HP Integrity Superdome 2 HP Integrity Superdome 2 Onboard Administrator User G - Page 178

Creating directory groups, In Onboard Administrator

Page 178 highlights

qTvgisrZeHtvmrmecvSxZm27b4Bj5XYN0VYcrwqKnH7X/tVhmwqGls7/YZyahNU1 lGB2OjoCq5eJxX+Ybx0CAwEAAaOCA00wggNJMAsGA1UdDwQEAwIFoDBEBgkqhkiG 9w0BCQ8ENzA1MA4GCCqGSIb3DQMCAgIAgDAOBggqhkiG9w0DBAICAIAwBwYFKw4D ...output truncated... -----END CERTIFICATE----8. Return to the OA Upload Certificate screen, paste the certificate contents into the window, and then click the Upload button. Creating directory groups Onboard Administrator authenticates users and assigns privileges by first verifying that the user name and password provided to Onboard Administrator match the credentials in the Directory. When a match is verified, Onboard Administrator queries the Directory to discover the names of the Active Directory groups the user is a member of. Onboard Administrator then matches those group names against the Directory Group names that exist in Onboard Administrator. In the following example, Onboard Administrator Directory Groups are created. The group name is used to determine LDAP users group membership and must match one of the following properties of a directory group: • Name • Distinguished name • Common name • Display name • SAM account name To create a directory group: 1. In Onboard Administrator, navigate to the Users/Authentications/Directory Groups link. 2. Click the New button. 3. Create a group named OA Admins which is the same name as the one created in the Active Directory. 4. Assign this group full administrative privileges over all server bays and interconnect bays and then click the Add button. 5. Create a Second Directory Group named OA Operators to match the operator group created in Active Directory. Assign the group Operator privilege level instead of Administrator, and do not allow the group access to Server Bays, but do allow access to Interconnect bays, and then click the Add button. 178 Enabling LDAP Directory Services Authentication to Microsoft Active Directory

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191

qTvgisrZeHtvmrmecvSxZm27b4Bj5XYN0VYcrwqKnH7X/tVhmwqGls7/YZyahNU1
lGB2OjoCq5eJxX+Ybx0CAwEAAaOCA00wggNJMAsGA1UdDwQEAwIFoDBEBgkqhkiG
9w0BCQ8ENzA1MA4GCCqGSIb3DQMCAgIAgDAOBggqhkiG9w0DBAICAIAwBwYFKw4D
output truncated
-----END CERTIFICATE-----
8.
Return to the OA Upload Certificate screen, paste the certificate contents into the window,
and then click the
Upload
button.
Creating directory groups
Onboard Administrator authenticates users and assigns privileges by first verifying that the user
name and password provided to Onboard Administrator match the credentials in the Directory.
When a match is verified, Onboard Administrator queries the Directory to discover the names of
the Active Directory groups the user is a member of. Onboard Administrator then matches those
group names against the Directory Group names that exist in Onboard Administrator. In the
following example, Onboard Administrator Directory Groups are created. The group name is used
to determine LDAP users group membership and must match one of the following properties of a
directory group:
Name
Distinguished name
Common name
Display name
SAM account name
To create a directory group:
1.
In Onboard Administrator, navigate to the Users/Authentications/Directory Groups link.
2.
Click the
New
button.
3.
Create a group named OA Admins which is the same name as the one created in the Active
Directory.
4.
Assign this group full administrative privileges over all server bays and interconnect bays and
then click the
Add
button.
5.
Create a Second Directory Group named OA Operators to match the operator group created
in Active Directory. Assign the group Operator privilege level instead of Administrator, and
do not allow the group access to Server Bays, but do allow access to Interconnect bays, and
then click the
Add
button.
178
Enabling LDAP Directory Services Authentication to Microsoft Active Directory