Configuring the iLO hostname and domain name for Kerberos authentication............. 306
Preparing the domain controller for Kerberos support................................................... 307
Generating a keytab file for iLO in a Windows environment.......................................... 307
Verifying that your environment meets the Kerberos authentication time requirement..309
Configuring Kerberos support in iLO..............................................................................310
Configuring supported browsers for single sign-on........................................................310
Directory integration..................................................................................................................312
Choosing a directory configuration to use with iLO...................................................................313
Schema-free directory authentication....................................................................................... 313
Prerequisites for using schema-free directory integration..............................................314
Process overview: Configuring iLO for schema-free directory integration..................... 315
Schema-free nested groups (Active Directory only).......................................................315
Process overview: Configuring the HPE Extended Schema with Active Directory........ 315
Prerequisites for configuring Active Directory with the HPE Extended Schema
configuration...................................................................................................................316
Directory services support..............................................................................................317
Installing the iLO directory support software.................................................................. 317
Running the Schema Extender...................................................................................... 319
Directory services objects.............................................................................................. 320
Managing roles and objects with the Active Directory snap-ins..................................... 320
Sample configuration: Active Directory and HPE Extended Schema............................ 324
Directory-enabled remote management (HPE Extended Schema configuration).....................327
Roles based on organizational structure........................................................................327
How role access restrictions are enforced..................................................................... 328
User access restrictions................................................................................................. 329
Role access restrictions................................................................................................. 330
Tools for configuring multiple iLO systems at a time.................................................................332
User login using directory services........................................................................................... 332
Directories Support for ProLiant Management Processors (HPLOMIG)...................................333
Configuring directory authentication with HPLOMIG................................................................ 334
Discovering management processors............................................................................335
Optional: Upgrading firmware on management processors (HPLOMIG).......................337
Selecting directory configuration options....................................................................... 338
Naming management processors (HPE Extended Schema only)................................. 340
Configuring directories when HPE Extended Schema is selected.................................341
Configuring management processors (Schema-free configuration only)....................... 344
Setting up management processors for directories........................................................345
Importing an LDAP CA Certificate..................................................................................346
Running directory tests with HPLOMIG (optional)......................................................... 347
HPE Management Core LDAP OID classes and attributes........................................... 349
Core class definitions..................................................................................................... 350
Core attribute definitions................................................................................................ 351
Lights-Out Management specific LDAP OID classes and attributes.............................. 354
Lights-Out Management attributes.................................................................................354
Lights-Out Management class definitions...................................................................... 354
Lights-Out Management attribute definitions................................................................. 355
Managing iLO reboots, factory reset, and NMI.................................357
Rebooting (resetting) the iLO processor with the web interface ................................... 357
Rebooting (resetting) iLO with the iLO 5 Configuration Utility........................................357
Rebooting (resetting) iLO with the server UID button.................................................... 358
12
Contents