HP Integrity BL870c HP Integrity iLO 2 Operations Guide, Eleventh Edition - Page 77

Setting Up Directory Security Groups, Login Process Using Directory Services Without Schema Extensions

Page 77 highlights

1. Follow the procedure for "Configuring LDAP Extended Schema" (page 74), but omit Step 8. It is not necessary to enter a new port number. 2. Set up directory security groups. Setting Up Directory Security Groups The following procedure describes how to set up directory security groups in schema-free LDAP using the iLO 2 MP TUI. To use the web interface, see "Group Accounts" (page 140). NOTE: Due to command syntax changes in schema-free LDAP, some customer-developed scripts may not run. You must change any scripts you developed to enable them to run with the new schema-free LDAP syntax. NOTE: You must select the default schema from the LDAP command for the schema-free LDAP settings to work. To set up directory security groups, follow these steps. 1. At the MP:CM> prompt, enter LDAP. The screen displays the current LDAP options. [hqgstlb3] MP:CM> ldap LDAP Current LDAP options: D - Directory settings G - Security Group Administration 2. Enter G. The current group configuration appears. Enter menu item or [Q] to Quit:G Current Group Configuration: Group Names Group Distinguished Names Access Rights 1 - Administrator 2 - User 3 - Custom1 4 - Custom2 5 - Custom3 6 - Custom4 C, P, M, U C, P None None None None Only the first 30 characters of the Group Distinguished Names are displayed. Enter number to view or modify, or [Q] to Quit: 3. Enter the number for the group you want to view or modify. The current LDAP group settings appear. 4. Set up a group distinguished name. 5. Select rights for the group. 6. Enter Y to confirm. Login Process Using Directory Services Without Schema Extensions You can control access to iLO 2 using directories without schema extensions. iLO 2 acquires the user name to determine group membership from the directory. iLO 2 then cross-references the group names with its locally stored names to determine user privilege level. iLO 2 must be configured with the appropriate group names and their associated privileges. To configure iLO 2, use one of the following methods: • Web GUI (Administration > Directory Settings > Group Administration page) • iLO 2 MP TUI (LDAP command) Configuring Schema-Free LDAP 77

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229

1.
Follow the procedure for
“Configuring LDAP Extended Schema” (page 74)
, but omit Step
8. It is not necessary to enter a new port number.
2.
Set up directory security groups.
Setting Up Directory Security Groups
The following procedure describes how to set up directory security groups in schema-free LDAP
using the iLO 2 MP TUI. To use the web interface, see
“Group Accounts” (page 140)
.
NOTE:
Due to command syntax changes in schema-free LDAP, some customer-developed
scripts may not run. You must change any scripts you developed to enable them to run with the
new schema-free LDAP syntax.
NOTE:
You must select the default schema from the
LDAP
command for the schema-free LDAP
settings to work.
To set up directory security groups, follow these steps.
1.
At the
MP:CM>
prompt, enter
LDAP
. The screen displays the current LDAP options.
[hqgstlb3] MP:CM> ldap
LDAP
Current LDAP options:
D - Directory settings
G - Security Group Administration
2.
Enter
G
. The current group configuration appears.
Enter menu item or [Q] to Quit:G
Current Group Configuration:
Group Names
Group Distinguished Names
Access Rights
--------------------------------------------------------------------------
1 - Administrator
C, P, M, U
2 - User
C, P
3 - Custom1
None
4 - Custom2
None
5 - Custom3
None
6 - Custom4
None
Only the first 30 characters of the Group Distinguished Names are displayed.
Enter number to view or modify, or [Q] to Quit:
3.
Enter the number for the group you want to view or modify. The current LDAP group
settings appear.
4.
Set up a group distinguished name.
5.
Select rights for the group.
6.
Enter
Y
to confirm.
Login Process Using Directory Services Without Schema Extensions
You can control access to iLO 2 using directories without schema extensions. iLO 2 acquires the
user name to determine group membership from the directory. iLO 2 then cross-references the
group names with its locally stored names to determine user privilege level. iLO 2 must be
configured with the appropriate group names and their associated privileges. To configure iLO
2, use one of the following methods:
Web GUI (Administration > Directory Settings > Group Administration page)
iLO 2 MP TUI (
LDAP
command)
Configuring Schema-Free LDAP
77