HP Integrity Superdome 2 16-socket HP Integrity Superdome 2 Onboard Administra - Page 181

Enabling LDAP Directory Services Authentication to Microsoft Active Directory, Certificate Services

Page 181 highlights

14 Enabling LDAP Directory Services Authentication to Microsoft Active Directory Certificate Services The Microsoft implementation of LDAP over SSL requires that the Domain Controllers install DC certificates from the CA of the organization. This process occurs when the Enterprise Root CA service is added to a server in Active Directory. HP strongly recommends using an Enterprise Root CA to minimize the complexities of requesting and accepting DC certificates from a standalone CA. Preparing the directory For a normal production environment, similar groups already exist in some form, but the following group names can be used as-is if desired. To prepare the directory: 1. Create an Active Directory group named OA Admins, and then put a user named Test Admin to this group 2. Create a group called OA Operators, and then add a user named Test Operator to this group. User permissions are irrelevant. Preparing the Onboard Administrator To prepare the Onboard Administrator: Certificate Services 181

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197

14 Enabling LDAP Directory Services Authentication to
Microsoft Active Directory
Certificate Services
The Microsoft implementation of LDAP over SSL requires that the Domain Controllers install DC
certificates from the CA of the organization. This process occurs when the Enterprise Root CA
service is added to a server in Active Directory. HP strongly recommends using an Enterprise Root
CA to minimize the complexities of requesting and accepting DC certificates from a standalone
CA.
Preparing the directory
For a normal production environment, similar groups already exist in some form, but the following
group names can be used as-is if desired.
To prepare the directory:
1.
Create an Active Directory group named OA Admins, and then put a user named Test Admin
to this group
2.
Create a group called OA Operators, and then add a user named Test Operator to this group.
User permissions are irrelevant.
Preparing the Onboard Administrator
To prepare the Onboard Administrator:
Certificate Services
181