HP Xw460c HP Integrated Lights-Out 2 User Guide for Firmware 1.75 and 1.77 - Page 138

Setup for Schema-free directory integration, Active Directory preparation

Page 138 highlights

• Multiple targets You do not need to use multiple targets in the directory. HP schema directory integration only requires one hpqTarget object, which can represent many LOM devices. Setup for Schema-free directory integration Before setting up the Schema-free option, your system must meet all the prerequisites outlined in the "Active Directory Preparation (on page 138)" section. You can set up iLO 2 for directories in three ways: • Manually using a browser ("Schema-free browser-based setup" on page 139). • Using a script ("Schema-free scripted setup" on page 140). • Using HPLOMIG ("Schema-free HPLOMIG-based setup" on page 140). Active Directory preparation The schema-free option is supported on the following operating systems: • Microsoft® Active Directory • Microsoft® Windows® Server 2003 Active Directory SSL must be enabled at the directory. To enable SSL, install a certificate for the domain in Active Directory. iLO 2 only communicates with the directory over a secure SSL connection. For more information, refer to the Microsoft® Knowledge Base, article number 247078: Enabling SSL Communication over LDAP for Windows® 2000 Domain Controllers on the Microsoft® website (http://support.microsoft.com/). To validate the setup, you should have the directory distinguished name for at least one user and the distinguished name of a security group the user is a member of. Introduction to certificate services Certificate Services are used to issue signed digital certificates to network hosts. The certificates are used to establish SSL connections with the host and verify the authenticity of the host. Installing Certificate Services allows Active Directory to receive a certificate that allows Lights-Out processors to connect to the directory service. Without a certificate, iLO 2 cannot connect to the directory server. Each directory server that you want iLO 2 to connect to must be issued a certificate. If you install an Enterprise Certificate Service, Active Directory can automatically request and install certificates for all of the Active Directory controllers on the network. Installing certificate services 1. Select Start>Settings>Control Panel. 2. Double-click Add/Remove Programs. 3. Click Add/Remove Windows Components to start the Windows Components wizard. 4. Select the Certificate Services check box. Click Next. Directory services 138

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235

Directory services 138
Multiple targets
You do not need to use multiple targets in the directory. HP schema directory integration only
requires one hpqTarget object, which can represent many LOM devices.
Setup for Schema-free directory integration
Before setting up the Schema-free option, your system must meet all the prerequisites outlined in the
"Active Directory Preparation (on page
138
)" section.
You can set up iLO 2 for directories in three ways:
Manually using a browser ("
Schema-free browser-based setup
" on page
139
).
Using a script ("
Schema-free scripted setup
" on page
140
).
Using HPLOMIG ("
Schema-free HPLOMIG-based setup
" on page
140
).
Active Directory preparation
The schema-free option is supported on the following operating systems:
Microsoft® Active Directory
Microsoft® Windows® Server 2003 Active Directory
SSL must be enabled at the directory. To enable SSL, install a certificate for the domain in Active
Directory. iLO 2 only communicates with the directory over a secure SSL connection. For more
information, refer to the Microsoft® Knowledge Base, article number 247078:
Enabling SSL
Communication over LDAP for Windows® 2000 Domain Controllers
on the Microsoft® website
(
).
To validate the setup, you should have the directory distinguished name for at least one user and the
distinguished name of a security group the user is a member of.
Introduction to certificate services
Certificate Services are used to issue signed digital certificates to network hosts. The certificates are used
to establish SSL connections with the host and verify the authenticity of the host.
Installing Certificate Services allows Active Directory to receive a certificate that allows Lights-Out
processors to connect to the directory service. Without a certificate, iLO 2 cannot connect to the directory
server.
Each directory server that you want iLO 2 to connect to must be issued a certificate. If you install an
Enterprise Certificate Service, Active Directory can automatically request and install certificates for all of
the Active Directory controllers on the network.
Installing certificate services
1.
Select
Start>Settings>Control Panel.
2.
Double-click
Add/Remove Programs.
3.
Click
Add/Remove Windows Components
to start the Windows Components wizard.
4.
Select the
Certificate Services
check box. Click
Next.