HP Xw460c HP Integrated Lights-Out 2 User Guide for Firmware 1.75 and 1.77 - Page 149

Snap-in installation and initialization for Active Directory

Page 149 highlights

IMPORTANT: Incorrectly editing the registry can severely damage your system. HP recommends creating a back up of any valued data on the computer before making changes to the registry. a. Start MMC. b. Install the Active Directory Schema snap-in in MMC. c. Right-click Active Directory Schema and select Operations Master. d. Select The Schema may be modified on this Domain Controller. e. Click OK. The Active Directory Schema folder might need to be expanded for the checkbox to be available. 4. Create a certificate or install Certificate Services. This step is necessary to create a certificate or install Certificate Services because iLO 2 communicates with Active Directory using SSL. Active Directory must be installed before installing Certificate Services. 5. To specify that a certificate be issued to the server running active directory: a. Launch Microsoft® Management Console on the server and add the default domain policy snap- in (Group Policy, then browse to Default domain policy object). b. Click Computer Configuration>Windows Settings>Security Settings>Public Key Policies. c. Right-click Automatic Certificate Requests Settings, and select new>automatic certificate request. d. Using the wizard, select the domain controller template, and the certificate authority you want to use. 6. Download the Smart Component, which contains the installers for the schema extender and the snap- ins. The Smart Component can be downloaded from the HP website (http://www.hp.com/servers/lights-out). 7. Run the schema installer application to extend the schema, which extends the directory schema with the proper HP objects. The schema installer associates the Active Directory snap-ins with the new schema. The snap-in installation setup utility is a Windows® MSI setup script and will run anywhere MSI is supported (Windows® XP, Windows® 2000, Windows® 98). However, some parts of the schema extension application require the .NET Framework, which can be downloaded from the Microsoft® website (http://www.microsoft.com). Snap-in installation and initialization for Active Directory 1. Run the snap-in installation application to install the snap-ins. 2. Configure the directory service to have the appropriate objects and relationships for iLO 2 management. a. Use the management snap-ins from HP to create iLO 2, Policy, Admin, and User Role objects. b. Use the management snap-ins from HP to build associations between the iLO 2 object, the policy object, and the role object. c. Point the iLO 2 object to the Admin and User role objects (Admin and User roles will automatically point back to the iLO 2 object). For more information on iLO 2 objects, refer to "Directory services objects (on page 152)." At a minimum, you must create: • One Role object that will contain one or more users and one or more iLO 2 objects. Directory services 149

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235

Directory services 149
IMPORTANT:
Incorrectly editing the registry can severely damage your system. HP
recommends creating a back up of any valued data on the computer before making changes
to the registry.
a.
Start MMC.
b.
Install the Active Directory Schema snap-in in MMC.
c.
Right-click
Active Directory Schema
and select
Operations Master.
d.
Select
The Schema may be modified on this Domain Controller.
e.
Click
OK.
The Active Directory Schema folder might need to be expanded for the checkbox to be available.
4.
Create a certificate or install Certificate Services. This step is necessary to create a certificate or
install Certificate Services because iLO 2 communicates with Active Directory using SSL. Active
Directory must be installed before installing Certificate Services.
5.
To specify that a certificate be issued to the server running active directory:
a.
Launch Microsoft® Management Console on the server and add the default domain policy snap-
in (Group Policy, then browse to Default domain policy object).
b.
Click
Computer Configuration>Windows Settings>Security Settings>Public Key Policies.
c.
Right-click
Automatic Certificate Requests Settings,
and select
new>automatic certificate request.
d.
Using the wizard, select the domain controller template, and the certificate authority you want to
use.
6.
Download the Smart Component, which contains the installers for the schema extender and the snap-
ins. The Smart Component can be downloaded from the HP website
(
).
7.
Run the schema installer application to extend the schema, which extends the directory schema with
the proper HP objects.
The schema installer associates the Active Directory snap-ins with the new schema. The snap-in
installation setup utility is a Windows® MSI setup script and will run anywhere MSI is supported
(Windows® XP, Windows® 2000, Windows® 98). However, some parts of the schema extension
application require the .NET Framework, which can be downloaded from the Microsoft® website
(
).
Snap-in installation and initialization for Active Directory
1.
Run the snap-in installation application to install the snap-ins.
2.
Configure the directory service to have the appropriate objects and relationships for iLO 2
management.
a.
Use the management snap-ins from HP to create iLO 2, Policy, Admin, and User Role objects.
b.
Use the management snap-ins from HP to build associations between the iLO 2 object, the policy
object, and the role object.
c.
Point the iLO 2 object to the Admin and User role objects (Admin and User roles will
automatically point back to the iLO 2 object).
For more information on iLO 2 objects, refer to "Directory services objects (on page
152
)."
At a minimum, you must create:
One Role object that will contain one or more users and one or more iLO 2 objects.