11.07.2015 Views

HP Integrated Lights-Out 2 User Guide

HP Integrated Lights-Out 2 User Guide

HP Integrated Lights-Out 2 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Directory servicesIn this sectionOverview of directory integration........................................................................................................... 104Benefits of directory integration.............................................................................................................. 104Advantages and disadvantages of schema-free and <strong>HP</strong> Extended schema .................................................. 105Setup for Schema-free directory integration ............................................................................................. 105Setting up <strong>HP</strong> schema directory integration ............................................................................................. 108Overview of directory integrationiLO 2 can be configured to use a directory to authenticate and authorize its users. Before configuring iLO2 for directories, you must decide whether or not you want to use the <strong>HP</strong> Extended schema option.The advantages of using the <strong>HP</strong> Extended schema option are:• There is much more flexibility in controlling access. For example, access can be limited to a time ofday or from a certain range of IP addresses.• Groups are maintained in the directory, not on each iLO 2.• RILOE and RILOE II only work with <strong>HP</strong> Extended schema. (Schema-free will be added to RILOE II atlater date.)iLO 2, RILOE, and RILOE II will only work with eDirectory with <strong>HP</strong> Extended schema.See the comprehensive list of benefits in the "Benefits of directory integration (on page 104)" section. The"Directory-enabled remote management (on page 129)" section details how roles, groups, and security isenabled and enforced using directories. There are also white papers available for more information ondirectory integration on the <strong>HP</strong> website (http://www.hp.com/servers/lights-out).Benefits of directory integration• Scalability—The directory can be leveraged to support thousands of users on thousands of iLO 2s.• Security—Robust user password policies are inherited from the directory. <strong>User</strong> password complexity,rotation frequency, and expiration are policy examples.• Anonymity (lack thereof)—In some environments, users share <strong>Lights</strong>-<strong>Out</strong> accounts, which results in thelack of knowing who performed an operation, instead of knowing what account (or role) was used.• Role-based administration—You can create roles (for instance, clerical, remote control of the host,complete control) and associate users or user groups with those roles. A change at a single roleapplies to all users and <strong>Lights</strong>-<strong>Out</strong> devices associated with that role.• Single point of administration—You can use native administrative tools like MMC and ConsoleOneto administrate <strong>Lights</strong>-<strong>Out</strong> users.• Immediacy—A single change in the directory rolls-out immediately to associated <strong>Lights</strong>-<strong>Out</strong>processors. This eliminates the need to script this process.• Elimination of another username and password—You can use existing user accounts and passwordsin the directory without having to record or remember a new set of credentials for <strong>Lights</strong>-<strong>Out</strong>.Directory services 104

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!