Installation Manual
2. Install the root CA to enable SSL. iLO communicates with the directory only over a secure
SSL connection.
For information about using Certificate Services with Active Directory, see the Microsoft
documentation.
3. Ensure that the directory DN of at least one user and the DN of a security group that contains
that user are available. This information is used for validating the directory setup.
4. Install an iLO Advanced license to enable Directory Service Authentication.
5. Verify that the correct DNS server is specified on the iLO network settings IPv4 or IPv6 page.
Using the iLO web interface to configure iLO for schema-free directory integration
1. Configure the iLO schema-free directory parameters.
2. Configure directory groups.
Using XML configuration and control scripts to configure iLO for schema-free
directory integration
1. Download the iLO RIBCL script samples from the following website: http://www.hpe.com/
support/ilo4.
2. Use the Mod_Directory.xml file as a template for enabling directory login and specifying
the directory server address.
3. Use the Mod_Schemaless_Directory.xml script as a template for specifying the
schema-free directory settings.
Required values for the schema-free integration with Active Directory:
The following values are required in the Mod_Directory.xml file:
• Directory Server Address—DIR_SERVER_ADDRESS
• Directory Server LDAP Port—DIR_SERVER_PORT
• Directory User Context—DIR_USER_CONTEXT_1
• Enable schema-free directory integration—DIR_ENABLE_GRP_ACCT
The following values are required in the Mod_Schemaless_Directory.xml file:
• The group container in the directory—DIR_GRPACCT1_NAME
• iLO privileges for the group—DIR_GRPACCT1_PRIV
• Enable schema-free directory integration—DIR_ENABLE_GRP_ACCT
For more information about the scripting values, see the iLO scripting and CLI guide.
Using the CLI, CLP, or SSH interface to configure iLO for schema-free directory
integration
1. Establish an ssh session to iLO and navigate to the target.
286 Kerberos authentication and Directory services