HP Integrity BL870c HP Integrity iLO 2 Operations Guide, Eleventh Edition - Page 185

Preparing Directory Services for Active Directory

Page 185 highlights

IMPORTANT: To install directory services for iLO 2, an Active Directory schema administrator must extend the schema. • Extending the schema in the Microsoft Windows 2000 Server Resource Kit, available at: http://www.microsoft.com • Installing Active Directory in the Microsoft Windows 2000 Server Resource Kit, available at: http://www.microsoft.com • Microsoft Knowledge Base articles: - 216999 "How to Install the Remote Server Administration Tools in Windows" - 314978 "How to Use Adminpak.msi to Install a Specific Server Administration Tool in Windows 2000" - 247078 "How to Enable SSL Communication over LDAP for Windows 2000 Domain Controllers" - 321051 "How to Enable LDAP over SSL with a Third-Party Certification Authority" - 299687 MS01-036 "Function Exposed by Using LDAP over SSL Could Enable Passwords to Be Changed" Integrity iLO 2 requires a secure connection to communicate with the directory service. This secure connection requires the installation of the Microsoft CA. For more information, see the following Microsoft technical references: • Securing Windows 2000, Appendix D, Configuring Digital Certificates on Domain Controllers for Secure LDAP and SMTP Replication at: http://www.microsoft.com • Microsoft Knowledge Base Article 321051 "How to Enable LDAP over SSL with a Third-Party Certification Authority" Preparing Directory Services for Active Directory To set up directory services for use with iLO 2, follow these steps: 1. Install Active Directory. For more information, see the resource kit, Installing Active Directory in the Microsoft Windows 2000 Server. 2. Install the Microsoft Admin Pack (the ADMINPAK.MSI file, which is located in the i386 subdirectory of the Windows 2000 Server or Advanced Server CD). For more information, see the Microsoft Knowledge Base Article 216999. 3. In Windows 2000, the safety interlock that prevents accidental writes to the schema must be temporarily disabled. The schema extender utility can do this if the remote registry service is running and you have appropriate rights. You can also do this by setting HKEY_LOCAL_MACHINE SYSTEM CurrentControlSet Services NTDS Parameters Schema Update Allowed in the registry to a nonzero value (see the "Order of Processing When Extending the Schema" section of the Installation of Schema Extensions in the Windows 2000 Server Resource Kit), or by doing the following: CAUTION: Incorrectly editing the registry can severely damage your system. HP recommends creating a backup of any valued data on the computer before making changes to the registry. NOTE: This step is not necessary if you are using Windows Server 2003. a. Start the MMC. b. In MMC, install the Active Directory schema snap-in. c. Right-click Active Directory Schema and select Operations Master. d. Select The Schema may be modified on this Domain Controller. e. Click OK. Directory Services for Active Directory 185

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229

IMPORTANT:
To install directory services for iLO 2, an Active Directory schema administrator
must extend the schema.
Extending the schema in the Microsoft Windows 2000 Server Resource Kit, available at:
http://www
.microsoft.com
Installing Active Directory in the Microsoft Windows 2000 Server Resource Kit, available
at:
http://www
.microsoft.com
Microsoft Knowledge Base articles:
216999 “How to Install the Remote Server Administration Tools in Windows”
314978 “How to Use Adminpak.msi to Install a Specific Server Administration Tool in
Windows 2000”
247078 “How to Enable SSL Communication over LDAP for Windows 2000 Domain
Controllers”
321051 “How to Enable LDAP over SSL with a Third-Party Certification Authority”
299687 MS01-036 “Function Exposed by Using LDAP over SSL Could Enable Passwords
to Be Changed”
Integrity iLO 2 requires a secure connection to communicate with the directory service. This
secure connection requires the installation of the Microsoft CA. For more information, see the
following Microsoft technical references:
Securing Windows 2000, Appendix D, Configuring Digital Certificates on Domain Controllers
for Secure LDAP and SMTP Replication at:
http://www
.microsoft.com
Microsoft Knowledge Base Article 321051 “How to Enable LDAP over SSL with a Third-Party
Certification Authority”
Preparing Directory Services for Active Directory
To set up directory services for use with iLO 2, follow these steps:
1.
Install Active Directory. For more information, see the resource kit, Installing Active Directory
in the Microsoft Windows 2000 Server.
2.
Install the Microsoft Admin Pack (the
ADMINPAK.MSI
file, which is located in the i386
subdirectory of the Windows 2000 Server or Advanced Server CD). For more information,
see the Microsoft Knowledge Base Article 216999.
3.
In Windows 2000, the safety interlock that prevents accidental writes to the schema must
be temporarily disabled. The schema extender utility can do this if the remote registry service
is running and you have appropriate rights. You can also do this by setting
HKEY_LOCAL_MACHINE SYSTEM CurrentControlSet Services NTDS Parameters Schema
Update Allowed
in the registry to a nonzero value (see the “Order of Processing When
Extending the Schema” section of the Installation of Schema Extensions in the Windows
2000 Server Resource Kit), or by doing the following:
CAUTION:
Incorrectly editing the registry can severely damage your system. HP
recommends creating a backup of any valued data on the computer before making changes
to the registry.
NOTE:
This step is not necessary if you are using Windows Server 2003.
a.
Start the MMC.
b.
In MMC, install the Active Directory schema snap-in.
c.
Right-click
Active Directory Schema
and select
Operations Master
.
d.
Select
The Schema may be modified on this Domain Controller
.
e.
Click
OK
.
Directory Services for Active Directory
185