<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: iLO Directory CA certificate issue - no AD login possible in Server Management - Remote Server Management</title>
    <link>https://community.hpe.com/t5/server-management-remote-server/ilo-directory-ca-certificate-issue-no-ad-login-possible/m-p/7022272#M8185</link>
    <description>&lt;P&gt;Hi Lulu,&lt;/P&gt;&lt;P&gt;If you have performed a reset of the ILO from ILO itself then it is not a factory reset.&amp;nbsp;&amp;nbsp;Please use the Intelligent Provisioning&amp;gt;Perform Maintenance&amp;gt;ILO configuration&amp;gt;Reset&amp;gt;Factory Reset to perform the factory reset. But please make sure that you backup/copy all the license and necessary information.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the issue persists then contact us by logging a case on the below portal:-&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.hpe.com/hpesc/public/home" target="_blank"&gt;https://support.hpe.com/hpesc/public/home&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Bunsol.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Oct 2018 09:19:35 GMT</pubDate>
    <dc:creator>Bunsol</dc:creator>
    <dc:date>2018-10-18T09:19:35Z</dc:date>
    <item>
      <title>iLO Directory CA certificate issue - no AD login possible</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-directory-ca-certificate-issue-no-ad-login-possible/m-p/7022196#M8184</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I (mistakenly) imported a domain controller AD certificate in the iLO of one of my servers (DL380p G8, iLO 4 2.61)&lt;/P&gt;&lt;P&gt;Security &amp;gt; Directory &amp;gt; scroll all the way down, Certificate Status &amp;gt; Import&lt;/P&gt;&lt;P&gt;And now AD authentication doesn't work anymore..&lt;/P&gt;&lt;P&gt;There is very very little documentation about&amp;nbsp;this "Directory Server CA Certificate" online.&lt;/P&gt;&lt;P&gt;The only information I have is from the iLO's help itself:&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;[...]&lt;BR /&gt;9. Optional: Import a new CA certificate.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;a. Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="bold"&gt;&lt;STRONG&gt;Import&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="bold"&gt;&lt;STRONG&gt;Certificate Status&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;text box.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;b. Paste the Base64-encoded X.509 certificate data into the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guilabel"&gt;&lt;STRONG&gt;Import Certificate&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;window, and then click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="bold"&gt;&lt;STRONG&gt;Import&lt;/STRONG&gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;10. Optional: Replace an existing CA certificate.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;a. Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="bold"&gt;&lt;STRONG&gt;View&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="bold"&gt;&lt;STRONG&gt;Certificate Status&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;text box.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;b. Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guibutton"&gt;&lt;STRONG&gt;New&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guilabel"&gt;&lt;STRONG&gt;Certificate Details&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;window.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;c. Paste the Base64-encoded X.509 certificate data into the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guilabel"&gt;&lt;STRONG&gt;Import Certificate&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;window, and then click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="bold"&gt;&lt;STRONG&gt;Import&lt;/STRONG&gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;11. To test the communication between the directory server and iLO, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guilabel"&gt;&lt;STRONG&gt;Test Settings&lt;/STRONG&gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;[...]&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;EM&gt;Directory Server CA Certificate&lt;/EM&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;EM&gt;During LDAP authentication, iLO validates the directory server certificate if the CA certificate is already imported. For successful certificate validation, make sure that you import the correct CA certificate. If certificate validation fails, iLO login is denied and an iLO event is logged. If no CA certificate is imported, the directory server certificate validation step is skipped.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;To verify SSL communication between the directory server and iLO, click&amp;nbsp;&lt;SPAN class="bold"&gt;&lt;STRONG&gt;Test Settings&lt;/STRONG&gt;&lt;/SPAN&gt;.&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm now trying to delete this imported certificate but I can't manage to find how to do that.&lt;BR /&gt;Nowhere in the iLO you have the option to delete this certificate, you can only import another one.&lt;BR /&gt;I've tried to reset the iLO to factory defaults but the certificate remains.&lt;BR /&gt;The cli doesn't give me the option to delete the certificate neither.&lt;/P&gt;&lt;P&gt;It used to work without certificate, and as mentioned in the iLO's help:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;If no CA certificate is imported, the directory server certificate validation step is skipped.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;However now that there's a certificate&amp;nbsp;the directory server certificate validation&amp;nbsp;is always checking the imported certificate which obviously doesn't work and AD auth. fails.&lt;/P&gt;&lt;P&gt;I'd like to rollback to the previous config where there was no certificate, does anyone know how to do this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 18:47:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-directory-ca-certificate-issue-no-ad-login-possible/m-p/7022196#M8184</guid>
      <dc:creator>lulu62</dc:creator>
      <dc:date>2018-10-17T18:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: iLO Directory CA certificate issue - no AD login possible</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-directory-ca-certificate-issue-no-ad-login-possible/m-p/7022272#M8185</link>
      <description>&lt;P&gt;Hi Lulu,&lt;/P&gt;&lt;P&gt;If you have performed a reset of the ILO from ILO itself then it is not a factory reset.&amp;nbsp;&amp;nbsp;Please use the Intelligent Provisioning&amp;gt;Perform Maintenance&amp;gt;ILO configuration&amp;gt;Reset&amp;gt;Factory Reset to perform the factory reset. But please make sure that you backup/copy all the license and necessary information.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the issue persists then contact us by logging a case on the below portal:-&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.hpe.com/hpesc/public/home" target="_blank"&gt;https://support.hpe.com/hpesc/public/home&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Bunsol.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Oct 2018 09:19:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-directory-ca-certificate-issue-no-ad-login-possible/m-p/7022272#M8185</guid>
      <dc:creator>Bunsol</dc:creator>
      <dc:date>2018-10-18T09:19:35Z</dc:date>
    </item>
  </channel>
</rss>

