HP Xw460c HP Integrated Lights-Out 2 User Guide for Firmware 1.75 and 1.77 - Page 197

Two-factor authentication error, Troubleshooting alert and trap problems

Page 197 highlights

2. For example, in Internet Explorer, select Tools>Internet Options>Connections>LAN Settings>Advanced, and then enter the iLO 2 IP address or DNS name in the Exceptions field. Two-factor authentication error When attempting to authenticate to iLO 2 using two-factor authentication, you might receive the message The page cannot be displayed. This message may appear for the following reasons: • No user certificates are registered on the client system. To correct this issue, register the necessary user certificate on the client system, which might require software provided by the smart card vendor. • The user certificate is stored on a smart card or USB token that is not connected to the client system. To correct this issue, connect the appropriate smart card or USB token to the client system. • The user certificate is not issued by the trusted CA. The trusted CA's certificate is configured in iLO 2 on the Two-Factor Authentication settings page. The certificate configured as the trusted CA, must be the public certificate of the CA that issues certificates in your organization. To correct this issue, configure the appropriate certificate as the trusted CA on the iLO 2 Two-Factor Authentication settings page, or use a user certificate that is issued by the trusted CA which is already configured. • The user certificate is expired or not yet valid. Regardless of whether the expired certificate maps to a local user, or whether it corresponds to a directory user account, iLO 2 will not allow authentication with a certificate that has expired or that is not yet valid. Check the validity dates of the certificate to verify that this is the cause of the The page cannot be displayed message. To correct this problem, issue a valid certificate to the user. Map the certificate to the local iLO 2 user account if you are authenticating local iLO 2 users and verify the iLO 2 time clock is set correctly. • The user certificate was not digitally signed with the same certificate that is specified as the trusted CA. Even though the name on the trusted CA certificate might match the issuer of the user certificate, the user certificate might have been digitally signed by a different certificate. View the certification path of the user certificate, and ensure that the public key of the issuing certificate is the same as the public key of the trusted CA certificate. To correct this issue, configure the appropriate certificate as the trusted CA on the iLO 2 Two-Factor Authentication settings page, or use a user certificate that was issued by the trusted CA. Troubleshooting alert and trap problems Alert Test Trap Server Power Outage Server Reset Failed Login Attempt General Error Logs Security Override Switch Changed: On/Off Rack Server Power On Failed Explanation This trap is generated by a user through the Web configuration page. Server has lost power. Server has been reset. Remote user login attempt failed. This is an error condition that is not predefined by the hard-coded MIB. Circular log has been overrun. The state of the Security Override Switch has changed (On/Off). The server was unable to power on because the BL p-Class rack indicated that insufficient power was available to power on the server. Troubleshooting iLO 2 197

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235

Troubleshooting iLO 2 197
2. For example, in Internet Explorer, select
Tools>Internet Options>Connections>LAN Settings>Advanced,
and then enter the iLO 2 IP address or DNS name in the Exceptions field.
Two-factor authentication error
When attempting to authenticate to iLO 2 using two-factor authentication, you might receive the message
The page cannot be displayed
. This message may appear for the following reasons:
No user certificates are registered on the client system. To correct this issue, register the necessary
user certificate on the client system, which might require software provided by the smart card
vendor.
The user certificate is stored on a smart card or USB token that is not connected to the client system.
To correct this issue, connect the appropriate smart card or USB token to the client system.
The user certificate is not issued by the trusted CA. The trusted CA's certificate is configured in iLO 2
on the Two-Factor Authentication settings page. The certificate configured as the trusted CA, must be
the public certificate of the CA that issues certificates in your organization. To correct this issue,
configure the appropriate certificate as the trusted CA on the iLO 2 Two-Factor Authentication
settings page, or use a user certificate that is issued by the trusted CA which is already configured.
The user certificate is expired or not yet valid. Regardless of whether the expired certificate maps to
a local user, or whether it corresponds to a directory user account, iLO 2 will not allow
authentication with a certificate that has expired or that is not yet valid. Check the validity dates of
the certificate to verify that this is the cause of the
The page cannot be displayed
message.
To correct this problem, issue a valid certificate to the user. Map the certificate to the local iLO 2
user account if you are authenticating local iLO 2 users and verify the iLO 2 time clock is set
correctly.
The user certificate was not digitally signed with the same certificate that is specified as the trusted
CA. Even though the name on the trusted CA certificate might match the issuer of the user certificate,
the user certificate might have been digitally signed by a different certificate.
View the certification
path of the user certificate, and ensure that the public key of the issuing certificate is the same as the
public key of the trusted CA certificate. To correct this issue, configure the appropriate certificate as
the trusted CA on the iLO 2 Two-Factor Authentication settings page, or use a user certificate that
was issued by the trusted CA.
Troubleshooting alert and trap problems
Alert
Explanation
Test Trap
This trap is generated by a user through the Web configuration page.
Server Power Outage
Server has lost power.
Server Reset
Server has been reset.
Failed Login Attempt
Remote user login attempt failed.
General Error
This is an error condition that is not predefined by the hard-coded MIB.
Logs
Circular log has been overrun.
Security Override Switch
Changed: On/Off
The state of the Security Override Switch has changed (On/Off).
Rack Server Power On
Failed
The server was unable to power on because the BL p-Class rack
indicated that insufficient power was available to power on the server.