User guide
Using directory services integration 189
2.
Click Add. The Enter Key dialog box appears.
3. Enter 387S9-M3228-JRM85-D2RZQ-NK8JR.
4. Click OK.
-or-
Click Cancel to exit without saving changes.
Configuring LDAP parameters
There are differences between the LDAP-based access controls used by console switches and Kerberos-
based access control that Windows® uses by default when users log in to workstations and servers. Some
of the user account properties in Active Directory apply only to Kerberos, while some apply to both
Kerberos and the LDAP-based access controls used by console switches. For example, configurable user
restrictions, like the "Log On To," "Logon Hours," and "Managed By" features, in Active Directory do not
apply to console switches and their attached servers. Other features, like user account expiration, user
account lockout, and the capability to disable a user account, do apply to console switches and attached
serves (subject to configuration of associated parameters in Active Directory). Because of the complexity
of Active Directory, it is always useful to run test cases to confirm it is correctly configured to enforce the
desired security policy. It is important to remember that LDAP cannot access the ACL data used by
Windows® to make its access control decisions. HP recommends following the configuration guidance
provided by this user guide. Configurations outside that guidance are not supported.
If individual user accounts are stored on an LDAP-enabled Directory server, such as Active Directory, you
can use the Directory service to authenticate users.
The settings made in the Authentication subcategory enable you to configure your authentication
configuration parameters. The HP IP Console Viewer sends the user name, password, and other
information to the console switch, which then determines whether the HP IP Console Viewer user has
permission to view or change configuration parameters for the console switch in the HP IP Console Viewer
main window.
CAUTION: Unless otherwise specified, use the LDAP default values unless Active Directory has been
reconfigured. Modifying the default values might cause LDAP server communication errors.
There are three tabs for configuring LDAP parameters.