HP Integrity rx2800 HP Integrity iLO 3 Operations Guide - Page 133

Directory services schema (LDAP), HP management core LDAP object identifier classes and attributes

Page 133 highlights

Figure 61 Restricting general use Alternatively, the directory administrator could create a role that grants the login right and restrict it to the corporate network, create another role that grants only the server reset right and restrict it to after-hours operation. This configuration is easier to manage but more dangerous because ongoing administration can create another role that grants users from addresses outside the corporate network the login right, which could unintentionally grant the iLO 3 administrators in the server reset role the ability to reset the server from anywhere, provided they satisfy the time constraints of that role. The previous configuration satisfies corporate security policy. However, adding another role that grants the login right can inadvertently grant server reset privileges from outside the corporate subnet after hours. A more manageable solution might be to restrict the reset role, as well as the general use role. Figure 62 Restricting the reset role Directory services schema (LDAP) A directory schema specifies the types of objects that a directory can have and the mandatory and optional attributes of each object type. The following sections describe both the HP management core, and the LDAP object identifier classes and attributes that are specific to iLO 3. HP management core LDAP object identifier classes and attributes Object identifiers (OIDs) are unique numbers that are used by LDAP to identify object class, attribute, syntaxes (data types), matching rules, protocol mechanisms, controls, extended operation and supported features. Directory services schema (LDAP) 133

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152

Figure 61 Restricting general use
Alternatively, the directory administrator could create a role that grants the login right and restrict
it to the corporate network, create another role that grants only the server reset right and restrict
it to after-hours operation. This configuration is easier to manage but more dangerous because
ongoing administration can create another role that grants users from addresses outside the
corporate network the login right, which could unintentionally grant the iLO 3 administrators in
the server reset role the ability to reset the server from anywhere, provided they satisfy the time
constraints of that role.
The previous configuration satisfies corporate security policy. However, adding another role that
grants the login right can inadvertently grant server reset privileges from outside the corporate
subnet after hours. A more manageable solution might be to restrict the reset role, as well as the
general use role.
Figure 62 Restricting the reset role
Directory services schema (LDAP)
A directory schema specifies the types of objects that a directory can have and the mandatory and
optional attributes of each object type. The following sections describe both the HP management
core, and the LDAP object identifier classes and attributes that are specific to iLO 3.
HP management core LDAP object identifier classes and attributes
Object identifiers (OIDs) are unique numbers that are used by LDAP to identify object class, attribute,
syntaxes (data types), matching rules, protocol mechanisms, controls, extended operation and
supported features.
Directory services schema (LDAP)
133