HP Xw460c HP Integrated Lights-Out 2 User Guide for Firmware 1.75 and 1.77 - Page 139

Verifying certificate services, Configuring Automatic Certificate Request

Page 139 highlights

5. Click OK at the warning that the server cannot be renamed. The Enterprise root CA option is selected because there is no CA registered in the active directory. 6. Enter the information appropriate for your site and organization. Accept the default time period of two years for the Valid for field. Click Next. 7. Accept the default locations of the certificate database and the database log. Click Next. 8. Browse to the c:\I386 folder when prompted for the Windows® 2000 Advanced Server CD. 9. Click Finish to close the wizard. Verifying certificate services Because management processors communicate with Active Directory using SSL, you must create a certificate or install Certificate Services. You must install an enterprise CA because you will be issuing certificates to objects within your organizational domain. To verify that certificate services is installed, select Start>Programs>Administrative Tools>Certification Authority. If Certificate Services is not installed an error message appears. Configuring Automatic Certificate Request To specify that a certificate be issued to the server: 1. Select Start>Run, and enter mmc. 2. Click Add. 3. Select Group Policy, and click Add to add the snap-in to the MMC. 4. Click Browse, and select the Default Domain Policy object. Click OK. 5. Select Finish>Close>OK. 6. Expand Computer Configuration>Windows Settings>Security Settings>Public Key Policies. 7. Right-click Automatic Certificate Requests Settings, and select New>Automatic Certificate Request. 8. Click Next when the Automatic Certificate Request Setup wizard starts. 9. Select the Domain Controller template, and click Next. 10. Select the certificate authority listed. (It is the same CA defined during the Certificate Services installation.) Click Next. 11. Click Finish to close the wizard. Schema-free browser-based setup Schema-free can be setup using the iLO 2 browser-based interface. 1. Log on to iLO 2 using an account that has the Configure iLO 2 Settings privilege. Click Administration. IMPORTANT: Only users with the Configure iLO 2 Settings privilege can change these settings. Users that do not have the Configure iLO 2 Settings privilege can only view the assigned settings. 2. Click Directory Settings. 3. Select Use Directory Default Schema in the Authentication Settings section. For more information, refer to the "Schema-free setup options (on page 140)" section. Directory services 139

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235

Directory services 139
5.
Click
OK
at the warning that the server cannot be renamed. The Enterprise root CA option is
selected because there is no CA registered in the active directory.
6.
Enter the information appropriate for your site and organization. Accept the default time period of
two years for the
Valid for
field. Click
Next.
7.
Accept the default locations of the certificate database and the database log. Click
Next.
8.
Browse to the c:\I386 folder when prompted for the Windows® 2000 Advanced Server CD.
9.
Click
Finish
to close the wizard.
Verifying certificate services
Because management processors communicate with Active Directory using SSL, you must create a
certificate or install Certificate Services. You must install an enterprise CA because you will be issuing
certificates to objects within your organizational domain.
To verify that certificate services is installed, select
Start>Programs>Administrative Tools>Certification
Authority.
If Certificate Services is not installed an error message appears.
Configuring Automatic Certificate Request
To specify that a certificate be issued to the server:
1.
Select
Start>Run,
and enter
mmc
.
2.
Click
Add.
3.
Select
Group Policy,
and click
Add
to add the snap-in to the MMC.
4.
Click
Browse,
and select the Default Domain Policy object. Click
OK.
5.
Select
Finish>Close>OK.
6.
Expand
Computer Configuration>Windows Settings>Security Settings>Public Key Policies.
7.
Right-click
Automatic Certificate Requests Settings,
and select
New>Automatic Certificate Request.
8.
Click
Next
when the Automatic Certificate Request Setup wizard starts.
9.
Select the
Domain Controller
template, and click
Next.
10.
Select the certificate authority listed. (It is the same CA defined during the Certificate Services
installation.) Click
Next.
11.
Click
Finish
to close the wizard.
Schema-free browser-based setup
Schema-free can be setup using the iLO 2 browser-based interface.
1.
Log on to iLO 2 using an account that has the Configure iLO 2 Settings privilege. Click
Administration.
IMPORTANT:
Only users with the Configure iLO 2 Settings privilege can change these settings.
Users that do not have the Configure iLO 2 Settings privilege can only view the assigned
settings.
2.
Click
Directory Settings.
3.
Select
Use Directory Default Schema
in the Authentication Settings section. For more information,
refer to the "Schema-free setup options (on page
140
)" section.