify User page, if a certificate has
been mapped to the user a thumbprint (an SHA1 hash of the certificate) is displayed, as well as a button
iLO security 61

Advertisement

Table of Contents
loading

Table of Contents