HP Integrity rx2800 HP Integrity iLO 3 Operations Guide - Page 36

Setting up directory security groups, Login process using directory services without schema extensions

Page 36 highlights

Setting up directory security groups The following procedure describes how to set up directory security groups in schema-free LDAP using the iLO 3 MP TUI. To use the web interface, see "Group Accounts" (page 91). NOTE: Due to command syntax changes in schema-free LDAP, some customer-developed scripts may not run. You must change any scripts you developed to enable them to run with the new schema-free LDAP syntax. NOTE: You must select the default schema from the LDAP command for the schema-free LDAP settings to work. To set up directory security groups: 1. At the CM:hpiLO-> prompt, enter LDAP. The screen displays the current LDAP options. [hqgstlb3] CM:hpiLO-> ldap LDAP Current LDAP options: D - Directory settings G - Security Group Administration 2. Enter G. The current group configuration appears. Enter menu item or [Q] to Quit:G Current Group Configuration: Group Names Group Distinguished Names Access Rights 1 - Administrator 2 - User 3 - Custom1 4 - Custom2 5 - Custom3 6 - Custom4 C, P, M, U C, P None None None None Only the first 30 characters of the Group Distinguished Names are displayed. Enter number to view or modify, or [Q] to Quit: 3. Enter the number for the group you want to view or modify. The current LDAP group settings appear. 4. Set up a group distinguished name. 5. Select rights for the group. 6. Enter Y to confirm. Login process using directory services without schema extensions You can control access to iLO 3 using directories without schema extensions. Integrity iLO 3 acquires the user name to determine group membership from the directory. The iLO 3 then cross-references the group names with its locally stored names to determine user privilege level. Integrity iLO 3 must be configured with the appropriate group names and their associated privileges. To configure iLO 3, use one of the following methods: • Web GUI (Administration > Directory Settings > Group Administration page) • iLO 3 MP TUI (LDAP command) 36 Configuring DHCP, DNS, LDAP, and schema-free LDAP

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152

Setting up directory security groups
The following procedure describes how to set up directory security groups in schema-free LDAP
using the iLO 3 MP TUI. To use the web interface, see
“Group Accounts” (page 91)
.
NOTE:
Due to command syntax changes in schema-free LDAP, some customer-developed scripts
may not run. You must change any scripts you developed to enable them to run with the new
schema-free LDAP syntax.
NOTE:
You must select the default schema from the
LDAP
command for the schema-free LDAP
settings to work.
To set up directory security groups:
1.
At the
CM:hpiLO->
prompt, enter
LDAP
. The screen displays the current LDAP options.
[hqgstlb3] CM:hpiLO-> ldap
LDAP
Current LDAP options:
D - Directory settings
G - Security Group Administration
2.
Enter
G
. The current group configuration appears.
Enter menu item or [Q] to Quit:G
Current Group Configuration:
Group Names
Group Distinguished Names
Access Rights
--------------------------------------------------------------------------
1 - Administrator
C, P, M, U
2 - User
C, P
3 - Custom1
None
4 - Custom2
None
5 - Custom3
None
6 - Custom4
None
Only the first 30 characters of the Group Distinguished Names are displayed.
Enter number to view or modify, or [Q] to Quit:
3.
Enter the number for the group you want to view or modify. The current LDAP group settings
appear.
4.
Set up a group distinguished name.
5.
Select rights for the group.
6.
Enter
Y
to confirm.
Login process using directory services without schema extensions
You can control access to iLO 3 using directories without schema extensions. Integrity iLO 3 acquires
the user name to determine group membership from the directory. The iLO 3 then cross-references
the group names with its locally stored names to determine user privilege level. Integrity iLO 3 must
be configured with the appropriate group names and their associated privileges. To configure iLO
3, use one of the following methods:
Web GUI (Administration > Directory Settings > Group Administration page)
iLO 3 MP TUI (
LDAP
command)
36
Configuring DHCP, DNS, LDAP, and schema-free LDAP