Dell PowerEdge R830 Integrated Remote Access Controller 8 Version 2.70.70.70 U - Page 139

Adding privileges, Adding iDRAC devices or iDRAC device groups

Page 139 highlights

Adding privileges To add privileges: Click the Privilege Object tab to add the privilege object to the association that defines the user's or user group's privileges when authenticating to an iDRAC device. Only one privilege object can be added to an Association Object. 1. Select the Privileges Object tab and click Add. 2. Enter the privilege object name and click OK. 3. Click the Privilege Object tab to add the privilege object to the association that defines the user's or user group's privileges when authenticating to an iDRAC device. Only one privilege object can be added to an Association Object. Adding iDRAC devices or iDRAC device groups To add iDRAC devices or iDRAC device groups: 1. Select the Products tab and click Add. 2. Enter iDRAC devices or iDRAC device group name and click OK. 3. In the Properties window, click Apply and click OK. 4. Click the Products tab to add one iDRAC device connected to the network that is available for the defined users or user groups. You can add multiple iDRAC devices to an Association Object. Configuring Active Directory with Extended schema using iDRAC web interface To configure Active Directory with extended schema using Web interface: NOTE: For information about the various fields, see the iDRAC Online Help. 1. In the iDRAC Web interface, go to Overview > iDRAC Settings > User Authentication > Directory Services > Microsoft Active Directory. The Active Directory summary page is displayed. 2. Click Configure Active Directory. The Active Directory Configuration and Management Step 1 of 4 page is displayed. 3. Optionally, enable certificate validation and upload the CA-signed digital certificate used during initiation of SSL connections when communicating with the Active Directory (AD) server. 4. Click Next. The Active Directory Configuration and Management Step 2 of 4 page is displayed. 5. Specify the location information about Active Directory (AD) servers and user accounts. Also, specify the time iDRAC must wait for responses from AD during login process. NOTE: • If certificate validation is enabled, specify the Domain Controller Server addresses and the FQDN. Make sure that DNS is configured correctly under Overview > iDRAC Settings > Network • If the user and iDRAC objects are in different domains, then do not select the User Domain from Login option. Instead select Specify a Domain option and enter the domain name where the iDRAC object is available. 6. Click Next. The Active Directory Configuration and Management Step 3 of 4 page is displayed. 7. Select Extended Schema and click Next. The Active Directory Configuration and Management Step 4 of 4 page is displayed. 8. Enter the name and location of the iDRAC device object in Active Directory (AD) and click Finish. The Active Directory settings for extended schema mode is configured. Configuring Active Directory with Extended schema using RACADM To configure Active Directory with Extended Schema using the RACADM: 1. Use the following commands: racadm set iDRAC.ActiveDirectory.Enable 1 racadm set iDRAC.ActiveDirectory.Schema 2 racadm set iDRAC.ActiveDirectory.RacName racadm set iDRAC.ActiveDirectory.RacDomain racadm set iDRAC.ActiveDirectory.DomainController1

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298

Adding privileges
To add privileges:
Click the
Privilege Object
tab to add the privilege object to the association that defines the user’s or user group’s privileges when
authenticating to an iDRAC device. Only one privilege object can be added to an Association Object.
1.
Select the
Privileges Object
tab and click
Add
.
2.
Enter the privilege object name and click
OK
.
3.
Click the
Privilege Object
tab to add the privilege object to the association that defines the user’s or user group’s privileges when
authenticating to an iDRAC device. Only one privilege object can be added to an Association Object.
Adding iDRAC devices or iDRAC device groups
To add iDRAC devices or iDRAC device groups:
1.
Select the
Products
tab and click
Add
.
2.
Enter iDRAC devices or iDRAC device group name and click
OK
.
3.
In the
Properties
window, click
Apply
and click
OK
.
4.
Click the
Products
tab to add one iDRAC device connected to the network that is available for the defined users or user groups. You
can add multiple iDRAC devices to an Association Object.
Configuring Active Directory with Extended schema using iDRAC web
interface
To configure Active Directory with extended schema using Web interface:
NOTE:
For information about the various fields, see the
iDRAC Online Help
.
1.
In the iDRAC Web interface, go to
Overview
>
iDRAC Settings
>
User Authentication
>
Directory Services
>
Microsoft Active
Directory
.
The
Active Directory
summary page is displayed.
2.
Click
Configure Active Directory
.
The
Active Directory Configuration and Management Step 1 of 4
page is displayed.
3.
Optionally, enable certificate validation and upload the CA-signed digital certificate used during initiation of SSL connections when
communicating with the Active Directory (AD) server.
4.
Click
Next
.
The
Active Directory Configuration and Management Step 2 of 4
page is displayed.
5.
Specify the location information about Active Directory (AD) servers and user accounts. Also, specify the time iDRAC must wait for
responses from AD during login process.
NOTE:
If certificate validation is enabled, specify the Domain Controller Server addresses and the FQDN. Make sure that
DNS is configured correctly under Overview > iDRAC Settings > Network
If the user and iDRAC objects are in different domains, then do not select the User Domain from Login option.
Instead select Specify a Domain option and enter the domain name where the iDRAC object is available.
6.
Click
Next
. The
Active Directory Configuration and Management Step 3 of 4
page is displayed.
7.
Select
Extended Schema
and click
Next
.
The
Active Directory Configuration and Management Step 4 of 4
page is displayed.
8.
Enter the name and location of the iDRAC device object in Active Directory (AD) and click
Finish
.
The Active Directory settings for extended schema mode is configured.
Configuring Active Directory with Extended schema using RACADM
To configure Active Directory with Extended Schema using the RACADM:
1.
Use the following commands:
racadm set iDRAC.ActiveDirectory.Enable 1
racadm set iDRAC.ActiveDirectory.Schema 2
racadm set iDRAC.ActiveDirectory.RacName <RAC common name>
racadm set iDRAC.ActiveDirectory.RacDomain <fully qualified rac domain name>
racadm set iDRAC.ActiveDirectory.DomainController1 <fully qualified domain name or IP
Configuring user accounts and privileges
139