<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active Directory and ILO2,  I am almost there!!!! in Server Management - Remote Server Management</title>
    <link>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165788#M3443</link>
    <description>Please try modifying the following settings from the Network settings page&lt;BR /&gt;(Administration-&amp;gt;Network) which would help the directory user to login  with "Email"(loginname@domain) and "NetBios name"(domain/loginname) &lt;BR /&gt;formats. &lt;BR /&gt;&lt;BR /&gt;Primary/Secondary/Tertiary DNS Server &lt;BR /&gt;The Primary/Secondary/Tertiary  DNS server IP address should be same&lt;BR /&gt;as the Active directory server IP address.&lt;BR /&gt;&lt;BR /&gt;Domain Name &lt;BR /&gt; This domain should be same as the domain for which the &lt;BR /&gt; Active directory server is configured. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;One other suggestion&lt;BR /&gt; Please ensure "Directory Server Address" under "Administration-&amp;gt;Security-&amp;gt;Directory" has "FQDN"(Fully qualified &lt;BR /&gt; domain name) instead of IP address.&lt;BR /&gt;   Example : test.rind.com&lt;BR /&gt;</description>
    <pubDate>Sun, 23 Mar 2008 15:41:21 GMT</pubDate>
    <dc:creator>M.S.Srivatsa</dc:creator>
    <dc:date>2008-03-23T15:41:21Z</dc:date>
    <item>
      <title>Active Directory and ILO2,  I am almost there!!!!</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165785#M3440</link>
      <description>OK I have been at setting up LDAP authentication through ad and ILO for about a week and have gotten really close and have tried every tid out there but still have one outstanding issue.&lt;BR /&gt;&lt;BR /&gt;I am able to login with my DN string&lt;BR /&gt;CN=Test\, Dan,CN=Users,DC=ad,DC=domain,DC=com&lt;BR /&gt;(I got the string from the ldp utility and if it was not for a poster I would never have figured out the \ after Test)&lt;BR /&gt;&lt;BR /&gt;I then was able to add &lt;BR /&gt;CN=Users,DC=ad,DC=domain,DC=com&lt;BR /&gt;to the Directory User Context 1: and now I can login with just Test\, Dan.  &lt;BR /&gt;&lt;BR /&gt;Obviously I can't leave it like this because users aren't gogin to know there DN especially with the \ after there last name.&lt;BR /&gt;&lt;BR /&gt;I am looking to do what everyone else is trying to do and that is to be able to use the login name that is "dtest" for this user. I have tried adding the @ad.domain.com to the Directory User Context and that did not work. &lt;BR /&gt;&lt;BR /&gt;I did see that there was mention of Active X having to be enabled and I have setup my active x setttings for "Internet" for the following&lt;BR /&gt;Allow previously unused ActiveX controls to run without prompt&lt;BR /&gt;Disable&lt;BR /&gt;Allow Scriptlets &lt;BR /&gt;Disable&lt;BR /&gt;Automatic prompting for ActiveX controls &lt;BR /&gt;Disable&lt;BR /&gt;Binary and script behaviors&lt;BR /&gt;Enable&lt;BR /&gt;Display video and animation on a webpage that does not use external media player&lt;BR /&gt;Disable&lt;BR /&gt;Download signed ActiveX controls&lt;BR /&gt;Prompt&lt;BR /&gt;Download unsigned ActiveX controls &lt;BR /&gt;Disable&lt;BR /&gt;Initialize and script ActiveX controls not marked as safe for scripting &lt;BR /&gt;Prompt&lt;BR /&gt;Run ActiveX controls and plug-ins&lt;BR /&gt;Enable&lt;BR /&gt;Script ActiveX controls marked as safe for scripting*&lt;BR /&gt;Enable&lt;BR /&gt;&lt;BR /&gt;With no luck&lt;BR /&gt;&lt;BR /&gt;Now I am not sure if there is a group policy pushing down to deny the active x ability to run and if anyone know the key to check that would be great. &lt;BR /&gt;&lt;BR /&gt;well that is where I stand and if anyone knows of any more things to check that would be great.</description>
      <pubDate>Fri, 21 Mar 2008 13:25:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165785#M3440</guid>
      <dc:creator>Dan Fitzgerald</dc:creator>
      <dc:date>2008-03-21T13:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory and ILO2,  I am almost there!!!!</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165786#M3441</link>
      <description>Is your users in a group called test? ie CN=Test,CN=Users,DC=ad,DC=domain,DC=com.  If so, add CN=TEST to your contest.&lt;BR /&gt;&lt;BR /&gt;Your client needs to be in the same domain as your directory server for the short name to work.  Try dtest@ad.domain.com.  &lt;BR /&gt;Need to enable&lt;BR /&gt;Initialize and script ActiveX controls not marked as safe for scripting</description>
      <pubDate>Fri, 21 Mar 2008 15:39:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165786#M3441</guid>
      <dc:creator>barnett chan</dc:creator>
      <dc:date>2008-03-21T15:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory and ILO2,  I am almost there!!!!</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165787#M3442</link>
      <description>Hey BWC,&lt;BR /&gt;&lt;BR /&gt;I do have a group similar to test called iLO (has the user dtest in it) so I added that to the string&lt;BR /&gt;CN=iLO,CN=Users,DC=ad,DC=domain,DC=com&lt;BR /&gt;I also made the change to the active X and tried logging in with dtest@ad.domain.com, ad.domain.com\dtest all without success.  &lt;BR /&gt;</description>
      <pubDate>Fri, 21 Mar 2008 19:21:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165787#M3442</guid>
      <dc:creator>Dan Fitzgerald</dc:creator>
      <dc:date>2008-03-21T19:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory and ILO2,  I am almost there!!!!</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165788#M3443</link>
      <description>Please try modifying the following settings from the Network settings page&lt;BR /&gt;(Administration-&amp;gt;Network) which would help the directory user to login  with "Email"(loginname@domain) and "NetBios name"(domain/loginname) &lt;BR /&gt;formats. &lt;BR /&gt;&lt;BR /&gt;Primary/Secondary/Tertiary DNS Server &lt;BR /&gt;The Primary/Secondary/Tertiary  DNS server IP address should be same&lt;BR /&gt;as the Active directory server IP address.&lt;BR /&gt;&lt;BR /&gt;Domain Name &lt;BR /&gt; This domain should be same as the domain for which the &lt;BR /&gt; Active directory server is configured. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;One other suggestion&lt;BR /&gt; Please ensure "Directory Server Address" under "Administration-&amp;gt;Security-&amp;gt;Directory" has "FQDN"(Fully qualified &lt;BR /&gt; domain name) instead of IP address.&lt;BR /&gt;   Example : test.rind.com&lt;BR /&gt;</description>
      <pubDate>Sun, 23 Mar 2008 15:41:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165788#M3443</guid>
      <dc:creator>M.S.Srivatsa</dc:creator>
      <dc:date>2008-03-23T15:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory and ILO2,  I am almost there!!!!</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165789#M3444</link>
      <description>Hi M.S&lt;BR /&gt;&lt;BR /&gt;I did what you said and:&lt;BR /&gt;&lt;BR /&gt;-Primary/Secondary/Tertiary DNS Server &lt;BR /&gt;The Primary/Secondary/Tertiary DNS server IP address should be same&lt;BR /&gt;as the Active directory server IP address.&lt;BR /&gt;&lt;BR /&gt;It is, I only have one AD server in this test environment and it is also the only dns server.&lt;BR /&gt;&lt;BR /&gt;-Domain Name &lt;BR /&gt;This domain should be same as the domain for which the &lt;BR /&gt;Active directory server is configured.&lt;BR /&gt;&lt;BR /&gt;It is, ad.domain.com&lt;BR /&gt;&lt;BR /&gt;-One other suggestion&lt;BR /&gt;Please ensure "Directory Server Address" under "Administration-&amp;gt;Security-&amp;gt;Directory" has "FQDN"(Fully qualified &lt;BR /&gt;domain name) instead of IP address.&lt;BR /&gt;Example : test.rind.com&lt;BR /&gt;&lt;BR /&gt;This also was setup correctly. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I tried logging in as ad.domain.com/dtest and it did not work. It came up as unauthorized. Man this is a good one..</description>
      <pubDate>Tue, 25 Mar 2008 13:01:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165789#M3444</guid>
      <dc:creator>Dan Fitzgerald</dc:creator>
      <dc:date>2008-03-25T13:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory and ILO2,  I am almost there!!!!</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165790#M3445</link>
      <description>Since you are able to login with Test\,Dan; I believe your setup is correct.  The problem is with the context.  iLO is not able to find your users in the context specified in iLO.&lt;BR /&gt;&lt;BR /&gt;Do you have a Container (folder) called Test?  I used the wrong term of group earlier.  &lt;BR /&gt;&lt;BR /&gt;If you look at the User property for Account Dan, does it show "User logon name" as Dan follow by @ad.domain.com or is it Dtest?&lt;BR /&gt;&lt;BR /&gt;If above is true.  Then you should be able to login as ad.domain.com\dan or dan@ad.domain.com&lt;BR /&gt;&lt;BR /&gt;Is it possible to get a screenshot of your mmc for the "AD Users and Computers" where the users are located?&lt;BR /&gt;</description>
      <pubDate>Tue, 25 Mar 2008 13:36:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165790#M3445</guid>
      <dc:creator>barnett chan</dc:creator>
      <dc:date>2008-03-25T13:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory and ILO2,  I am almost there!!!!</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165791#M3446</link>
      <description>ad.domain.com\dtest may not work.  Try using ad\dtest or dtest@ad.domin.com.  Assuming dtest is your login name.</description>
      <pubDate>Tue, 25 Mar 2008 14:56:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165791#M3446</guid>
      <dc:creator>barnett chan</dc:creator>
      <dc:date>2008-03-25T14:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory and ILO2,  I am almost there!!!!</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165792#M3447</link>
      <description>Hey BWC,&lt;BR /&gt;&lt;BR /&gt;I dontt have a container called test. I have one called ilo so in ad under the USERS group I created the user dtest and also in the USERS folder I created the group ilo and added the user dtest to the ilo group. Is that the issue? Should the group ILO not be ing the USERS group that is created with AD? rather it should be under a new ou?  I can get screen shots tomorow because it is in our test environment.&lt;BR /&gt;&lt;BR /&gt;As far as this question&lt;BR /&gt;If you look at the User property for Account Dan, does it show "User logon name" as Dan follow by @ad.domain.com or is it Dtest?&lt;BR /&gt;&lt;BR /&gt;it is dtest then @ad.analog.com</description>
      <pubDate>Tue, 25 Mar 2008 19:11:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165792#M3447</guid>
      <dc:creator>Dan Fitzgerald</dc:creator>
      <dc:date>2008-03-25T19:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory and ILO2,  I am almost there!!!!</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165793#M3448</link>
      <description>Dan,&lt;BR /&gt;&lt;BR /&gt;If the users and groups are in the Users container, iLO should be able to locate the users.  To make it simple to trouble shoot, go ahead and remove the group for now.&lt;BR /&gt;Are you using the "extended schema" method?</description>
      <pubDate>Tue, 25 Mar 2008 22:08:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165793#M3448</guid>
      <dc:creator>barnett chan</dc:creator>
      <dc:date>2008-03-25T22:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory and ILO2,  I am almost there!!!!</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165794#M3449</link>
      <description>No I am using the default schema or Schema-less approach.  so you are saying to remove the user from the ilo group adn leave it in the users group?  so the search context and the administrator group string would just be &lt;BR /&gt;CN=Users,DC=ad,DC=domain,DC=com</description>
      <pubDate>Wed, 26 Mar 2008 11:31:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165794#M3449</guid>
      <dc:creator>Dan Fitzgerald</dc:creator>
      <dc:date>2008-03-26T11:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory and ILO2,  I am almost there!!!!</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165795#M3450</link>
      <description>If your "iLO User (dtest)" is in the group iLO, and the iLO group is in the "Users" container, then the "Directory User Context" should be:&lt;BR /&gt;CN=Users,DC=ad,DC=domain,DC=com.&lt;BR /&gt;The "Directory Server Address" is ad.domain.com.  Verify that you can ping ad.domain.com.  If not, DNS issue.&lt;BR /&gt;-Click on "Administrator Group" button.  Point this to your iLO Group.  iLO below is the "User Group". ie&lt;BR /&gt;CN=iLO,CN=Users,DC=ad,DC=domain,DC=com.&lt;BR /&gt;-Make sure popup blocker is disabled on the browser.&lt;BR /&gt;-Need to enable&lt;BR /&gt;"Initialize and script ActiveX controls not marked as safe for scripting"&lt;BR /&gt;&lt;BR /&gt;Logon as ad\dtest or dtest@ad.domain.com.&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Mar 2008 15:51:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165795#M3450</guid>
      <dc:creator>barnett chan</dc:creator>
      <dc:date>2008-03-26T15:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory and ILO2,  I am almost there!!!!</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165796#M3451</link>
      <description>Hello everyone,&lt;BR /&gt;&lt;BR /&gt;IÂ´m almost having the same problem. IÂ´m able to logon using full distinguished name or username@ad.domain.com. I have put up two "Directory User Context"&lt;BR /&gt;&lt;BR /&gt;1 @ad.domain.com&lt;BR /&gt;2 OU=Users,OU=tech,DC=ad,DC=domain,DC=com&lt;BR /&gt;&lt;BR /&gt;Why canÂ´t I logon using only the user id instead of full name?</description>
      <pubDate>Thu, 27 Mar 2008 07:56:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165796#M3451</guid>
      <dc:creator>Roger Sandström</dc:creator>
      <dc:date>2008-03-27T07:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory and ILO2,  I am almost there!!!!</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165797#M3452</link>
      <description>I have contacted HP support and have not gotten nearly as far as I have from the Forums but one thing they did tell me is that it is not supported i.e dtest. So you will need to login either (in my case) dtest@ad.domain.com or ad.domain.com/dtest.  At least you have the @domain working. I can't even get that far.. I have to use the the CN of Test\, &lt;BR /&gt;&lt;BR /&gt;If I am wrong on this please let me know...</description>
      <pubDate>Thu, 27 Mar 2008 13:20:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165797#M3452</guid>
      <dc:creator>Dan Fitzgerald</dc:creator>
      <dc:date>2008-03-27T13:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory and ILO2,  I am almost there!!!!</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165798#M3453</link>
      <description>One more note for Default Schema:&lt;BR /&gt;Using @domain.com in the user context only &lt;BR /&gt;works with HP Extended Schema  which is what can prevent you from logging in with your user id.</description>
      <pubDate>Thu, 27 Mar 2008 17:30:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165798#M3453</guid>
      <dc:creator>M.S.Srivatsa</dc:creator>
      <dc:date>2008-03-27T17:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory and ILO2,  I am almost there!!!!</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165799#M3454</link>
      <description>Now I am using the the default schema (schema-less) so is HP wrong that I can't use just my user id?</description>
      <pubDate>Thu, 27 Mar 2008 17:47:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/active-directory-and-ilo2-i-am-almost-there/m-p/4165799#M3454</guid>
      <dc:creator>Dan Fitzgerald</dc:creator>
      <dc:date>2008-03-27T17:47:21Z</dc:date>
    </item>
  </channel>
</rss>

