HP Xw460c HP Integrated Lights-Out 2 User Guide for Firmware 1.75 and 1.77 - Page 142

Setting up HP schema directory integration, Features supported by HP schema directory integration

Page 142 highlights

Setting up HP schema directory integration When using the HP schema directory integration, iLO 2 supports both Active Directory and eDirectory. However, these directory services require the schema being extended. Features supported by HP schema directory integration iLO 2 Directory Services functionality enables you to: • Authenticate users from a shared, consolidated, scalable user database. • Control user privileges (authorization) using the directory service. • Use roles in the directory service for group-level administration of iLO 2 management processors and iLO 2 users. Extending the schema must be completed by a Schema Administrator. The local user database is retained. You can decide not to use directories, to use a combination of directories and local accounts, or to use directories exclusively for authentication. NOTE: When connected through the Diagnostics Port, the directory server is not available. You can log in using a local account only. Setting up directory services To successfully enable directory-enabled management on any Lights-Out management processor: 1. Plan Review the following sections: o "Directory services (on page 134)" o "Directory services schema (on page 213)" o "Directory-enabled remote management (on page 166)" 2. Install a. Download the HP Lights-Out Directory Package containing the schema installer, the management snap-in installer, and the migrations utilities from the HP website (http://www.hp.com/servers/lights-out). b. Run the schema installer (on page 144) once to extend the schema. c. Run the management snap-in installer (on page 147), and install the appropriate snap-in for your directory service on one or more management workstations. 3. Update a. Flash the ROM on the Lights-Out management processor with the directory-enabled firmware. b. Set directory server settings and the distinguished name of the management processor objects on the Directory Settings (on page 51) page in the iLO 2 GUI. 4. Manage a. Create a management device object and a role object ("Directory services objects" on page 152) using the snap-in. b. Assign rights to the role object, as necessary, and associate the role with the management device object. Directory services 142

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235

Directory services 142
Setting up HP schema directory integration
When using the HP schema directory integration, iLO 2 supports both Active Directory and eDirectory.
However, these directory services require the schema being extended.
Features supported by HP schema directory integration
iLO 2 Directory Services functionality enables you to:
Authenticate users from a shared, consolidated, scalable user database.
Control user privileges (authorization) using the directory service.
Use roles in the directory service for group-level administration of iLO 2 management processors and
iLO 2 users.
Extending the schema must be completed by a Schema Administrator. The local user database is
retained. You can decide not to use directories, to use a combination of directories and local accounts, or
to use directories exclusively for authentication.
NOTE:
When connected through the Diagnostics Port, the directory server is not available.
You can log in using a local account only.
Setting up directory services
To successfully enable directory-enabled management on any Lights-Out management processor:
1.
Plan
Review the following sections:
o
"Directory services (on page
134
)"
o
"Directory services schema (on page
213
)"
o
"Directory-enabled remote management (on page
166
)"
2.
Install
a.
Download the HP Lights-Out Directory Package containing the schema installer, the management
snap-in installer, and the migrations utilities from the HP website
(
).
b.
Run the schema installer (on page
144
) once to extend the schema.
c.
Run the management snap-in installer (on page
147
), and install the appropriate snap-in for your
directory service on one or more management workstations.
3.
Update
a.
Flash the ROM on the Lights-Out management processor with the directory-enabled firmware.
b.
Set directory server settings and the distinguished name of the management processor objects on
the Directory Settings (on page
51
) page in the iLO 2 GUI.
4.
Manage
a.
Create a management device object and a role object ("
Directory services objects
" on page
152
) using the snap-in.
b.
Assign rights to the role object, as necessary, and associate the role with the management device
object.