11.07.2015 Views

HP Integrated Lights-Out 2 User Guide

HP Integrated Lights-Out 2 User Guide

HP Integrated Lights-Out 2 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

• Flexibility—You can create a single role for a single user on a single iLO 2, or you can create asingle role for multiple users on multiple iLOs, or you can use a combinations of roles as is suitablefor your enterprise.• Compatibility—<strong>Lights</strong>-<strong>Out</strong> directory integration applies to iLO 2, RILOE and RILOE II products. Theintegration supports the popular Active Directory and eDirectory.• Standards—<strong>Lights</strong>-<strong>Out</strong> directory support builds on top of the LDAP 2.0 standard for secure directoryaccess.Advantages and disadvantages of schema-free and <strong>HP</strong>Extended schemaBefore configuring iLO 2 for directories, you must decide whether to use the directory's schema-free(default schema) or the <strong>HP</strong> Extended schema option.The advantages of using the schema-free option are:• There is no need to extend the directory's schema.• When ActiveX controls are enabled on the browser, login using NetBIOS and e-mail formats issupported.The advantages of using the <strong>HP</strong> Extended schema option are:• There is much more flexibility in controlling access. For example, access can be limited to a time ofday or from a certain range of IP addresses.• Groups are maintained in the directory, not on each iLO 2.• RILOE and RILOE II only work with <strong>HP</strong> Extended schema. (Schema-free will be added to RILOE II atlater date.)• iLO 2, RILOE, and RILOE II will only work with eDirectory with <strong>HP</strong> Extended schema.Setup for Schema-free directory integrationBefore setting up the Schema-free option, your system must meet all the prerequisites outlined in the"Active Directory Preparation (on page 105)" section.You can set up iLO for directories in three ways:• Manually using a browser ("Schema-free browser-based setup" on page 107).• Using a script ("Schema-free scripted setup" on page 107).• Using <strong>HP</strong>LOMIG ("Schema-free <strong>HP</strong>LOMIG-based setup" on page 107).Active Directory preparationThe schema-free option is supported on the following operating systems:• Microsoft® Active Directory• Microsoft® Windows® Server 2003 Active DirectorySSL must be enabled at the directory. To enable SSL, install a certificate for the domain in ActiveDirectory. iLO 2 only communicates with the directory over a secure SSL connection. For moreinformation, refer to the Microsoft® Knowledge Base, article number 247078: Enabling SSLCommunication over LDAP for Windows® 2000 Domain Controllers on the Microsoft® website(http://support.microsoft.com/).To validate the setup, you should have the directory distinguished name for at least one user and thedistinguished name of a security group the user is a member of.Directory services 105

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!