Dell PowerEdge VRTX Chassis Management Controller Version 1.0 for Dell PowerEd - Page 191

Active Directory, FlexAddress and FlexAddressPlus

Page 191 highlights

Active Directory Does Active Directory support CMC login across multiple trees? Yes. The CMC's Active Directory querying algorithm supports multiple trees in a single forest. Does the login to CMC using Active Directory work in mixed mode (that is, the domain controllers in the forest run different operating systems, such as Microsoft Windows 2000 or Windows Server 2003)? Yes. In mixed mode, all objects used by the CMC querying process (among user, RAC Device Object, and Association Object) must be in the same domain. The Dell-extended Active Directory Users and Computers Snap-In checks the mode and limits users in order to create objects across domains, if in a mixed mode. Does using CMC with Active Directory support multiple domain environments? Yes. The domain forest function level must be in Native mode or Windows 2003 mode. In addition, the groups among Association Object, RAC user objects, and RAC Device Objects (including Association Object) must be universal groups. Can these Dell-extended objects (Dell Association Object, Dell RAC Device, and Dell Privilege Object) be in different domains? The Association Object and the Privilege Object must be in the same domain. The Dell-extended Active Directory Users and Computers Snap-In allows to create these two objects in the same domain only. Other objects can be in different domains. Are there any restrictions on Domain Controller SSL configuration? Yes. All SSL certificates for Active Directory servers in the forest must be signed by the same root certificate authoritysigned certificate, because CMC only allows upload of one trusted certificate authority-signed SSL certificate. The Web interface does not launch after a new RAC certificate is created and uploaded. If Microsoft Certificate Services is used to generate the RAC certificate, the User Certificate option may have been used instead of Web Certificate, when creating the certificate. To recover, generate a CSR, create a new Web certificate from Microsoft Certificate Services, and then upload it by running the following RACADM commands: racadm sslcsrgen [-g] [-f {filename}] racadm sslcertupload -t 1 -f {web_sslcert} FlexAddress and FlexAddressPlus What happens if a feature card is removed? There is no visible change if a feature card is removed. Feature cards can be removed and stored, or can be left in place. What happens if a feature card that was used in one chassis is removed and put into another chassis? The Web interface displays the following error message: This feature card was activated with a different chassis. It must be removed before accessing the FlexAddress feature. Current Chassis Service Tag = XXXXXXXX Feature Card Chassis Service Tag = YYYYYYYY An entry is added to the CMC log that states: cmc : feature 'FlexAddress@YYYYYYYY' not activated; chassis ID='XXXXXXXX' What happens if the feature card is removed and a non-FlexAddress card is installed? 191

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193

Active Directory
Does Active Directory support CMC login across multiple trees?
Yes. The CMC’s Active Directory querying algorithm supports multiple trees in a single forest.
Does the login to CMC using Active Directory work in mixed mode (that is, the domain controllers in the forest run
different operating systems, such as Microsoft Windows 2000 or Windows Server 2003)?
Yes. In mixed mode, all objects used by the CMC querying process (among user, RAC Device Object, and Association
Object) must be in the same domain.
The Dell-extended Active Directory Users and Computers Snap-In checks the mode and limits users in order to create
objects across domains, if in a mixed mode.
Does using CMC with Active Directory support multiple domain environments?
Yes. The domain forest function level must be in Native mode or Windows 2003 mode. In addition, the groups among
Association Object, RAC user objects, and RAC Device Objects (including Association Object) must be universal groups.
Can these Dell-extended objects (Dell Association Object, Dell RAC Device, and Dell Privilege Object) be in different
domains?
The Association Object and the Privilege Object must be in the same domain. The Dell-extended Active Directory Users
and Computers Snap-In allows to create these two objects in the same domain only. Other objects can be in different
domains.
Are there any restrictions on Domain Controller SSL configuration?
Yes. All SSL certificates for Active Directory servers in the forest must be signed by the same root certificate authority-
signed certificate, because CMC only allows upload of one trusted certificate authority-signed SSL certificate.
The Web interface does not launch after a new RAC certificate is created and uploaded.
If Microsoft Certificate Services is used to generate the RAC certificate, the User Certificate option may have been used
instead of Web Certificate, when creating the certificate.
To recover, generate a CSR, create a new Web certificate from Microsoft Certificate Services, and then upload it by
running the following RACADM commands:
racadm sslcsrgen [-g] [-f {filename}]
racadm sslcertupload -t 1 -f {web_sslcert}
FlexAddress and FlexAddressPlus
What happens if a feature card is removed?
There is no visible change if a feature card is removed. Feature cards can be removed and stored, or can be left in
place.
What happens if a feature card that was used in one chassis is removed and put into another chassis?
The Web interface displays the following error message:
This feature card was activated with a different chassis. It must be removed
before accessing the FlexAddress feature.
Current Chassis Service Tag = XXXXXXXX
Feature Card Chassis Service Tag = YYYYYYYY
An entry is added to the CMC log that states:
cmc <date timestamp> : feature 'FlexAddress@YYYYYYYY' not activated; chassis
ID='XXXXXXXX'
What happens if the feature card is removed and a non-FlexAddress card is installed?
191