HP Integrity and HP 9000 iLO MP Operations Guide, Fifth Edition

7 Installing and Configuring Directory Services
You can install and configure iLO MP directory services to leverage the benefits of a single point
of administration for iLO MP user accounts.
This chapter provides information about the features and functions, installation, and configuration
of iLO MP directory services.
This chapter addresses the following topics:
“Directory Services” (page 91)
“Directory Services for Active Directory” (page 96)
“Directory Services for eDirectory” (page 107)
“User Login Using Directory Services” (page 117)
“Certificate Services” (page 118)
“Directory-Enabled Management” (page 118)
“Directory Services Schema (LDAP)” (page 124)
Directory Services
The following are benefits of directory integration:
Scalability You can leverage the directory to support thousands of
users on thousands of iLOs.
Security Robust user password policies are inherited from the
directory. User password complexity, rotation frequency,
and expiration are policy examples.
Role-based administration You can create roles (for instance, clerical, remote control
of the host, complete control), and associate users or user
groups with those roles. When you change a single role,
the change applies to all users and iLO MP devices
associated with that role.
Single point of administration You can use native administrative tools, like Microsoft
Management Console (MMC) and ConsoleOne, to
administer iLO MP users.
Immediacy A single change in the directory rolls out immediately to
associated iLO MPs eliminating the need to script this
process.
Reuse of username and password You can use existing user accounts and passwords in the
directory without having to record or remember a new set
of credentials for the iLO MP.
Flexibility You can create a single role for a single user on a single
iLO MP; you can create a single role for multiple users on
multiple iLOs; or you can use a combination of roles to
best fit your enterprise.
Compatibility iLO MP directory integration applies to iLO MP products
and supports the popular directories Active Directory and
eDirectory.
Standards The iLO MP directory support builds on the LDAP 2.0
standard for secure directory access.
Directory Services 91