HP rp3440 HP Integrity and HP 9000 iLO MP Operations Guide, Fifth Edition - Page 91

Installing and Configuring Directory Services, Directory Services

Page 91 highlights

7 Installing and Configuring Directory Services You can install and configure iLO MP directory services to leverage the benefits of a single point of administration for iLO MP user accounts. This chapter provides information about the features and functions, installation, and configuration of iLO MP directory services. This chapter addresses the following topics: • "Directory Services" (page 91) • "Directory Services for Active Directory" (page 96) • "Directory Services for eDirectory" (page 107) • "User Login Using Directory Services" (page 117) • "Certificate Services" (page 118) • "Directory-Enabled Management" (page 118) • "Directory Services Schema (LDAP)" (page 124) Directory Services The following are benefits of directory integration: Scalability You can leverage the directory to support thousands of users on thousands of iLOs. Security Robust user password policies are inherited from the directory. User password complexity, rotation frequency, and expiration are policy examples. Role-based administration Single point of administration You can create roles (for instance, clerical, remote control of the host, complete control), and associate users or user groups with those roles. When you change a single role, the change applies to all users and iLO MP devices associated with that role. You can use native administrative tools, like Microsoft Management Console (MMC) and ConsoleOne, to administer iLO MP users. Immediacy A single change in the directory rolls out immediately to associated iLO MPs eliminating the need to script this process. Reuse of username and password You can use existing user accounts and passwords in the directory without having to record or remember a new set of credentials for the iLO MP. Flexibility Compatibility You can create a single role for a single user on a single iLO MP; you can create a single role for multiple users on multiple iLOs; or you can use a combination of roles to best fit your enterprise. iLO MP directory integration applies to iLO MP products and supports the popular directories Active Directory and eDirectory. Standards The iLO MP directory support builds on the LDAP 2.0 standard for secure directory access. Directory Services 91

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140

7 Installing and Configuring Directory Services
You can install and configure iLO MP directory services to leverage the benefits of a single point
of administration for iLO MP user accounts.
This chapter provides information about the features and functions, installation, and configuration
of iLO MP directory services.
This chapter addresses the following topics:
“Directory Services” (page 91)
“Directory Services for Active Directory” (page 96)
“Directory Services for eDirectory” (page 107)
“User Login Using Directory Services” (page 117)
“Certificate Services” (page 118)
“Directory-Enabled Management” (page 118)
“Directory Services Schema (LDAP)” (page 124)
Directory Services
The following are benefits of directory integration:
Scalability
You can leverage the directory to support thousands of
users on thousands of iLOs.
Security
Robust user password policies are inherited from the
directory. User password complexity, rotation frequency,
and expiration are policy examples.
Role-based administration
You can create roles (for instance, clerical, remote control
of the host, complete control), and associate users or user
groups with those roles. When you change a single role,
the change applies to all users and iLO MP devices
associated with that role.
Single point of administration
You can use native administrative tools, like Microsoft
Management Console (MMC) and ConsoleOne, to
administer iLO MP users.
Immediacy
A single change in the directory rolls out immediately to
associated iLO MPs eliminating the need to script this
process.
Reuse of username and password
You can use existing user accounts and passwords in the
directory without having to record or remember a new set
of credentials for the iLO MP.
Flexibility
You can create a single role for a single user on a single
iLO MP; you can create a single role for multiple users on
multiple iLOs; or you can use a combination of roles to
best fit your enterprise.
Compatibility
iLO MP directory integration applies to iLO MP products
and supports the popular directories Active Directory and
eDirectory.
Standards
The iLO MP directory support builds on the LDAP 2.0
standard for secure directory access.
Directory Services
91