HP Integrity BL870c HP Integrity iLO 2 Operations Guide, Eleventh Edition - Page 179

Installing and Configuring Directory Services, Directory Services

Page 179 highlights

9 Installing and Configuring Directory Services This chapter provides information on how to install and configure iLO 2 directory services. You can install and configure iLO 2 directory services to leverage the benefits of a single point of administration for iLO 2 user accounts. Directory Services The following are benefits of directory integration: Scalability Leverage the directory to support thousands of users on thousands of iLO 2s. Security Robust user password policies are inherited from the directory. User password complexity, rotation frequency, and expiration are policy examples. Role-based administration You can create roles (for instance, clerical, remote control of the host, complete control), and associate users or user groups with those roles. When you change a single role, the change applies to all users and the iLO 2 devices associated with that role. Single point of administration You can use native administrative tools, like Microsoft Management Console (MMC) and ConsoleOne, to administer the iLO 2 users. Immediacy A single change in the directory rolls out immediately to associated iLO 2s, eliminating the need to script this process. Reuse of user name and password You can use existing user accounts and passwords in the directory without having to record or remember a new set of credentials for iLO 2. Flexibility You can create a single role for a single user on a single iLO 2; you can create a single role for multiple users on multiple iLO 2s; or you can use a combination of roles to best fit your enterprise. Compatibility The iLO 2 directory integration applies to the iLO 2 products and supports the popular directories Active Directory and eDirectory. Standards The iLO 2 directory support builds on the LDAP 2.0 standard for secure directory access. Features Supported by Directory Integration The iLO 2 directory services functionality enables you to do the following: • Authenticate users from a shared, consolidated, scalable user database. • Control user privileges (authorization) using the directory service. • Use roles in the directory service for group-level administration of iLO 2 and iLO 2 users. To install directory services for the iLO 2, a schema administrator must extend the directory schema. The local user database is retained. You can choose not to use directories, to use a combination of directories and local accounts, or to use directories exclusively for authentication. Directory Services 179

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229

9 Installing and Configuring Directory Services
This chapter provides information on how to install and configure iLO 2 directory services.
You can install and configure iLO 2 directory services to leverage the benefits of a single point
of administration for iLO 2 user accounts.
Directory Services
The following are benefits of directory integration:
Scalability
Leverage the directory to support thousands of users on
thousands of iLO 2s.
Security
Robust user password policies are inherited from the
directory. User password complexity, rotation frequency,
and expiration are policy examples.
Role-based administration
You can create roles (for instance, clerical, remote control
of the host, complete control), and associate users or user
groups with those roles. When you change a single role,
the change applies to all users and the iLO 2 devices
associated with that role.
Single point of administration
You can use native administrative tools, like Microsoft
Management Console (MMC) and ConsoleOne, to
administer the iLO 2 users.
Immediacy
A single change in the directory rolls out immediately to
associated iLO 2s, eliminating the need to script this
process.
Reuse of user name and password
You can use existing user accounts and passwords in the
directory without having to record or remember a new set
of credentials for iLO 2.
Flexibility
You can create a single role for a single user on a single
iLO 2; you can create a single role for multiple users on
multiple iLO 2s; or you can use a combination of roles to
best fit your enterprise.
Compatibility
The iLO 2 directory integration applies to the iLO 2
products and supports the popular directories Active
Directory and eDirectory.
Standards
The iLO 2 directory support builds on the LDAP 2.0
standard for secure directory access.
Features Supported by Directory Integration
The iLO 2 directory services functionality enables you to do the following:
Authenticate users from a shared, consolidated, scalable user database.
Control user privileges (authorization) using the directory service.
Use roles in the directory service for group-level administration of iLO 2 and iLO 2 users.
To install directory services for the iLO 2, a schema administrator must extend the directory
schema.
The local user database is retained. You can choose not to use directories, to use a combination
of directories and local accounts, or to use directories exclusively for authentication.
Directory Services
179