HP Xw460c HP Integrated Lights-Out 2 User Guide for Firmware 1.75 and 1.77 - Page 56

HP SIM single sign-on (SSO), Setting up iLO 2 for HP SIM SSO

Page 56 highlights

IMPORTANT: Incorrectly editing the registry can severely damage your system. HP recommends creating a back up of any valued data on the computer before making changes to the registry. For information on how to restore your registry, see the Microsoft Knowledge base article (http://support.microsoft.com/kb/307545). To connect to iLO 2 through an SSH connection, see your SSH utility documentation to set the cipher strength. When connecting through the XML channel, the CPQLOCFG utility uses a secure 3DES cipher by default. CPQLOCFG 2.26 or later displays the following current-connection cipher strength on the XML output. For example: Connecting to Server.. Negotiated cipher: 168-bit Triple DES with RSA and a SHA1 MAC AES encryption is not supported by Internet Explorer on a Windows® 2000 Professional client. To use AES encryption with this operating system, use another browser (such as Mozilla). HP SIM single sign-on (SSO) HP SIM SSO enables you to browse directly from HP SIM to your LOM processor, bypassing an intermediate login step. To use SSO, a current version of HP SIM is required, and you must configure your LOM processor to accept the links from HP SIM. HP SIM requires the latest updates and patches to function correctly. For more information about HP Systems Insight Manager and available updates, see the HP website (http://www.hp.com/go/hpsim). HP SIM SSO is a licensed feature available with the purchase of optional licenses. For more information, see "Licensing (on page 26)". The HP SIM SSO page enables you to view and configure SSO settings through the iLO 2 interface. For more information, see the section, "Setting up HP SIM SSO (on page 58)." You can also access HP SIM SSO configuration settings using scripts, text files, and through a commandline using text-based clients such as SSH over the network or from the operating system on the host computer. Scripting SSO enables you to use the same SSO settings on all your LOM processors. For more information, example scripts, and CLP extensions to read, modify, and write HP SIM SSO configuration settings, see the HP Integrated Lights-Out Management Processor Scripting and Command Line Resource Guide. Setting up iLO 2 for HP SIM SSO Before you start SSO setup, you must have the network address of HP SIM and ensure that a license key is installed. To setup SSO: 1. Enable Single Sign-On Trust Mode by selecting either Trust by Certificate (recommended), Trust by Name, or Trust All. 2. Add the HP SIM certificate of the server to iLO 2. a. Click Add an HP SIM Server. b. Enter the HP SIM server network address. c. Click Import Certificate. The certificate repository is sized to allow five typical iLO 2 certificates. However, certificate sizes can vary if typical certificates are not issued. There is 6KB of combined storage allocated for Configuring iLO 2 56

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235

Configuring iLO 2 56
IMPORTANT:
Incorrectly editing the registry can severely damage your system. HP
recommends creating a back up of any valued data on the computer before making changes
to the registry. For information on how to restore your registry, see the Microsoft
Knowledge
base article (
).
To connect to iLO 2 through an SSH connection, see your SSH utility documentation to set the cipher
strength.
When connecting through the XML channel, the CPQLOCFG utility uses a secure 3DES cipher by default.
CPQLOCFG 2.26 or later displays the following current-connection cipher strength on the XML output. For
example:
Connecting to Server..
Negotiated cipher: 168-bit Triple DES with RSA and a SHA1 MAC
AES encryption is not supported by Internet Explorer on a Windows® 2000 Professional client. To use
AES encryption with this operating system, use another browser (such as Mozilla).
HP SIM single sign-on (SSO)
HP SIM SSO enables you to browse directly from HP SIM to your LOM processor, bypassing an
intermediate login step. To use SSO, a current version of HP SIM is required, and you must configure your
LOM processor to accept the links from HP SIM. HP SIM requires the latest updates and patches to
function correctly. For more information about HP Systems Insight Manager and available updates, see
the HP website (
).
HP SIM SSO is a licensed feature available with the purchase of optional licenses. For more information,
see "Licensing (on page
26
)".
The HP SIM SSO page enables you to view and configure SSO settings through the iLO 2 interface. For
more information, see the section, "Setting up HP SIM SSO (on page
58
)."
You can also access HP SIM SSO configuration settings using scripts, text files, and through a command-
line using text-based clients such as SSH over the network or from the operating system on the host
computer. Scripting SSO enables you to use the same SSO settings on all your LOM processors. For more
information, example scripts, and CLP extensions to read, modify, and write HP SIM SSO configuration
settings, see the
HP Integrated Lights-Out Management Processor Scripting and Command Line Resource
Guide.
Setting up iLO 2 for HP SIM SSO
Before you start SSO setup, you must have the network address of HP SIM and ensure that a license key is
installed. To setup SSO:
1.
Enable Single Sign-On Trust Mode by selecting either
Trust by Certificate
(recommended),
Trust by
Name
, or
Trust All
.
2.
Add the HP SIM certificate of the server to iLO 2.
a.
Click
Add an HP SIM Server.
b.
Enter the HP SIM server network address.
c.
Click
Import Certificate.
The certificate repository is sized to allow five typical iLO 2 certificates. However, certificate sizes
can vary if typical certificates are not issued. There is 6KB of combined storage allocated for