HP Integrity Superdome 2 8-socket HP Integrity Superdome 2 Onboard Administrat - Page 154

Edit Local User Certificate Information tab, Two-Factor Authentication screen

Page 154 highlights

Edit Local User Certificate Information tab When Two-Factor Authentication is enabled, a user must have a user certificate to log on to the Onboard Administrator. Users with administrator privileges can upload or map a valid certificate to a selected user. Upload certificates for use in HP Superdome 2 Onboard Administrator in the following ways: • Paste certificate contents into the text box, and then click the Upload button. • Paste the URL of the certificate into the URL box, and then click the Apply button. When the certificate is successfully uploaded, the SHA1 fingerprint of the user certificate appears. If a user already has a certificate mapped to an account, the SHA1 fingerprint of the certificate appears. Any user with administrator privileges can delete their certificate and upload a new user certificate. Two-Factor Authentication screen Two-Factor Authentication Settings tab NOTE: Onboard Administrator must be configured in Virtual Connect mode before enabling Two-Factor Authentication when using Virtual Connect Manager and Two-Factor Authentication. When Two-Factor Authentication is enabled, only users with a valid user certificate are allowed to log on to Onboard Administrator. A valid user certificate is signed by a trusted Certificate Authority and is mapped to the respective user on the Onboard Administrator. To enable Two-Factor Authentication for user authentication during log on, select Enable Two-Factor Authentication. When Two-Factor Authentication is enabled, Secure Shell and Telnet access is disabled by default. Disabling Two-Factor Authentication does not automatically re-enable Secure Shell and Telnet. You must go to the Network Access screen, and then select Enable Secure Shell and Enable Telnet. To enable the Onboard Administrator to verify with the Certifying Authority that the certificate being used has been added to the certificate revocation list (CRL), select Check for Certificate Revocation. If the certificate is on the CRL, the log on is denied. Certificate Owner Field You can configure the Onboard Administrator to use the user principle name in the SAN by selecting SAN or to use the certificate subject name by selecting Subject when authenticating directory users with a directory server. To save settings, click the Apply button. Two-Factor Authentication Certificate Information tab This screen displays all Certificate Authorities trusted by the Onboard Administrator. Any user certificates uploaded to the Onboard Administrator must be signed by one of these Certificate Authorities. A maximum of three Certificate Authority certificates can be uploaded to the Onboard Administrator. Row Description Certificate Version Version number of current certificate Issuer Organization Name of the organization that issued the certificate Issuer Organization Unit Name of the organizational unit that issued the certificate Issued By The authority that issued the certificate 154 Configuring HP Integrity Superdome 2 compute enclosures and enclosure devices

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197

Edit Local User Certificate Information tab
When Two-Factor Authentication is enabled, a user must have a user certificate to log on to the
Onboard Administrator. Users with administrator privileges can upload or map a valid certificate
to a selected user.
Upload certificates for use in HP Superdome 2 Onboard Administrator in the following ways:
Paste certificate contents into the text box, and then click the
Upload
button.
Paste the URL of the certificate into the URL box, and then click the
Apply
button.
When the certificate is successfully uploaded, the SHA1 fingerprint of the user certificate appears.
If a user already has a certificate mapped to an account, the SHA1 fingerprint of the certificate
appears. Any user with administrator privileges can delete their certificate and upload a new user
certificate.
Two-Factor Authentication screen
Two-Factor Authentication Settings tab
NOTE:
Onboard Administrator must be configured in Virtual Connect mode before enabling
Two-Factor Authentication when using Virtual Connect Manager and Two-Factor Authentication.
When Two-Factor Authentication is enabled, only users with a valid user certificate are allowed
to log on to Onboard Administrator. A valid user certificate is signed by a trusted Certificate
Authority and is mapped to the respective user on the Onboard Administrator.
To enable Two-Factor Authentication for user authentication during log on, select
Enable Two-Factor
Authentication
. When Two-Factor Authentication is enabled, Secure Shell and Telnet access is
disabled by default. Disabling Two-Factor Authentication does not automatically re-enable Secure
Shell and Telnet. You must go to the Network Access screen, and then select
Enable Secure Shell
and
Enable Telnet
.
To enable the Onboard Administrator to verify with the Certifying Authority that the certificate
being used has been added to the certificate revocation list (CRL), select
Check for Certificate
Revocation
. If the certificate is on the CRL, the log on is denied.
Certificate Owner Field
You can configure the Onboard Administrator to use the user principle name in the SAN by selecting
SAN or to use the certificate subject name by selecting Subject when authenticating directory users
with a directory server.
To save settings, click the
Apply
button.
Two-Factor Authentication Certificate Information tab
This screen displays all Certificate Authorities trusted by the Onboard Administrator. Any user
certificates uploaded to the Onboard Administrator must be signed by one of these Certificate
Authorities. A maximum of three Certificate Authority certificates can be uploaded to the Onboard
Administrator.
Description
Row
Version number of current certificate
Certificate Version
Name of the organization that issued the certificate
Issuer Organization
Name of the organizational unit that issued the certificate
Issuer Organization Unit
The authority that issued the certificate
Issued By
154
Configuring HP Integrity Superdome 2 compute enclosures and enclosure devices