Users Guide

Table Of Contents
组类Active Directory 务器
Security - 使机访
-
组类使限,使
Windows Server 2008 R2 x64 SSO
1. 为域 technet.microsoft.com/en-us/library/dd560670(WS.10).aspx
2. 以使 DES-CBC-MD5
能会容性Kerberos
Computer Configuration > Security Settings > Local Policies > Security
Options
3. 户端 GPO
4. ,键 gpupdate /force 使 klist purge Keytab
5. GPO keytab
6. keytab iDRAC
使 SSO iDRAC
Windows 7 Windows Server 2008 R2 Active Directory
Windows 7 Windows Server 2008 R2
1. 以管份登
2. 运行 gpedit.msc ocal Group Policy Editor窗口
3. Local Computer Settings算机 > Windows SettingsWindows > Security Settings
> Local Policies > Security Options
4. Network Security: Configure encryption types allowed for kerberos Kerberos
Properties
5. 项。
6. OK可以使 SSO iDRAC
Extended Schema
1. Local Group Policy Editor导航 Local Computer Settings >
Windows SettingsWindows > Security Settings > Local Policies > Security
Options
2. Network Security: Restrict NTLM: Outgoing NTLM traffic to remote server NTLM
的出 NTLM Properties
3. Allow all OK关闭 Local Group Policy Editor
4. 运行 cmd
5. gpupdate /force提示
6. regedit Registry Editor注册
7. HKEY_LOCAL_MACHINE > System > CurrentControlSet > Control > LSA
8. New建) > DWORD (32-bit) ValueDWORD [32 ]
9. SuppressExtendedProtection
10. SuppressExtendedProtection Modify
11. Value data 1 OK
12. Registry Editor 使 SSO iDRAC
iDRAC SSO 使 Internet Explorer iDRACSSO 并提
iDRAC IP Tools > Internet Options > Security > Trusted sites可信
未列SSO Cancel
使 Active Directory iDRAC
322