<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic iLO Configuration with Active directory in Server Management - Remote Server Management</title>
    <link>https://community.hpe.com/t5/server-management-remote-server/ilo-configuration-with-active-directory/m-p/4075927#M2976</link>
    <description>Dear Ms.Sir,&lt;BR /&gt;&lt;BR /&gt;I am configuring iLO and AD so that we can do authentication using AD. We have extended the schema in AD for iLO. When we we try to authenticate as an AD user we get the folowing error.&lt;BR /&gt;&lt;BR /&gt;Warning: certificate does not match Directory Server Address 10.64.2.10.&lt;BR /&gt;Unable to access directory with LOM Object Password.&lt;BR /&gt;&lt;BR /&gt;I'm not sure why the iLO is looking for the ip address and not the host name.&lt;BR /&gt;&lt;BR /&gt;Thank you in advance for your help.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;Larry</description>
    <pubDate>Tue, 25 Sep 2007 13:20:06 GMT</pubDate>
    <dc:creator>larryb</dc:creator>
    <dc:date>2007-09-25T13:20:06Z</dc:date>
    <item>
      <title>iLO Configuration with Active directory</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-configuration-with-active-directory/m-p/4075927#M2976</link>
      <description>Dear Ms.Sir,&lt;BR /&gt;&lt;BR /&gt;I am configuring iLO and AD so that we can do authentication using AD. We have extended the schema in AD for iLO. When we we try to authenticate as an AD user we get the folowing error.&lt;BR /&gt;&lt;BR /&gt;Warning: certificate does not match Directory Server Address 10.64.2.10.&lt;BR /&gt;Unable to access directory with LOM Object Password.&lt;BR /&gt;&lt;BR /&gt;I'm not sure why the iLO is looking for the ip address and not the host name.&lt;BR /&gt;&lt;BR /&gt;Thank you in advance for your help.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;Larry</description>
      <pubDate>Tue, 25 Sep 2007 13:20:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-configuration-with-active-directory/m-p/4075927#M2976</guid>
      <dc:creator>larryb</dc:creator>
      <dc:date>2007-09-25T13:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: iLO Configuration with Active directory</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-configuration-with-active-directory/m-p/4075928#M2977</link>
      <description>Hi Larry,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Follow link below :&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h20000.www2.hp.com/bizsupport/TechSupport/CoreRedirect.jsp?redirectReason=DocIndexPDF&amp;amp;prodSeriesId=397989&amp;amp;targetPage=http%3A%2F%2Fh20000.www2.hp.com%2Fbc%2Fdocs%2Fsupport%2FSupportManual%2Fc00190541%2Fc00190541.pdf" target="_blank"&gt;http://h20000.www2.hp.com/bizsupport/TechSupport/CoreRedirect.jsp?redirectReason=DocIndexPDF&amp;amp;prodSeriesId=397989&amp;amp;targetPage=http%3A%2F%2Fh20000.www2.hp.com%2Fbc%2Fdocs%2Fsupport%2FSupportManual%2Fc00190541%2Fc00190541.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Hopes its helpful &lt;BR /&gt;&lt;BR /&gt;Cheers :)</description>
      <pubDate>Tue, 25 Sep 2007 14:19:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-configuration-with-active-directory/m-p/4075928#M2977</guid>
      <dc:creator>HP_Sammy</dc:creator>
      <dc:date>2007-09-25T14:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: iLO Configuration with Active directory</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-configuration-with-active-directory/m-p/4075929#M2978</link>
      <description>Try this&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h20000.www2.hp.com/bizsupport/TechSupport/CoreRedirect.jsp?redirectReason=DocIndexPDF&amp;amp;prodSeriesId=397989&amp;amp;targetPage=http%3A%2F%2Fh20000.www2.hp.com%2Fbc%2Fdocs%2Fsupport%2FSupportManual%2Fc00190541%2Fc00190541.pdf" target="_blank"&gt;http://h20000.www2.hp.com/bizsupport/TechSupport/CoreRedirect.jsp?redirectReason=DocIndexPDF&amp;amp;prodSeriesId=397989&amp;amp;targetPage=http%3A%2F%2Fh20000.www2.hp.com%2Fbc%2Fdocs%2Fsupport%2FSupportManual%2Fc00190541%2Fc00190541.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Cheers :)</description>
      <pubDate>Tue, 25 Sep 2007 14:22:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-configuration-with-active-directory/m-p/4075929#M2978</guid>
      <dc:creator>HP_Sammy</dc:creator>
      <dc:date>2007-09-25T14:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: iLO Configuration with Active directory</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-configuration-with-active-directory/m-p/4075930#M2979</link>
      <description>I dont know why that link is not working &lt;BR /&gt;&lt;BR /&gt;try this &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h20000.www2.hp.com/bizsupport/TechSupport/DocumentIndex.jsp?contentType=SupportManual" target="_blank"&gt;http://h20000.www2.hp.com/bizsupport/TechSupport/DocumentIndex.jsp?contentType=SupportManual&lt;/A&gt;〈=en&amp;amp;cc=us&amp;amp;docIndexId=179111&amp;amp;taskId=101&amp;amp;prodTypeId=18964&amp;amp;prodSeriesId=397989&lt;BR /&gt;&lt;BR /&gt;Go to whitepapers and under that u will find a doc for integrating iLO with AD&lt;BR /&gt;&lt;BR /&gt;Cheers :)</description>
      <pubDate>Tue, 25 Sep 2007 14:42:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-configuration-with-active-directory/m-p/4075930#M2979</guid>
      <dc:creator>HP_Sammy</dc:creator>
      <dc:date>2007-09-25T14:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: iLO Configuration with Active directory</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-configuration-with-active-directory/m-p/4075931#M2980</link>
      <description>Hi Larry,&lt;BR /&gt;&lt;BR /&gt;Try Following and also check pg 27 of pdf &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;********************************************&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;HP Proliant iLO/RILOE Authentication with MS Active Directory&lt;BR /&gt;&lt;BR /&gt;( Schema-less Configuration ) Schem Free !&lt;BR /&gt;&lt;BR /&gt;Required:  HP iLO/RILEO Firmware : v1.91 (or later)&lt;BR /&gt;&lt;BR /&gt;HP iLO/RILEO Configuration&lt;BR /&gt;&lt;BR /&gt;1)    Login to the iLO/RILEO as the â  Administratorâ   User&lt;BR /&gt;&lt;BR /&gt;2)    Goto the â  Administrationâ   tab and select â  Directory Servicesâ  &lt;BR /&gt;&lt;BR /&gt;3)    Configure â  Directory Settingsâ   with the following information:&lt;BR /&gt;&lt;BR /&gt;[formatted]&lt;BR /&gt;Authentication Settings&lt;BR /&gt;&lt;BR /&gt;Å¾ Use Directory Default Schema&lt;BR /&gt;&lt;BR /&gt;Directory Server Settings&lt;BR /&gt;Directory Server Address: servername.HP.com&lt;BR /&gt;&lt;BR /&gt;            Directory Server LDAP Port: 636&lt;BR /&gt;&lt;BR /&gt;Select â  Apply Settingsâ   (answer â  Yes/OKâ   on any subsequent questions)&lt;BR /&gt;[unformatted]&lt;BR /&gt;&lt;BR /&gt;4)    Select â  Administer Groupsâ  . Highlight â  Administratorâ   and select â  View/Modifyâ  &lt;BR /&gt;&lt;BR /&gt;5)    Configure the â  Administrator Group Settingsâ   with the following information:&lt;BR /&gt;Security Group Distinguished Name: CN=Administrators,OU=Groups,DC=HP,DC=com&lt;BR /&gt;&lt;BR /&gt;Administer Group Accounts: Yes&lt;BR /&gt;&lt;BR /&gt;Remote Console Access: Yes&lt;BR /&gt;&lt;BR /&gt;Virtual Power and Reset: Yes&lt;BR /&gt;&lt;BR /&gt;Virtual Media: Yes&lt;BR /&gt;&lt;BR /&gt;Configure iLO Settings: Yes &lt;BR /&gt;Select â  Save Group Informationâ  &lt;BR /&gt;&lt;BR /&gt;6)    Return to the â  Directory Settingsâ   Page and select â  Test Settingsâ  . Enter a â  Test User Nameâ   and â  Test User Passwordâ   to validate the configuration.&lt;BR /&gt;&lt;BR /&gt;NOTE : Ensure that you use the appropriate Distinguished Name (DN) for the user that youâ  re going to test with. Check Active Directory for the appropriate DN for the user container.&lt;BR /&gt;&lt;BR /&gt;[formatted]&lt;BR /&gt;            Active Directory Users and Computers&lt;BR /&gt;&lt;BR /&gt;            - Find the user&lt;BR /&gt;&lt;BR /&gt;            - Righ Click on the User Object&lt;BR /&gt;&lt;BR /&gt;            - Select â  Name Mapping â ¦â  &lt;BR /&gt;&lt;BR /&gt;(Here is where some basic knowledge of directory services is needed as to what to context use â   CN=Container, OU=Organizational Unit, DC=Domain etc.)&lt;BR /&gt;&lt;BR /&gt;ie:        CN=LastName\, FirstName,OU=Users,DC=HP,DC=com&lt;BR /&gt;&lt;BR /&gt;NOTE: Since â  ,â   are delimiters for a DN, they will need to be escaped with a â  \â   when being used.&lt;BR /&gt;&lt;BR /&gt;Server Name:  servername&lt;BR /&gt;&lt;BR /&gt;iLO name:  iLOname&lt;BR /&gt;&lt;BR /&gt;Current User:  Administrator&lt;BR /&gt;[unformatted]&lt;BR /&gt;&lt;BR /&gt;A successful test will render the following output:     [Administration â   Directory Settings]&lt;BR /&gt;&lt;BR /&gt;Directory Tests&lt;BR /&gt;&lt;BR /&gt;[formatted]&lt;BR /&gt;RESULTS&lt;BR /&gt;Overall Status                            Passed&lt;BR /&gt;Test Description                          Status&lt;BR /&gt;Ping Directory Server                     Passed&lt;BR /&gt;Directory Server IP address               Not run&lt;BR /&gt;Directory Server DNS Name                 Passed&lt;BR /&gt;Connect to Directory Server               Passed&lt;BR /&gt;Connect using SSL                         Passed&lt;BR /&gt;Certificate of Directory Server           Passed&lt;BR /&gt;Bind to Directory Server                  Passed&lt;BR /&gt;Directory Administrator login             Not Run&lt;BR /&gt;User Authentication                       Passed&lt;BR /&gt;User Authorization                        Passed&lt;BR /&gt;Directory User Context 1                  Not Run&lt;BR /&gt;Directory User Context 2                  Not Run&lt;BR /&gt;Directory User Context 3                  Not Run&lt;BR /&gt;LOM Object exists                         Not Run&lt;BR /&gt;LOM Object password                       Not Run&lt;BR /&gt;[unformatted]&lt;BR /&gt;&lt;BR /&gt;TEST LOG&lt;BR /&gt;Directory Server address servername.HP.com resolved to 192.168.1.1&lt;BR /&gt;&lt;BR /&gt;Accepting Directory Server certificate for /servername.HP.com signed by /DC=com/DC=HP/CN=Common Certificate Issuer&lt;BR /&gt;&lt;BR /&gt;Test user CN=LastName\, FirstName,OU=Users,DC=HP,DC=comauthenticated.&lt;BR /&gt;&lt;BR /&gt;Cumulative rights gained:&lt;BR /&gt;&lt;BR /&gt;Â·          Login&lt;BR /&gt;&lt;BR /&gt;Â·          Administer Local User Accounts&lt;BR /&gt;&lt;BR /&gt;Â·          Remote Console Access&lt;BR /&gt;&lt;BR /&gt;Â·          Virtual Power and Reset&lt;BR /&gt;&lt;BR /&gt;Â·          Virtual Media&lt;BR /&gt;&lt;BR /&gt;Â·         Configure Local Device (iLO) Settings&lt;BR /&gt;&lt;BR /&gt;Test Complete.&lt;BR /&gt;&lt;BR /&gt;IE/Web browser Configuration&lt;BR /&gt;&lt;BR /&gt;In order for the IE (ActiveX Control) to translate your Username into the proper Distinguished Name (DN) for the iLO Authentication, the following needs to be configured:&lt;BR /&gt;&lt;BR /&gt;1)      Within IE, select â  Tools Ã&amp;nbsp; Internet Optionsâ  &lt;BR /&gt;&lt;BR /&gt;2)      On the â  Securityâ   Tab, select â  Custom Levelâ ¦â  &lt;BR /&gt;&lt;BR /&gt;3)      Ensure the following is set with regards to â  ActiveX Controls and Plug-  Insâ  &lt;BR /&gt;&lt;BR /&gt;a.      Automatic prompting of ActiveX controls: Enable&lt;BR /&gt;&lt;BR /&gt;b.      Binary and Script behavior: Enable&lt;BR /&gt;&lt;BR /&gt;c.       Download signed ActiveX controls: Prompt&lt;BR /&gt;&lt;BR /&gt;d.      Download unsigned ActiveX controls: Prompt&lt;BR /&gt;&lt;BR /&gt;e.      Initialize and script ActiveX controls not marked as safe: Prompt&lt;BR /&gt;&lt;BR /&gt;f.        Run ActiveX controls and plug-ins: Enable&lt;BR /&gt;&lt;BR /&gt;g.      Script ActiveX controls marked safe for scripting: Enable&lt;BR /&gt;&lt;BR /&gt;4)      Select â  OKâ   (on any subsequent diaglog boxes).&lt;BR /&gt;&lt;BR /&gt;5)      Restart IE and access the iLO&lt;BR /&gt;&lt;BR /&gt;At this point, the configuration is complete for the iLO and IE to be able to accept MS Active Directory accounts for authentication and authorities.&lt;BR /&gt;&lt;BR /&gt;Valid representation of Usernames are: &lt;DOMAIN&gt;\&lt;USERNAME&gt; - a.k.a NetBIOS Username &lt;USERNAME&gt;@&lt;FQDN&gt; - a.k.a. User Principle Name (UPN)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;********************************************&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Cheers :)&lt;/FQDN&gt;&lt;/USERNAME&gt;&lt;/USERNAME&gt;&lt;/DOMAIN&gt;</description>
      <pubDate>Tue, 25 Sep 2007 21:50:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-configuration-with-active-directory/m-p/4075931#M2980</guid>
      <dc:creator>HP_Sammy</dc:creator>
      <dc:date>2007-09-25T21:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: iLO Configuration with Active directory</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-configuration-with-active-directory/m-p/4075932#M2981</link>
      <description>hi larryb&lt;BR /&gt;&lt;BR /&gt;try this thread&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=1005787" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=1005787&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;regards</description>
      <pubDate>Wed, 26 Sep 2007 00:20:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-configuration-with-active-directory/m-p/4075932#M2981</guid>
      <dc:creator>KarloChacon</dc:creator>
      <dc:date>2007-09-26T00:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: iLO Configuration with Active directory</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-configuration-with-active-directory/m-p/4075933#M2982</link>
      <description>Hi All,&lt;BR /&gt;&lt;BR /&gt;Thank you all for your help. We found the problem. We were using the default iLO password to try and logon not the AD password. In addition to that we had the LDAPdn full qualified path wrong. IE: cn=aduser,dc=example,dc=com&lt;BR /&gt;&lt;BR /&gt;again thank you for your help.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Sep 2007 07:42:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-configuration-with-active-directory/m-p/4075933#M2982</guid>
      <dc:creator>larryb</dc:creator>
      <dc:date>2007-09-26T07:42:29Z</dc:date>
    </item>
  </channel>
</rss>

