White Papers

CMC for PowerEdge VRTX Features Enabled by Digital Licensing
6
Directory Services
The Directory Services maintains a common database for storing information about users,
computers, printers, and others on a network. If you use either Microsoft
®
Active Directory
®
or
Generic Lightweight Directory Access Protocol (LDAP) services, you can configure the service to
provide access to the CMC, allowing you to add and control CMC user privileges to the existing users
in your directory service.
iDRAC Single Sign-On
The iDRAC Single Sign-On feature allows a user to launch the iDRAC GUI or Remote Console from the
CMC without having to sign on to the target server, a second time. The Single Sign-On policy is as
follows:
A CMC user who has the Server Administrative privilege is automatically logged in to iDRAC
using single sign-on. After logging in to the iDRAC GUI, this user is automatically granted
Administrator privileges. The login occurs even if the user does not have an iDRAC account,
or has an account without an Administrator’s privileges.
A CMC user without the Server Administrative privilege, but having the same account on
iDRAC is automatically logged in to iDRAC using single sign-on. After logging in to the iDRAC
GUI, the user is granted the privileges assigned to the iDRAC account.
A CMC user who does not have the Server Administrative privilege, or the same account on
the iDRAC will not be automatically logged in to iDRAC using single sign-on. This user is
directed to the iDRAC login page when the Launch iDRAC GUI or the Launch Remote
Console button is clicked.
Two-Factor Authentication
Two-factor Authentication provides a higher-level of security by requiring users to have a password
or PIN, and a physical card containing a private key or digital certificate. Kerberos uses this two-
factor authentication mechanism allowing systems to prove their authenticity.
PK Authentication
PK Authentication allows you to configure up to six public keys that can be used with the service
username over an SSH interface. The service username is a special user account that can be used
when accessing the CMC through SSH. When the PKA over SSH is set up and used correctly, you need
not enter username or passwords to log in to the CMC. This can be very useful to set up automated
scripts to perform various functions.
Remote File Share
The Remote File Share feature enables the ability to connect, disconnect, or deploy a media file
available on the network. When connected, the remote file is accessible in a similar manner as a
local file. Two types of media are supported: floppy disk drives and CD/DVD drives.