Installation Manual
Schema-free nested groups (Active Directory only)....................................................................287
HPE Extended Schema directory authentication..............................................................................287
Process overview: Configuring the HPE Extended Schema with Active Directory.....................287
Prerequisites for configuring Active Directory with the HPE Extended Schema configuration....288
Directory services support...........................................................................................................288
Installing the iLO directory support software...............................................................................288
Directories Support for ProLiant Management Processors install options.............................289
Running the Schema Extender...................................................................................................290
Schema Extender required information..................................................................................291
Directory services objects............................................................................................................291
Managing roles and objects with the Active Directory snap-ins..................................................291
Setting a client IP address or DNS name restriction..............................................................294
Sample configuration: Active Directory and HPE Extended Schema..........................................294
Configuration process overview.............................................................................................295
Snap-in installation and initialization for Active Directory.......................................................295
Creating and configuring directory objects for use with iLO in Active Directory.....................295
Directory-enabled remote management (HPE Extended Schema configuration)............................297
Roles based on organizational structure.....................................................................................297
How role access restrictions are enforced..................................................................................298
User access restrictions..............................................................................................................299
User address restrictions.......................................................................................................299
IP address range restrictions.................................................................................................299
IP address and subnet mask restrictions...............................................................................299
DNS-based restrictions..........................................................................................................299
User time restrictions.............................................................................................................300
Role access restrictions...............................................................................................................300
Role-based time restrictions...................................................................................................300
Role-based address restrictions.............................................................................................301
Multiple restrictions and roles.................................................................................................301
Tools for configuring multiple iLO systems at a time........................................................................302
User login using directory services...................................................................................................302
Directories Support for ProLiant Management Processors utility (HPLOMIG.exe)..........................303
Directories Support for ProLiant Management Processors Compatibility...................................304
Configuring directory authentication with HPLOMIG........................................................................304
Discovering management processors.........................................................................................304
HPLOMIG management processor search criteria................................................................305
HPLOMIG management processor import list requirements.................................................306
Optional: Upgrading firmware on management processors (HPLOMIG)....................................306
Selecting directory configuration options.....................................................................................307
Management processor selection methods...........................................................................309
Directory access methods and settings.................................................................................309
Naming management processors (HPE Extended Schema only)...............................................309
Configuring directories when HPE Extended Schema is selected..............................................310
Configuring management processors (Schema-free configuration only)....................................315
Management processor settings............................................................................................316
Setting up management processors for directories.....................................................................316
25 Troubleshooting.............................................................................................319
Using the iLO Virtual Serial Port with Windbg..................................................................................319
Using the ProLiant Preboot Health Summary...................................................................................320
Preboot Health Summary details.................................................................................................321
Event log entries...............................................................................................................................322
Incorrect time stamp on iLO Event Log entries................................................................................322
Login and iLO access issues............................................................................................................322
iLO firmware login name and password not accepted................................................................322
Contents 15