Dell PowerEdge VRTX Chassis Management Controller Version 1.0 for Dell PowerEd - Page 119

Configuring CMC For Single Sign-On Or Smart Card Login, System Requirements, Client Systems

Page 119 highlights

10 Configuring CMC For Single Sign-On Or Smart Card Login This section provides information to configure CMC for Smart Card login and Single Sign-On (SSO) login for Active Directory users. SSO uses Kerberos as an authentication method allowing users, who have signed in as an automatic- or single sign-on to subsequent applications such as Exchange. For single sign-on login, CMC uses the client system's credentials, which are cached by the operating system after you log in using a valid Active Directory account. Two-factor-authentication, provides a higher-level of security by requiring users to have a password or PIN, and a physical card containing a private key or digital certificate. Kerberos uses this two-factor authentication mechanism allowing systems to prove their authenticity. NOTE: Selecting a login method does not set policy attributes with respect to other login interfaces, for example, SSH. You must set other policy attributes for other login interfaces also. If you want to disable all other login interfaces, navigate to the Services page and disable all (or some) the login interfaces. Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows 7, and Windows Server 2008 can use Kerberos as the authentication mechanism for SSO and smart card login. For information about Kerberos, see the Microsoft Website. System Requirements To use the Kerberos authentication, the network must include: • DNS server • Microsoft Active Directory Server NOTE: If you are using Active Directory on Microsoft Windows 2003, make sure that you have the latest service packs and patched installed on the client system. If you are using Active Directory on Microsoft Windows 2008, make sure that you have installed SP1 along with the following hot fixes: Windows6.0-KB951191-x86.msu for the KTPASS utility. Without this patch the utility generates bad keytab files. Windows6.0-KB957072-x86.msu for using GSS_API and SSL transactions during an LDAP bind. • Kerberos Key Distribution Center (packaged with the Active Directory Server software). • DHCP server (recommended). • The DNS server reverse zone must have an entry for the Active Directory server and CMC. Client Systems • For only Smart Card login, the client system must have the Microsoft Visual C++ 2005 redistributable. For more information see www.microsoft.com/downloads/details.aspx?FamilyID= 32BC1BEEA3F9-4C13-9C99-220B62A191EE&displaylang=en • For Single Sign-On or smart card login, the client system must be a part of the Active Directory domain and Kerberos Realm. 119

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193

10
Configuring CMC For Single Sign-On Or Smart
Card Login
This section provides information to configure CMC for Smart Card login and Single Sign-On (SSO) login for Active
Directory users.
SSO uses Kerberos as an authentication method allowing users, who have signed in as an automatic- or single sign-on
to subsequent applications such as Exchange. For single sign-on login, CMC uses the client system’s credentials, which
are cached by the operating system after you log in using a valid Active Directory account.
Two-factor-authentication, provides a higher-level of security by requiring users to have a password or PIN, and a
physical card containing a private key or digital certificate. Kerberos uses this two-factor authentication mechanism
allowing systems to prove their authenticity.
NOTE:
Selecting a login method does not set policy attributes with respect to other login interfaces, for example,
SSH. You must set other policy attributes for other login interfaces also. If you want to disable all other login
interfaces, navigate to the
Services
page and disable all (or some) the login interfaces.
Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows 7, and Windows Server 2008
can use Kerberos as the authentication mechanism for SSO and smart card login.
For information about Kerberos, see the Microsoft Website.
System Requirements
To use the Kerberos authentication, the network must include:
DNS server
Microsoft Active Directory Server
NOTE:
If you are using Active Directory on Microsoft Windows 2003, make sure that you have the latest
service packs and patched installed on the client system. If you are using Active Directory on Microsoft
Windows 2008, make sure that you have installed SP1 along with the following hot fixes:
Windows6.0-KB951191-x86.msu
for the KTPASS utility. Without this patch the utility generates bad keytab
files.
Windows6.0-KB957072-x86.msu
for using GSS_API and SSL transactions during an LDAP bind.
Kerberos Key Distribution Center (packaged with the Active Directory Server software).
DHCP server (recommended).
The DNS server reverse zone must have an entry for the Active Directory server and CMC.
Client Systems
For only Smart Card login, the client system must have the Microsoft Visual C++ 2005 redistributable. For more
information see
www.microsoft.com/downloads/details.aspx?FamilyID=
32BC1BEEA3F9-4C13-9C99-220B62A191EE&displaylang=en
For Single Sign-On or smart card login, the client system must be a part of the Active Directory domain and
Kerberos Realm.
119