<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: iLO LDAP integration letting everyone in!? in Server Management - Remote Server Management</title>
    <link>https://community.hpe.com/t5/server-management-remote-server/ilo-ldap-integration-letting-everyone-in/m-p/6883497#M7812</link>
    <description>&lt;P&gt;I tried again with the latest iLO 2.44. Still no luck, it's letting everyone in with their domain creds. Oh well.&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jul 2016 15:45:34 GMT</pubDate>
    <dc:creator>wreigle</dc:creator>
    <dc:date>2016-07-29T15:45:34Z</dc:date>
    <item>
      <title>iLO LDAP integration letting everyone in!?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-ldap-integration-letting-everyone-in/m-p/6877140#M7804</link>
      <description>&lt;P&gt;I have configured iLO with LDAP directory integration. I am able to successfully login to iLO using my AD credentials. However, other AD users are also able to login to iLO. Users who are NOT in the "iloadmins" security group shown below are able to successfully login to iLO.&lt;/P&gt;&lt;P&gt;Settings I am using:&lt;BR /&gt;Administration &amp;gt; Security &amp;gt; Directory&lt;BR /&gt;"User Directory Default Schema"&lt;BR /&gt;Directory Server Address: &amp;lt;FQDN of AD server&amp;gt;&lt;BR /&gt;Port: 636&lt;BR /&gt;Directory User Context 1:&amp;nbsp;OU=groups,OU=employees,DC=contoso,DC=dc,DC=com&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Administration &amp;gt; User Administration&lt;BR /&gt;Directory Groups:&amp;nbsp;CN=iloadmins,OU=groups,OU=employees,DC=&lt;SPAN&gt;contoso&lt;/SPAN&gt;&lt;SPAN&gt;,DC=&lt;/SPAN&gt;&lt;SPAN&gt;dc&lt;/SPAN&gt;&lt;SPAN&gt;,DC=com&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2016 17:21:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-ldap-integration-letting-everyone-in/m-p/6877140#M7804</guid>
      <dc:creator>wreigle1</dc:creator>
      <dc:date>2016-07-11T17:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: iLO LDAP integration letting everyone in!?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-ldap-integration-letting-everyone-in/m-p/6877576#M7805</link>
      <description>&lt;P&gt;Go to "&lt;SPAN&gt;Administration-&amp;gt;User Administration" &amp;nbsp;and remove the "Authenticated Users" from the Directory Groups.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2016 17:39:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-ldap-integration-letting-everyone-in/m-p/6877576#M7805</guid>
      <dc:creator>Oscar A. Perez</dc:creator>
      <dc:date>2016-07-12T17:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: iLO LDAP integration letting everyone in!?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-ldap-integration-letting-everyone-in/m-p/6877580#M7806</link>
      <description>&lt;P&gt;Thanks for the suggestion Oscar but that did not resolve my issue. I deleted the Autehnticated Users group all together. &amp;nbsp;Another user was still able to login to iLO.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2016 17:49:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-ldap-integration-letting-everyone-in/m-p/6877580#M7806</guid>
      <dc:creator>wreigle</dc:creator>
      <dc:date>2016-07-12T17:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: iLO LDAP integration letting everyone in!?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-ldap-integration-letting-everyone-in/m-p/6878314#M7807</link>
      <description>&lt;P&gt;Any other ideas here? A bug in iLO 4 (version 2.40)?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 13:15:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-ldap-integration-letting-everyone-in/m-p/6878314#M7807</guid>
      <dc:creator>wreigle</dc:creator>
      <dc:date>2016-07-14T13:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: iLO LDAP integration letting everyone in!?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-ldap-integration-letting-everyone-in/m-p/6883497#M7812</link>
      <description>&lt;P&gt;I tried again with the latest iLO 2.44. Still no luck, it's letting everyone in with their domain creds. Oh well.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 15:45:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-ldap-integration-letting-everyone-in/m-p/6883497#M7812</guid>
      <dc:creator>wreigle</dc:creator>
      <dc:date>2016-07-29T15:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: iLO LDAP integration letting everyone in!?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-ldap-integration-letting-everyone-in/m-p/6884998#M7813</link>
      <description>&lt;P&gt;Every time we get a case like this, it ends up being caused by a misconfiguration. Like for example, the&amp;nbsp;iLO&amp;nbsp;group you've created is inheriting permissions from other groups or, there are nested groups associated with this iLO group. &amp;nbsp; If user "Bob", for example, is a member of such groups, he will be able to login to iLO.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please have a hard look at how your AD groups are setup and check for all "effective"&amp;nbsp;permissions user "Bob" has.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2016 13:52:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-ldap-integration-letting-everyone-in/m-p/6884998#M7813</guid>
      <dc:creator>Oscar A. Perez</dc:creator>
      <dc:date>2016-08-03T13:52:03Z</dc:date>
    </item>
  </channel>
</rss>

