Users Guide

Table Of Contents
Configuring Smart Card Login
NOTE: For Active Directory Smart Card Configuration, iDRAC must be configured either with Standard or Extended
Schema SSO Login.
Configuring iDRAC smart card login for Active Directory users
Before configuring iDRAC Smart Card login for Active Directory users, make sure that you have completed the required
prerequisites.
To configure iDRAC for smart card login:
1. In iDRAC Web interface, while configuring Active Directory to set up an user account based on standard schema or extended
schema, on the Active Directory Configuration and Management Step 1 of 4 page:
Enable certificate validation.
Upload a trusted CA-signed certificate.
Upload the keytab file.
2. Enable smart card login. For information about the options, see the iDRAC Online Help.
Configuring iDRAC smart card login for local users
To configure iDRAC local user for smart card login:
1. Upload the smart card user certificate and trusted CA certificate to iDRAC.
2. Enable smart card login.
Uploading smart card user certificate
Before you upload the user certificate, make sure that the user certificate from the smart card vendor is exported in Base64
format. SHA-2 certificates are also supported.
Uploading smart card user certificate using web interface
To upload smart card user certificate:
1. In iDRAC web interface, go to iDRAC Settings > Users > Smart Card.
NOTE: The Smart Card login feature requires the configuration of the local and/or Active Directory user certificate.
2. Under Configure Smart Card Logon, select Enabled With Remote RACADM to enable the configuration..
3. Set the option to Enable CRL Check for Smart Card Logon.
4. Click Apply.
Uploading smart card user certificate using RACADM
To upload smart card user certificate, use the usercertupload object. For more information, see the iDRAC RACADM CLI Guide
available at https://www.dell.com/idracmanuals.
Requesting Certificate for smart card enrollment
Follow these steps to request certificate for smart card enrollment:
1. Connect the smart card in the client system and install the required drivers & software.
2. Verify the driver status in the Device Manager.
3. Launch the smart card enrollment agent in the browser.
4. Enter the Username & Password and click OK.
5. Click Request Certificate.
Configuring iDRAC for Single Sign-On or smart card login
169