HP Integrity rx2800 HP Integrity iLO 3 Operations Guide - Page 131

Enforcing directory login restrictions, Enforcing user time restrictions,

Page 131 highlights

Enforcing directory login restrictions The following figure shows how two sets of restrictions potentially limit a directory user's access to iLO 3 devices. User access restrictions limit a user's access to authenticate to the directory. Role access restrictions limit an authenticated user's ability to receive iLO 3 privileges based on rights specified in one or more roles. Figure 59 shows the user and role access restrictions. Figure 59 User and role access restrictions Enforcing user time restrictions You can place a time restriction on directory user accounts. Time restrictions limit the ability of the user to log in (authenticate) to the directory. Typically, time restrictions are enforced using the time on the directory server, but if the directory server is located in a different time zones or a replica in a different time zone is accessed, time zone information from the managed object can be used to adjust for relative time. While directory server evaluates user time restrictions, the determination can be complicated by time zone changes or by the authentication mechanism. Figure 60 shows the user time restrictions. Directory-enabled remote management 131

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152

Enforcing directory login restrictions
The following figure shows how two sets of restrictions potentially limit a directory user's access to
iLO 3 devices. User access restrictions limit a user's access to authenticate to the directory. Role
access restrictions limit an authenticated user's ability to receive iLO 3 privileges based on rights
specified in one or more roles.
Figure 59
shows the user and role access restrictions.
Figure 59 User and role access restrictions
Enforcing user time restrictions
You can place a time restriction on directory user accounts. Time restrictions limit the ability of the
user to log in (authenticate) to the directory. Typically, time restrictions are enforced using the time
on the directory server, but if the directory server is located in a different time zones or a replica
in a different time zone is accessed, time zone information from the managed object can be used
to adjust for relative time.
While directory server evaluates user time restrictions, the determination can be complicated by
time zone changes or by the authentication mechanism.
Figure 60
shows the user time restrictions.
Directory-enabled remote management
131