11.07.2015 Views

HP Integrated Lights-Out 2 User Guide

HP Integrated Lights-Out 2 User Guide

HP Integrated Lights-Out 2 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Two-factor authentication loginWhen you connect to iLO 2 and two-factor authentication is required, the Client Authentication pageprompts you to select the certificate you want to use. The Client Authentication page displays all of thecertificates available to authenticate a client. Select your certificate. The certificate can be a certificatemapped to a local user in iLO 2, or a user specific certificate issued for authenticating to the domain.After you have selected a certificate, if the certificate is protected with a password or if the certificate isstored on a smart card, a second page appears prompting you to enter the PIN or password associatedwith the chosen certificate.The certificate is examined by iLO 2 to ensure it was issued by a trusted CA by checking the signatureagainst the CA certificate configured in iLO 2. iLO 2 determines if the certificate has been revoked and ifit maps to a user in the iLO 2 local user database. If all of these tests pass, then the normal iLO 2 userinterface appears.If your credential authentication fails, the Login Failed page appears. If login fails, you are instructed toclose the browser, open a new browser page, and try connecting again. If directory authentication isenabled, and local user authentication fails, iLO 2 displays a login page with the directory user namefield populated with either the <strong>User</strong> Principal Name from the certificate or the Distinguished Name(derived from the subject of the certificate). iLO 2 requests the password for the account. After providingthe password, you are authenticated.Using two-factor authentication with directory authenticationIn some cases, configuring two-factor authentication with directory authentication is complicated. iLO 2can use <strong>HP</strong> Extended schema or Default Directory schema to integrate with directory services. To ensuresecurity when two-factor authentication is enforced, iLO 2 uses an attribute from the client certificate asthe directory user's login name. Which client certificate attribute iLO 2 uses is determined by theCertificate Owner Field configuration setting on the Two-Factor Authentication Settings page. If CertificateConfiguring iLO 2 42

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!