Installation Manual
5. Enter the directory server port number in the Directory Server LDAP Port box.
6. Enter the location of this iLO instance in the directory tree in the LOM Object Distinguished
Name box.
7. Enter valid search contexts in one or more of the Directory User Context boxes.
8. Click Apply Settings.
9. To test the communication between the directory server and iLO, click Test Settings.
10. Optional: To configure directory groups, click Administer Groups to navigate to the User
Administration page.
More information
HPE Extended Schema directory authentication
Local user accounts with Kerberos authentication and directory integration
Directory user contexts
Running directory tests
HPE Extended Schema directory settings
• Use HPE Extended Schema—Selects directory authentication and authorization by using
directory objects created with the HPE Extended Schema. Select this option when the
directory has been extended with the HPE Extended Schema. The HPE Extended Schema
works only with Microsoft Windows.
• Directory Server Address—Specifies the network DNS name or IP address of the directory
server. The directory server address can be up to 127 characters.
If you enter the FQDN, ensure that the DNS settings are configured in iLO.
Hewlett Packard Enterprise recommends using DNS round-robin when you define the
directory server.
• Directory Server LDAP Port—Specifies the port number for the secure LDAP service on
the server. The default value is 636. If your directory service is configured to use a different
port, you can specify a different value. Make sure that you enter a secured LDAP port. iLO
cannot connect to an unsecured LDAP port.
• LOM Object Distinguished Name—Specifies where this iLO instance is listed in the directory
tree (for example, cn=Mail Server,ou=Management Devices,o=ab). This option is
available when Use HPE Extended Schema is selected.
User search contexts are not applied to the LOM object DN when iLO accesses the directory
server.
• Directory User Contexts—These boxes enable you to specify common directory subcontexts
so that users do not need to enter their full DNs at login. Directory user contexts can be up
to 128 characters.
Directory user contexts
You can identify the objects listed in a directory by using unique DNs. However, DNs can be
long, users might not know their DNs, or users might have accounts in different directory contexts.
80 Configuring the iLO security features