Users Guide
Conguring IPMI over LAN using RACADM......................................................................................................... 126
Enabling or disabling remote RACADM........................................................................................................................126
Enabling or disabling remote RACADM using web interface...............................................................................126
Enabling or disabling remote RACADM using RACADM......................................................................................127
Disabling local RACADM................................................................................................................................................ 127
Enabling IPMI on managed system...............................................................................................................................127
Conguring Linux for serial console during boot.........................................................................................................127
Enabling login to the virtual console after boot.................................................................................................... 128
Supported SSH cryptography schemes...................................................................................................................... 129
Using public key authentication for SSH...............................................................................................................130
7 Conguring user accounts and privileges....................................................................................................134
Recommended characters in user names and passwords........................................................................................ 134
Conguring local users...................................................................................................................................................135
Conguring local users using iDRAC web interface............................................................................................. 135
Conguring local users using RACADM.................................................................................................................135
Conguring Active Directory users...............................................................................................................................137
Prerequisites for using Active Directory authentication for iDRAC....................................................................138
Supported Active Directory authentication mechanisms.................................................................................... 140
Standard schema Active Directory overview........................................................................................................140
Conguring Standard schema Active Directory.................................................................................................... 141
Extended schema Active Directory overview....................................................................................................... 143
Conguring Extended schema Active Directory...................................................................................................145
Testing Active Directory settings............................................................................................................................153
Conguring generic LDAP users...................................................................................................................................154
Conguring generic LDAP directory service using iDRAC web-based interface..............................................154
Conguring generic LDAP directory service using RACADM............................................................................. 155
Testing LDAP directory service settings................................................................................................................155
8 Conguring iDRAC for Single Sign-On or smart card login......................................................................... 157
Prerequisites for Active Directory Single Sign-On or smart card login.................................................................... 157
Registering iDRAC as a computer in Active Directory root domain................................................................... 158
Generating Kerberos keytab le............................................................................................................................. 158
Creating Active Directory objects and providing privileges.................................................................................159
Conguring iDRAC SSO login for Active Directory users..........................................................................................159
Conguring iDRAC SSO login for Active Directory users using web interface.................................................159
Conguring iDRAC SSO login for Active Directory users using RACADM........................................................160
Conguring iDRAC smart card login for local users................................................................................................... 160
Uploading smart card user certicate....................................................................................................................160
Uploading trusted CA certicate for smart card...................................................................................................161
Conguring iDRAC smart card login for Active Directory users................................................................................161
Enabling or disabling smart card login...........................................................................................................................161
Enabling or disabling smart card login using web interface.................................................................................162
Enabling or disabling smart card login using RACADM........................................................................................162
Enabling or disabling smart card login using iDRAC settings utility....................................................................162
Contents
7