HP rp4440 HP Integrity and HP 9000 iLO MP Operations Guide, Fifth Edition - Page 97

Preparing Directory Services for Active Directory, Update Allowed

Page 97 highlights

IMPORTANT: To install directory services for the iLO MP, an Active Directory administrator must extend the Active Directory schema. • Extending the Schema in the Microsoft Windows 2000 Server Resource Kit, available at: http://www.microsoft.com/mspress/books/1394.aspx. • Installing Active Directory in the Microsoft Windows 2000 Server Resource Kit, available at: http://www.microsoft.com/windowsserver2003/technologies/directory/activedirectory/default.mspx/. • Microsoft Knowledge Base Articles: - 216999 "How to Install the Remote Server Administration Tools in Windows" - 314978 "How to Use Adminpak.msi to Install a Specific Server Administration Tool in Windows 2000" - 247078 "How to Enable SSL Communication over LDAP for Windows 2000 Domain Controllers" - 321051 "How to Enable LDAP over SSL with a Third-Party Certification Authority" - 299687 MS01-036 "Function Exposed by Using LDAP over SSL Could Enable Passwords to Be Changed" The iLO MP requires a secure connection to communicate with the directory service. This secure connection requires the installation of the Microsoft Certification Authority Certificate (CA). For more information, see the following Microsoft technical references: • Appendix D: Configuring Digital Certificates on Domain Controllers for Secure LDAP and SMTP Replication at: http://www.microsoft.com/technet/security/prodtech/windows2000/secwin2k/swin2kad.mspx • Microsoft Knowledge Base Article 321051 "How to Enable LDAP over SSL with a Third-Party Certification Authority" Preparing Directory Services for Active Directory To set up directory services for use with iLOs, follow these steps: 1. Install Active Directory. For more information, see the resource kit, Installing Active Directory in the Microsoft Windows 2000 Server. 2. Install the Microsoft Admin Pack (the ADMINPAK.MSI file, which is located in the i386 subdirectory of the Windows 2000 Server or Advanced Server CD). For more information, see the Microsoft Knowledge Base Article 216999 "How to Install the Remote Server Administration Tools in Windows". 3. In Windows 2000, the safety interlock that prevents accidental writes to the schema must be temporarily disabled. The schema extender utility can do this if the remote registry service is running and you have appropriate rights. You can also do this by setting HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters\Schema Update Allowed in the registry to a non-zero value (see the "Order of Processing When Extending the Schema" section of the Installation of Schema Extensions in the Windows 2000 Server Resource Kit) or by doing the following : CAUTION: Incorrectly editing the registry can severely damage your system. HP recommends creating a backup of any valued data on the computer before making changes to the registry. NOTE: This step is not necessary if you are using Windows Server 2003. a. Start the MMC. b. In MMC, install the Active Directory schema snap-in. Directory Services for Active Directory 97

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140

IMPORTANT:
To install directory services for the iLO MP, an Active Directory administrator
must extend the Active Directory schema.
Extending the Schema in the Microsoft Windows 2000 Server Resource Kit, available at:
.
Installing Active Directory in the Microsoft Windows 2000 Server Resource Kit, available
at:
/.
Microsoft Knowledge Base Articles:
216999 “How to Install the Remote Server Administration Tools in Windows”
314978 “How to Use Adminpak.msi to Install a Specific Server Administration Tool in
Windows 2000”
247078 “How to Enable SSL Communication over LDAP for Windows 2000 Domain
Controllers”
321051 “How to Enable LDAP over SSL with a Third-Party Certification Authority”
299687 MS01-036 “Function Exposed by Using LDAP over SSL Could Enable Passwords
to Be Changed”
The iLO MP requires a secure connection to communicate with the directory service. This secure
connection requires the installation of the Microsoft Certification Authority Certificate (CA). For
more information, see the following Microsoft technical references:
Appendix D: Configuring Digital Certificates on Domain Controllers for Secure LDAP and
SMTP Replication at:
Microsoft Knowledge Base Article 321051 “How to Enable LDAP over SSL with a Third-Party
Certification Authority”
Preparing Directory Services for Active Directory
To set up directory services for use with iLOs, follow these steps:
1.
Install Active Directory. For more information, see the resource kit, Installing Active Directory
in the Microsoft Windows 2000 Server.
2.
Install the Microsoft Admin Pack (the
ADMINPAK.MSI
file, which is located in the i386
subdirectory of the Windows 2000 Server or Advanced Server CD). For more information,
see the Microsoft Knowledge Base Article 216999 “How to Install the Remote Server
Administration Tools in Windows”.
3.
In Windows 2000, the safety interlock that prevents accidental writes to the schema must
be temporarily disabled. The schema extender utility can do this if the remote registry service
is running and you have appropriate rights. You can also do this by setting
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters\Schema
Update Allowed
in the registry to a non-zero value (see the “Order of Processing When
Extending the Schema” section of the Installation of Schema Extensions in the Windows
2000 Server Resource Kit) or by doing the following :
CAUTION:
Incorrectly editing the registry can severely damage your system. HP
recommends creating a backup of any valued data on the computer before making changes
to the registry.
NOTE:
This step is not necessary if you are using Windows Server 2003.
a.
Start the MMC.
b.
In MMC, install the Active Directory schema snap-in.
Directory Services for Active Directory
97