Kerberos authentication and Directory services
Kerberos authentication with iLO
Kerberos support enables a user to log in to iLO by clicking the
Zero Sign In
button on the login page
instead of entering a user name and password. To log in successfully, the client workstation must be
logged in to the domain, and the user must be a member of a directory group for which iLO is configured.
If the workstation is not logged in to the domain, the user can log in to iLO by using the Kerberos UPN
and domain password.
Because a system administrator establishes a trust relationship between iLO and the domain before user
sign-on, any form of authentication (including two-factor authentication) is supported. For information
about configuring a user account to support two-factor authentication, see the server operating system
documentation.
Configuring Kerberos authentication
Procedure
1. Configure the iLO host name and domain name
2. Install an iLO license to enable Kerberos Authentication
.
3. Prepare the domain controller for Kerberos support
4. Generate a Kerberos keytab file
.
5. Verify that your environment meets the Kerberos authentication time requirement
.
6. Configure Kerberos support in iLO
7. Configure supported browsers for single-sign-on
Configuring the iLO hostname and domain name for Kerberos
authentication
If a DHCP server does not supply the domain name or DNS servers you want to use:
Procedure
1.
Click
iLO Dedicated Network Port
in the navigation tree.
2.
Click the
IPv4
tab.
3.
Clear the following check boxes, and then click
Submit
.
•
Use DHCPv4 Supplied Domain Name
•
Use DHCPv4 Supplied DNS Servers
4.
Click the
IPv6
tab.
5.
Clear the following check boxes, and then click
Submit
.
306
Kerberos authentication and Directory services