HP Xw460c HP Integrated Lights-Out 2 User Guide for Firmware 1.75 and 1.77 - Page 44

User accounts and access, Privileges, Login security

Page 44 highlights

iLO 2 provides support for the TPM mezzanine module in ProLiant 100 and ProLiant 300/500 series servers. On a supported system, iLO 2 decodes the TPM record and passes the configuration status to iLO 2, CLP, and XML interface. The System Status page displays the TPM configuration status. If the host system or System ROM does not support TPM, TPM Status is not displayed in Status Summary page. The Status Summary displays the following TPM status information: • Not Present-A TPM module is not installed. • Present-when: o A TPM module is installed but it is disabled. o A TPM module is installed and enabled. o A TPM module is installed, enabled, and Expansion ROM measuring is enabled. If Expansion ROM measuring is enabled, the Update iLO 2 Firmware page displays a legal warning message when you click Send firmware image. User accounts and access iLO 2 supports the configuration of up to 12 local user accounts. Each of these accounts can be managed through the use of the following features: • Privileges (on page 44) • Login security (on page 44) iLO 2 can be configured to use a directory to authenticate and authorize its users. This configuration enables a virtually unlimited number of users, and easily scales to the number of Lights-Out devices in an enterprise. Additionally, the directory provides a central point of administration for Lights-Out devices and users, and the directory can enforce a stronger password policy. iLO 2 enables you to use local users, directory users, or both. Two configuration options are available: using a directory that has been extended with HP Schema ("Setting up HP schema directory integration" on page 142) or using the directory's default schema (schema-free ("Setup for Schema-free directory integration" on page 138)). Privileges iLO 2 allows the administrator to control user account access to iLO 2 functions through the use of privileges. When a user attempts to use a function, the iLO 2 system verifies that the user has the privilege before the user is allowed to perform the function. Each feature available through iLO 2 can be controlled through privileges, including Administer User Accounts, Remote Console Access, Virtual Power and Reset, Virtual Media, and Configure iLO 2 Settings. Privileges for each user can be configured on the User Administration page of the Administration tab. Login security iLO 2 provides several login security features. After an initial failed login attempt, iLO 2 imposes a delay of five seconds. After a second failed attempt, iLO 2 imposes a delay of 10 seconds. After the third failed attempt, and any subsequent attempts, iLO 2 imposes a delay of 60 seconds. All subsequent failed login attempts cycles through these values. An information page is displayed during each delay. This will continue until a valid login is completed. This feature assists in defending against possible dictionary attacks against the browser login port. Configuring iLO 2 44

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235

Configuring iLO 2 44
iLO 2 provides support for the TPM mezzanine module in ProLiant 100 and ProLiant 300/500 series
servers.
On a supported system, iLO 2 decodes the TPM record and passes the configuration status to iLO 2, CLP,
and XML interface. The System Status page displays the TPM configuration status. If the host system or
System ROM does not support TPM, TPM Status is not displayed in Status Summary page. The Status
Summary displays the following TPM status information:
Not Present—A TPM module is not installed.
Present—when:
o
A TPM module is installed but it is disabled.
o
A TPM module is installed and enabled.
o
A TPM module is installed, enabled, and Expansion ROM
measuring is enabled. If Expansion
ROM measuring is enabled, the Update iLO 2 Firmware page displays a legal warning message
when you click
Send firmware image
.
User accounts and access
iLO 2 supports the configuration of up to 12 local user accounts. Each of these accounts can be managed
through the use of the following features:
Privileges (on page
44
)
Login security (on page
44
)
iLO 2 can be configured to use a directory to authenticate and authorize its users. This configuration
enables a virtually unlimited number of users, and easily scales to the number of Lights-Out devices in an
enterprise. Additionally, the directory provides a central point of administration for Lights-Out devices and
users, and the directory can enforce a stronger password policy. iLO 2 enables you to use local users,
directory users, or both.
Two configuration options are available: using a directory that has been extended with HP Schema
("
Setting up HP schema directory integration
" on page
142
) or using the directory’s default schema
(schema-free ("
Setup for Schema-free directory integration
" on page
138
)).
Privileges
iLO 2 allows the administrator to control user account access to iLO 2 functions through the use of
privileges. When a user attempts to use a function, the iLO 2 system verifies that the user has the privilege
before the user is allowed to perform the function.
Each feature available through iLO 2 can be controlled through privileges, including Administer User
Accounts, Remote Console Access, Virtual Power and Reset, Virtual Media, and Configure iLO 2 Settings.
Privileges for each user can be configured on the User Administration page of the Administration tab.
Login security
iLO 2 provides several login security features. After an initial failed login attempt, iLO 2 imposes a delay
of five seconds. After a second failed attempt, iLO 2 imposes a delay of 10 seconds. After the third failed
attempt, and any subsequent attempts, iLO 2 imposes a delay of 60 seconds. All subsequent failed login
attempts cycles through these values. An information page is displayed during each delay. This will
continue until a valid login is completed. This feature assists in defending against possible dictionary
attacks against the browser login port.