HP rp3440 HP Integrity and HP 9000 iLO MP Operations Guide, Fifth Edition - Page 47

Setting up Directory Security Groups, Login Process Using Directory Services Without Schema Extensions

Page 47 highlights

Setting up Directory Security Groups The following procedures describes how to set up directory security groups in LDAP Lite using the iLO MP TUI. To use the web GUI, see "Administration > Directory Settings > Group Administration" (page 87). NOTE: You must select the default schema from the LDAP command for the LDAP Lite settings to work. To set up directory security groups, follow these steps. 1. At the command mode prompt (MP:CM>), enter LDAP. The screen displays the current LDAP options. [hqgstlb3] MP:CM> ldap LDAP Current LDAP options: D - Directory settings G - Security Group Administration 2. Enter G- Security Group Administration. The screen displays the current group configuration. Enter menu item or [Q] to Quit:G Current Group Configuration: Group Names Group Distinguished Names Access Rights 1 - Administrator 2 - User 3 - Custom1 4 - Custom2 5 - Custom3 6 - Custom4 C, P, M, U C, P None None None None Only the first 30 characters of the Group Distinguished Names are displayed. Enter number to view or modify, or [Q] to Quit: 3. Enter the number for the group you want to view or modify. The screen displays the current LDAP group settings. 4. Set up a group distinguished name. 5. Select rights for the group. 6. Enter Y to confirm. Login Process Using Directory Services Without Schema Extensions You can control access to the iLO MP using directories without schema extensions. The iLO MP acquires the user name to determine group membership from the directory. The iLO MP then cross-references the group names with its locally stored names to determine user privilege level. The iLO MP must be configured with the appropriate group names and their associated privileges. To configure the iLO MP, use one of the following options: • Web GUI, (Administration > Directory Settings > Group Administration page) • iLO MP TUI (use the LDAP command) Configuring LDAP Lite Default Schema 47

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140

Setting up Directory Security Groups
The following procedures describes how to set up directory security groups in LDAP Lite using
the iLO MP TUI. To use the web GUI, see
“Administration > Directory Settings > Group
Administration” (page 87)
.
NOTE:
You must select the default schema from the
LDAP
command for the LDAP Lite settings
to work.
To set up directory security groups, follow these steps.
1.
At the command mode prompt (
MP:CM>
), enter
LDAP
. The screen displays the current LDAP
options.
[hqgstlb3] MP:CM> ldap
LDAP
Current LDAP options:
D - Directory settings
G - Security Group Administration
2.
Enter
G
- Security Group Administration. The screen displays the current group configuration.
Enter menu item or [Q] to Quit:G
Current Group Configuration:
Group Names
Group Distinguished Names
Access Rights
--------------------------------------------------------------------------
1 - Administrator
C, P, M, U
2 - User
C, P
3 - Custom1
None
4 - Custom2
None
5 - Custom3
None
6 - Custom4
None
Only the first 30 characters of the Group Distinguished Names are displayed.
Enter number to view or modify, or [Q] to Quit:
3.
Enter the number for the group you want to view or modify. The screen displays the current
LDAP group settings.
4.
Set up a group distinguished name.
5.
Select rights for the group.
6.
Enter
Y
to confirm.
Login Process Using Directory Services Without Schema Extensions
You can control access to the iLO MP using directories without schema extensions. The iLO MP
acquires the user name to determine group membership from the directory. The iLO MP then
cross-references the group names with its locally stored names to determine user privilege level.
The iLO MP must be configured with the appropriate group names and their associated privileges.
To configure the iLO MP, use one of the following options:
Web GUI, (Administration > Directory Settings > Group Administration page)
iLO MP TUI (use the
LDAP
command)
Configuring LDAP Lite Default Schema
47