<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ILO Kerberos Sign-In Issues in Server Management - Remote Server Management</title>
    <link>https://community.hpe.com/t5/server-management-remote-server/ilo-kerberos-sign-in-issues/m-p/6978693#M7922</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I tried using this video guide to configure kerberos integration for one of our ILO's:&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=rGnm2Kc10J0" target="_blank"&gt;https://www.youtube.com/watch?v=rGnm2Kc10J0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Unfortunately it does not seem to be working.&amp;nbsp; A diagnostic tests says the following:&lt;/P&gt;&lt;P&gt;Directory Server DNS Name: Success&lt;/P&gt;&lt;P&gt;Ping Directory Server: Success&lt;/P&gt;&lt;P&gt;Connect to Directory Server: Success&lt;/P&gt;&lt;P&gt;Bind to Directory Server: Success&lt;/P&gt;&lt;P&gt;Directory Administrator Login: Success&lt;/P&gt;&lt;P&gt;User Authorization: Success&lt;/P&gt;&lt;P&gt;Directory User Contexts: Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a suspicion that this error is causing my problem:&lt;/P&gt;&lt;P&gt;Connect using SSL&amp;nbsp; Success&amp;nbsp; Certificate subject OK, verify OK, error code 27 (certificate not trusted), Subject /CN=xxxx.xx.xxxx.xxxx Issued By /DC=root/DC=xxxx/CN=XXXCA1&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But - how do I go about making the certificate so that it is trusted?&lt;/P&gt;&lt;P&gt;The ILO already has a certificate installed from the same CA which is used by the Directory Server.&lt;/P&gt;&lt;P&gt;Any clues?&lt;/P&gt;&lt;P&gt;Pete&lt;/P&gt;</description>
    <pubDate>Mon, 02 Oct 2017 14:22:17 GMT</pubDate>
    <dc:creator>Peter J West</dc:creator>
    <dc:date>2017-10-02T14:22:17Z</dc:date>
    <item>
      <title>ILO Kerberos Sign-In Issues</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-kerberos-sign-in-issues/m-p/6978693#M7922</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I tried using this video guide to configure kerberos integration for one of our ILO's:&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=rGnm2Kc10J0" target="_blank"&gt;https://www.youtube.com/watch?v=rGnm2Kc10J0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Unfortunately it does not seem to be working.&amp;nbsp; A diagnostic tests says the following:&lt;/P&gt;&lt;P&gt;Directory Server DNS Name: Success&lt;/P&gt;&lt;P&gt;Ping Directory Server: Success&lt;/P&gt;&lt;P&gt;Connect to Directory Server: Success&lt;/P&gt;&lt;P&gt;Bind to Directory Server: Success&lt;/P&gt;&lt;P&gt;Directory Administrator Login: Success&lt;/P&gt;&lt;P&gt;User Authorization: Success&lt;/P&gt;&lt;P&gt;Directory User Contexts: Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a suspicion that this error is causing my problem:&lt;/P&gt;&lt;P&gt;Connect using SSL&amp;nbsp; Success&amp;nbsp; Certificate subject OK, verify OK, error code 27 (certificate not trusted), Subject /CN=xxxx.xx.xxxx.xxxx Issued By /DC=root/DC=xxxx/CN=XXXCA1&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But - how do I go about making the certificate so that it is trusted?&lt;/P&gt;&lt;P&gt;The ILO already has a certificate installed from the same CA which is used by the Directory Server.&lt;/P&gt;&lt;P&gt;Any clues?&lt;/P&gt;&lt;P&gt;Pete&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2017 14:22:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-kerberos-sign-in-issues/m-p/6978693#M7922</guid>
      <dc:creator>Peter J West</dc:creator>
      <dc:date>2017-10-02T14:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: ILO Kerberos Sign-In Issues</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-kerberos-sign-in-issues/m-p/6978701#M7923</link>
      <description>&lt;P&gt;Just to follow up on this.&lt;/P&gt;&lt;P&gt;It looks like almost everything is working as expected, but for some reason it's not able to confirm that the login being used is a member of the appropriate group.&lt;/P&gt;&lt;P&gt;If I deliberately enter a bad password when doing the test then it fails on many of the tests; but when you enter valid credentials everything passes apart from this:&lt;/P&gt;&lt;P&gt;User Authentication&amp;nbsp; Warning&amp;nbsp; Test user ilotest@xxx.xxx.xxx not authenticated, or does not have login rights.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Quite strange.&amp;nbsp; Any ideas would be welcomed.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2017 15:27:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-kerberos-sign-in-issues/m-p/6978701#M7923</guid>
      <dc:creator>Peter J West</dc:creator>
      <dc:date>2017-10-02T15:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: ILO Kerberos Sign-In Issues</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-kerberos-sign-in-issues/m-p/7087582#M8660</link>
      <description>&lt;P&gt;Try doing these things.&lt;/P&gt;&lt;P&gt;1. log out of the SUT..&lt;/P&gt;&lt;P&gt;2. Clear the DNS&amp;nbsp; Cache at the Server &amp;amp; restart the DNS&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; Now&amp;nbsp; at the SUT&amp;nbsp; use Alt+ Crtl+ Delete &amp;amp; login..&lt;/P&gt;&lt;P&gt;Using Alt+Crtl+ Delete, it will&amp;nbsp;basically&amp;nbsp;create a new Ticket &amp;amp; it will fix the issue..&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make Sure at the iLO , below things must be set correctly.&lt;/P&gt;&lt;P&gt;Refere&amp;nbsp; the link :&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=rGnm2Kc10J0&amp;nbsp;" target="_blank"&gt;https://www.youtube.com/watch?v=rGnm2Kc10J0&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please do check all&amp;nbsp; Time of all Client , Server &amp;amp; ILO must be in sync.. i had this issue if any 1 is not in sync&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 04:30:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-kerberos-sign-in-issues/m-p/7087582#M8660</guid>
      <dc:creator>SandurMavericK</dc:creator>
      <dc:date>2020-05-11T04:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: ILO Kerberos Sign-In Issues</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-kerberos-sign-in-issues/m-p/7091396#M8718</link>
      <description>&lt;P&gt;1. Setup Domain Controller DNS &amp;amp; AD&lt;/P&gt;&lt;P&gt;Create Both Forward Lookup Zone &amp;amp; Reverse Lookup&amp;nbsp; Zone for the Subnets Used for iLO&lt;/P&gt;&lt;P&gt;2. Install the LDAP Role&lt;/P&gt;&lt;P&gt;3. Install the CA ( Root CA or Enterprise CA) - Import the CA Certificate to the windows Clinet Machine &amp;amp; Install the same.&lt;/P&gt;&lt;P&gt;Path : Open Certificate Authorithy --&amp;gt; Right Click --&amp;gt; your CA --&amp;gt; Properties--&amp;gt; View Certificate &amp;amp; Export&lt;/P&gt;&lt;P&gt;4. Set Group Policy at Domain Controller at Default Domain Policy&lt;/P&gt;&lt;P&gt;PATH : Policies --&amp;gt;Windows Settings--&amp;gt;Security Settings---&amp;gt; Local Policies--&amp;gt;&lt;/P&gt;&lt;P&gt;Uncheck All except "AES128_HMAC_SHA1" &amp;amp; AES256_HMAC_SHA1", Future Encryption Types at&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Network Security: Configure Encryption types allowed for Kerberos" ( Security Policy)&lt;/P&gt;&lt;P&gt;5. Now Follow these steps as per the below link :&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=rGnm2Kc10J0&amp;nbsp;" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.youtube.com/watch?v=rGnm2Kc10J0&amp;nbsp; &lt;/A&gt;&lt;/P&gt;&lt;P&gt;For High Security, FIPS &amp;amp; CSNA Generate with Supported Crypto (Command)&lt;BR /&gt;Ktpass +rndPass -ptype KRB5_NT_SRV_HST -princHTTP/myilo.somedomain.net@SOMEDOMAIN.NET -mapuser myilo$@somedomain.net-out myilo.keytab -crypto AES256-SHA1&lt;/P&gt;&lt;P&gt;Note : Date &amp;amp; Time Sync must be same for Domain Conrtoller + iLO + Client Machine.&lt;/P&gt;&lt;P&gt;Note : iLO must resolve with Hostname&lt;/P&gt;&lt;P&gt;Please configure the Browser as below&lt;BR /&gt;1. Enable authentication in Internet Explorer.&lt;BR /&gt;a. Select Tools &amp;gt; Internet options.&lt;BR /&gt;b. Click the Advanced tab.&lt;BR /&gt;c. Scroll to the Security section.&lt;BR /&gt;d. Verify that the Enable Integrated Windows Authentication option is selected.&lt;BR /&gt;e. Click OK.&lt;/P&gt;&lt;P&gt;2. Add the iLO domain to the Intranet zone.&lt;BR /&gt;a. Select Tools &amp;gt; Internet options.&lt;BR /&gt;b. Click the Security tab.&lt;BR /&gt;c. Click the Local intranet icon.&lt;BR /&gt;d. Click the Sites button.&lt;BR /&gt;e. Click the Advanced button.&lt;BR /&gt;f. Enter the site to add in the Add this website to the zone box&lt;BR /&gt;g. On a corporate network, *.example.net is sufficient.&lt;BR /&gt;h. Click Add.&lt;BR /&gt;i. Click Close.&lt;BR /&gt;j. To close the Local intranet dialog box, click OK.&lt;BR /&gt;k. To close the Internet Options dialog box, click OK.&lt;/P&gt;&lt;P&gt;3. Enable the Automatic login only in Intranet zone setting.&lt;BR /&gt;a. Select Tools &amp;gt; Internet options.&lt;BR /&gt;b. Click the Security tab.&lt;BR /&gt;c. Click the Local intranet icon.&lt;BR /&gt;d. Click Custom level.&lt;BR /&gt;e. Scroll to the User Authentication section.&lt;BR /&gt;f. Verify that the Automatic logon only in Intranet zone option is selected.&lt;BR /&gt;g. To close the Security Settings — Local Intranet Zone window, click OK.&lt;BR /&gt;h. To close the Internet Options dialog box, click OK.&lt;/P&gt;&lt;P&gt;4. If any options were changed in steps 1–3, close and restart Internet Explorer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 14:28:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-kerberos-sign-in-issues/m-p/7091396#M8718</guid>
      <dc:creator>SandurMavericK</dc:creator>
      <dc:date>2020-06-12T14:28:53Z</dc:date>
    </item>
  </channel>
</rss>

