HP Integrity BL870c HP Integrity iLO 2 Operations Guide, Eleventh Edition - Page 76

Configuring Schema-Free LDAP

Page 76 highlights

It assists with installing the schema and snap-ins needed for Active Directory to work with iLO 2 products including Integrity iLO 2. This is for set up and management. It will not do automatic migration for you. For Integrity iLO 2, you must manually add iLO 2 objects to the directory server and set up user accounts and privileges. You can find the tool on the HP website at: http://h20000.www2.hp.com/bizsupport/TechSupport/ SoftwareDescription.jsp?lang=en&cc=US&swItem=MTX-UNITY-I23896 Using directory services after users enter their login and password, the browser sends the cookie to iLO 2. The iLO 2 processor accesses the directory service to determine which roles are available for that user login. iLO 2 first uses the credentials to access the iLO 2 device object in the directory. The directory service returns only the roles for which the user has rights. If the user credentials allow read access to the iLO 2 device object and the role object, iLO 2 determines the role object's distinguished name and the associated user privileges. iLO 2 then calculates the current user privileges based on those roles and grants them to that user. Configuring Schema-Free LDAP IMPORTANT: Due to command syntax changes in schema-free LDAP, some customer-developed scripts may not run. You must change any scripts you developed to enable them to run with the new schema-free LDAP syntax. Integrity iLO 2 schema-free directory integration enables you to use the standard directory schema instead of adding HP's schema to the directory database. You accomplish this by authenticating users from the directory database and authorizing iLO 2 privileges based on matching groups stored on each iLO 2. NOTE: Schema-Free LDAP is available only if you have the iLO 2 Advanced Pack license. In addition to general directory integration benefits, iLO 2 schema-free integration provides the following advantages: • Easy implementation without schema extensions. iLO 2 schema-free integration is configured from any iLO 2 user interface (browser, command line, or script). • Minimal administration and maintenance. - After initial setup, only groups and permissions require maintenance support on iLO 2; typically group and permission changes occur infrequently. - The schema-free approach does not require updating directory databases with new iLO 2 devices objects. • Reliable security. Integrity iLO 2 schema-free integration does not affect standard directory attributes, avoiding conflicting use of attributes that can result over time. • Complements two-factor authentication. Integrity iLO 2 schema-free integration can be used in conjunction with iLO 2 two-factor authentication to provide asset protection using strong authentication. NOTE: If you have already extended your directory with HP schema, there is no need to switch to the schema-free approach. Schema extension provides the lowest maintenance approach for directory integration. Once this process has taken place, there is no advantage for the schema-free approach until a schema change is required. To configure schema-free LDAP, follow these steps: 76 Configuring DHCP, DNS, LDAP, and Schema-Free LDAP

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229

It assists with installing the schema and snap-ins needed for Active Directory to work with iLO
2 products including Integrity iLO 2. This is for set up and management. It will not do automatic
migration for you. For Integrity iLO 2, you must manually add iLO 2 objects to the directory
server and set up user accounts and privileges. You can find the tool on the HP website at:
echSupport/
Softw
areDescription.jsp?lang=en&cc=US&swItem=MTX-UNITY-I23896
Using directory services after users enter their login and password, the browser sends the cookie
to iLO 2. The iLO 2 processor accesses the directory service to determine which roles are available
for that user login. iLO 2 first uses the credentials to access the iLO 2 device object in the directory.
The directory service returns only the roles for which the user has rights. If the user credentials
allow read access to the iLO 2 device object and the role object, iLO 2 determines the role object’s
distinguished name and the associated user privileges. iLO 2 then calculates the current user
privileges based on those roles and grants them to that user.
Configuring Schema-Free LDAP
IMPORTANT:
Due to command syntax changes in schema-free LDAP, some customer-developed
scripts may not run. You must change any scripts you developed to enable them to run with the
new schema-free LDAP syntax.
Integrity iLO 2 schema-free directory integration enables you to use the standard directory
schema instead of adding HP’s schema to the directory database. You accomplish this by
authenticating users from the directory database and authorizing iLO 2 privileges based on
matching groups stored on each iLO 2.
NOTE:
Schema-Free LDAP is available only if you have the iLO 2 Advanced Pack license.
In addition to general directory integration benefits, iLO 2 schema-free integration provides the
following advantages:
Easy implementation without schema extensions.
iLO 2 schema-free integration is configured from any iLO 2 user interface (browser, command
line, or script).
Minimal administration and maintenance.
After initial setup, only groups and permissions require maintenance support on iLO
2; typically group and permission changes occur infrequently.
The schema-free approach does not require updating directory databases with new iLO
2 devices objects.
Reliable security.
Integrity iLO 2 schema-free integration does not affect standard directory attributes, avoiding
conflicting use of attributes that can result over time.
Complements two-factor authentication.
Integrity iLO 2 schema-free integration can be used in conjunction with iLO 2 two-factor
authentication to provide asset protection using strong authentication.
NOTE:
If you have already extended your directory with HP schema, there is no need to switch
to the schema-free approach. Schema extension provides the lowest maintenance approach for
directory integration. Once this process has taken place, there is no advantage for the schema-free
approach until a schema change is required.
To configure schema-free LDAP, follow these steps:
76
Configuring DHCP, DNS, LDAP, and Schema-Free LDAP