<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: iLO Client side cert (2-factor) auth failing in Server Management - Remote Server Management</title>
    <link>https://community.hpe.com/t5/server-management-remote-server/ilo-client-side-cert-2-factor-auth-failing/m-p/3866550#M2268</link>
    <description>Folks, I seem to have stumbled on the solution. If I point my browser to http://&lt;ILO-ADDRESS&gt;/ rather than https://&lt;ILO-ADDRESS&gt;/, the server forces a re-direct to https://&lt;ILO-ADDRESS&gt;/ and I can get in. This is highly consistent in that if I go to https: it fails everytime and http: re-directs with success! I guess that when the initial 2-factor authentication is enabled, the automatic re-start performs the same correct re-direct as using http: does.&lt;BR /&gt;&lt;BR /&gt;I have to conclude form this that there's a small bug in the iLO server web front-end. Hopefully HP will fix this at some point but in the meantime I have a working solution. Thanks to all that replied.&lt;BR /&gt;&lt;BR /&gt;Steve.&lt;/ILO-ADDRESS&gt;&lt;/ILO-ADDRESS&gt;&lt;/ILO-ADDRESS&gt;</description>
    <pubDate>Fri, 22 Sep 2006 09:24:57 GMT</pubDate>
    <dc:creator>Steve Forrester_1</dc:creator>
    <dc:date>2006-09-22T09:24:57Z</dc:date>
    <item>
      <title>iLO Client side cert (2-factor) auth failing</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-client-side-cert-2-factor-auth-failing/m-p/3866545#M2263</link>
      <description>Connecting to iLO (V1.82 firmware) using 2-factor authentication fails on 2nd and subsequent attempts. Strangely enough it works on the 1st attempt. Has anyone else observed this curious behaviour? &lt;BR /&gt;&lt;BR /&gt;I've repeated this several times by switching in and out of 2-factor auth. Following the re-boot- that occurs after re-enabling 2-factor auth I can get in on 1st attempt but not again. This suggests that there is nothing particularly wrong with the certificate side of this. Any known bugs?&lt;BR /&gt;&lt;BR /&gt;Thanks.</description>
      <pubDate>Wed, 20 Sep 2006 11:59:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-client-side-cert-2-factor-auth-failing/m-p/3866545#M2263</guid>
      <dc:creator>Steve Forrester_1</dc:creator>
      <dc:date>2006-09-20T11:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: iLO Client side cert (2-factor) auth failing</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-client-side-cert-2-factor-auth-failing/m-p/3866546#M2264</link>
      <description>Hi Steve,&lt;BR /&gt;&lt;BR /&gt;You might have enabled the 2-factor on this iLO.&lt;BR /&gt;If so, you may have problems with your certificate or your client does not have a cert that iLO is looking for. Find out that your client have the correct cert in your smartcard device.&lt;BR /&gt;&lt;BR /&gt;If your client cert is good, than you will need to disable 2-factor and recheck your 2-Factor certificates in iLO.&lt;BR /&gt;&lt;BR /&gt;To disable 2-factor, press F8 at boot to get into the iLO RBSU setup, or run hponcfg with the Mod_2Factor.xml script from the OS(Windows or Linux).&lt;BR /&gt;&lt;BR /&gt;Sample script is at &lt;A href="http://h18000.www1.hp.com/support/files/Server/us/download/23218.html" target="_blank"&gt;http://h18000.www1.hp.com/support/files/Server/us/download/23218.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;hponcfg is at&lt;BR /&gt;&lt;A href="http://h18007.www1.hp.com/support/files/server/us/download/23045.html" target="_blank"&gt;http://h18007.www1.hp.com/support/files/server/us/download/23045.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Hope this works!!!!!&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;rmn</description>
      <pubDate>Thu, 21 Sep 2006 05:52:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-client-side-cert-2-factor-auth-failing/m-p/3866546#M2264</guid>
      <dc:creator>ramesh_naik_</dc:creator>
      <dc:date>2006-09-21T05:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: iLO Client side cert (2-factor) auth failing</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-client-side-cert-2-factor-auth-failing/m-p/3866547#M2265</link>
      <description>Ramesh,&lt;BR /&gt;&lt;BR /&gt;Thanks for responding to this one but I can't see a problem with any of the certificates, as the first 2-factor authentication ALWAYS works. Furthermore I've now tried with three different CAs and each gives the same problem. I've also tried with two different servers (both DL380s with iLO V1.82), again with the same results.&lt;BR /&gt;&lt;BR /&gt;Given the consistency of the problem, this has to be a configuration issue of some sort but I can't see what this can possibly be. Any idea what certificate attributes are checked as part of the SSL handshake (e.g. is the CN checked against the username)?&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;&lt;BR /&gt;Steve.</description>
      <pubDate>Thu, 21 Sep 2006 06:49:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-client-side-cert-2-factor-auth-failing/m-p/3866547#M2265</guid>
      <dc:creator>Steve Forrester_1</dc:creator>
      <dc:date>2006-09-21T06:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: iLO Client side cert (2-factor) auth failing</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-client-side-cert-2-factor-auth-failing/m-p/3866548#M2266</link>
      <description>No silver bullets here, but...&lt;BR /&gt;&lt;BR /&gt;First, try the latest iLO firmware.  There is a bug fix related to certificate expiration.  While that is probably not related to this issue, it is a 2-factor change.&lt;BR /&gt;&lt;BR /&gt;Also, the 2-factor support for iLO user accounts tests that:&lt;BR /&gt;1: the client certificate (stored in the token) was stored by the imported root CA,&lt;BR /&gt;and&lt;BR /&gt;2: The client certificate thumbprint matches the one stored for the user account.</description>
      <pubDate>Thu, 21 Sep 2006 11:25:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-client-side-cert-2-factor-auth-failing/m-p/3866548#M2266</guid>
      <dc:creator>acartes</dc:creator>
      <dc:date>2006-09-21T11:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: iLO Client side cert (2-factor) auth failing</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-client-side-cert-2-factor-auth-failing/m-p/3866549#M2267</link>
      <description>I had seen this.  After you enabled 2 Factor, iLO will reset.  You do not have to reboot the server.  If you do reboot the server, wait for the OS to comeup and your 2 factor login should work.</description>
      <pubDate>Thu, 21 Sep 2006 15:06:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-client-side-cert-2-factor-auth-failing/m-p/3866549#M2267</guid>
      <dc:creator>barnett chan</dc:creator>
      <dc:date>2006-09-21T15:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: iLO Client side cert (2-factor) auth failing</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-client-side-cert-2-factor-auth-failing/m-p/3866550#M2268</link>
      <description>Folks, I seem to have stumbled on the solution. If I point my browser to http://&lt;ILO-ADDRESS&gt;/ rather than https://&lt;ILO-ADDRESS&gt;/, the server forces a re-direct to https://&lt;ILO-ADDRESS&gt;/ and I can get in. This is highly consistent in that if I go to https: it fails everytime and http: re-directs with success! I guess that when the initial 2-factor authentication is enabled, the automatic re-start performs the same correct re-direct as using http: does.&lt;BR /&gt;&lt;BR /&gt;I have to conclude form this that there's a small bug in the iLO server web front-end. Hopefully HP will fix this at some point but in the meantime I have a working solution. Thanks to all that replied.&lt;BR /&gt;&lt;BR /&gt;Steve.&lt;/ILO-ADDRESS&gt;&lt;/ILO-ADDRESS&gt;&lt;/ILO-ADDRESS&gt;</description>
      <pubDate>Fri, 22 Sep 2006 09:24:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-client-side-cert-2-factor-auth-failing/m-p/3866550#M2268</guid>
      <dc:creator>Steve Forrester_1</dc:creator>
      <dc:date>2006-09-22T09:24:57Z</dc:date>
    </item>
  </channel>
</rss>

