Installation Manual

2. Install the root CA to enable SSL. iLO communicates with the directory only over a secure
SSL connection.
For information about using Certificate Services with Active Directory, see the Microsoft
documentation.
3. Ensure that the directory DN of at least one user and the DN of a security group that contains
that user are available. This information is used for validating the directory setup.
4. Install an iLO Advanced license to enable Directory Service Authentication.
5. Verify that the correct DNS server is specified on the iLO network settings IPv4 or IPv6 page.
Using the iLO web interface to configure iLO for schema-free directory integration
1. Configure the iLO schema-free directory parameters.
2. Configure directory groups.
Using XML configuration and control scripts to configure iLO for schema-free
directory integration
1. Download the iLO RIBCL script samples from the following website: http://www.hpe.com/
support/ilo4.
2. Use the Mod_Directory.xml file as a template for enabling directory login and specifying
the directory server address.
3. Use the Mod_Schemaless_Directory.xml script as a template for specifying the
schema-free directory settings.
Required values for the schema-free integration with Active Directory:
The following values are required in the Mod_Directory.xml file:
Directory Server Address—DIR_SERVER_ADDRESS
Directory Server LDAP Port—DIR_SERVER_PORT
Directory User Context—DIR_USER_CONTEXT_1
Enable schema-free directory integration—DIR_ENABLE_GRP_ACCT
The following values are required in the Mod_Schemaless_Directory.xml file:
The group container in the directory—DIR_GRPACCT1_NAME
iLO privileges for the group—DIR_GRPACCT1_PRIV
Enable schema-free directory integration—DIR_ENABLE_GRP_ACCT
For more information about the scripting values, see the iLO scripting and CLI guide.
Using the CLI, CLP, or SSH interface to configure iLO for schema-free directory
integration
1. Establish an ssh session to iLO and navigate to the target.
286 Kerberos authentication and Directory services