Installation Manual

Kerberos KDC Server Port—The TCP or UDP port number on which the KDC is listening.
The default value is 88.
Kerberos Keytab—A binary file that contains pairs of service principal names and encrypted
passwords. In the Windows environment, you use the ktpass utility to generate the keytab
file.
Configuring schema-free directory settings in iLO
1. Navigate to the AdministrationSecurityDirectory page.
2. Select the Use Directory Default Schema option for LDAP Directory Authentication.
3. Select the Enabled option for Local User Accounts if you want to use local user accounts
at the same time as directory integration.
4. Enter the FQDN or IP address of a directory server in the Directory Server Address box.
5. Enter the directory server port number in the Directory Server LDAP Port box.
6. Enter valid search contexts in one or more of the Directory User Context boxes.
7. Click Apply Settings.
8. To test the communication between the directory server and iLO, click Test Settings.
9. Optional: To configure directory groups, click Administer Groups to navigate to the User
Administration page.
More information
Schema-free directory authentication
Local user accounts with Kerberos authentication and directory integration
Directory user contexts
Running directory tests
Schema-free directory settings
Use Directory Default Schema—Selects directory authentication and authorization by
using user accounts in the directory. Select this option when the directory is not extended
with the HPE Extended Schema. User accounts and group memberships are used to
authenticate and authorize users.
Directory Server Address—Specifies the network DNS name or IP address of the directory
server. The directory server address can be up to 127 characters.
If you enter the FQDN, ensure that the DNS settings are configured in iLO.
Hewlett Packard Enterprise recommends using DNS round-robin when you define the
directory server.
Directory Server LDAP Port—Specifies the port number for the secure LDAP service on
the server. The default value is 636. If your directory service is configured to use a different
port, you can specify a different value. Make sure that you enter a secured LDAP port. iLO
cannot connect to an unsecured LDAP port.
Directory User Contexts—These boxes enable you to specify common directory subcontexts
so that users do not need to enter their full DNs at login. Directory user contexts can be up
to 128 characters.
Configuring HPE Extended Schema directory settings in iLO
1. Navigate to the AdministrationSecurityDirectory page.
2. Select the Use Extended Schema option for LDAP Directory Authentication.
3. Select the Enabled option for Local User Accounts if you want to use local user accounts
at the same time as directory integration.
4. Enter the FQDN or IP address of a directory server in the Directory Server Address box.
Directory authentication and authorization 79