HP Integrity rx2800 HP Integrity iLO 3 Operations Guide - Page 102

Installing and configuring directory services, Directory services

Page 102 highlights

8 Installing and configuring directory services You can install and configure iLO 3 directory services to leverage the benefits of a single point of administration for iLO 3 user accounts. This chapter provides information on how to install and configure iLO 3 directory services. Directory services The following are benefits of directory integration: Scalability Leverage the directory to support thousands of users on thousands of iLO 3s. Security Robust user password policies are inherited from the directory. User password complexity, rotation frequency, and expiration are policy examples. Role-based administration You can create roles (for instance, clerical, remote control of the host, complete control), and associate users or user groups with those roles. When you change a single role, the change applies to all users and the iLO 3 devices associated with that role. Single point of administration You can use native administrative tools, like Microsoft Management Console (MMC) and ConsoleOne, to administer the iLO 3 users. Immediacy A single change in the directory rolls out immediately to associated iLO 3s, eliminating the need to script this process. Reuse of user name and password You can use existing user accounts and passwords in the directory without having to record or remember a new set of credentials for iLO 3. Flexibility You can create a single role for a single user on a single iLO 3; you can create a single role for multiple users on multiple iLO 3s; or you can use a combination of roles to best fit your enterprise. Compatibility The iLO 3 directory integration applies to the iLO 3 products and supports the popular directories Active Directory and eDirectory. Standards The iLO 3 directory support builds on the LDAP 2.0 standard for secure directory access. Features supported by directory integration The iLO 3 directory services functionality enables you to do the following: • Authenticate users from a shared, consolidated, scalable user database. • Control user privileges (authorization) using the directory service. • Use roles in the directory service for group-level administration of iLO 3 and iLO 3 users. To install directory services for the iLO 3, a schema administrator must extend the directory schema. The local user database is retained. You can choose not to use directories, to use a combination of directories and local accounts, or to use directories exclusively for authentication. Directory services installation prerequisites Before installing directory services, you must configure LDAP. 102 Installing and configuring directory services

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152

8 Installing and configuring directory services
You can install and configure iLO 3 directory services to leverage the benefits of a single point of
administration for iLO 3 user accounts.
This chapter provides information on how to install and configure iLO 3 directory services.
Directory services
The following are benefits of directory integration:
Scalability
Leverage the directory to support thousands of users on
thousands of iLO 3s.
Security
Robust user password policies are inherited from the
directory. User password complexity, rotation frequency,
and expiration are policy examples.
Role-based administration
You can create roles (for instance, clerical, remote control
of the host, complete control), and associate users or user
groups with those roles. When you change a single role,
the change applies to all users and the iLO 3 devices
associated with that role.
Single point of administration
You can use native administrative tools, like Microsoft
Management Console (MMC) and ConsoleOne, to
administer the iLO 3 users.
Immediacy
A single change in the directory rolls out immediately to
associated iLO 3s, eliminating the need to script this process.
Reuse of user name and password
You can use existing user accounts and passwords in the
directory without having to record or remember a new set
of credentials for iLO 3.
Flexibility
You can create a single role for a single user on a single
iLO 3; you can create a single role for multiple users on
multiple iLO 3s; or you can use a combination of roles to
best fit your enterprise.
Compatibility
The iLO 3 directory integration applies to the iLO 3 products
and supports the popular directories Active Directory and
eDirectory.
Standards
The iLO 3 directory support builds on the LDAP 2.0 standard
for secure directory access.
Features supported by directory integration
The iLO 3 directory services functionality enables you to do the following:
Authenticate users from a shared, consolidated, scalable user database.
Control user privileges (authorization) using the directory service.
Use roles in the directory service for group-level administration of iLO 3 and iLO 3 users.
To install directory services for the iLO 3, a schema administrator must extend the directory schema.
The local user database is retained. You can choose not to use directories, to use a combination
of directories and local accounts, or to use directories exclusively for authentication.
Directory services installation prerequisites
Before installing directory services, you must configure LDAP.
102
Installing and configuring directory services