HP Integrated Lights-Out 2 User Guide

Table Of Contents
Depending on the server, the iLO 2 Security Override Switch might be a single jumper or a specific
switch position on a dip switch panel. To access and locate the iLO 2 Security Override Switch,
see the server documentation. The iLO 2 Security Override Switch can also be located using the
diagrams on the server access panel.
Trusted Platform Module support
TPM is a hardware based system security feature. It is a computer chip that securely stores artifacts
used to authenticate the platform. These artifacts can include passwords, certificates, or encryption
keys. You can also use a TPM to store platform measurements to help ensure that the platform
remains trustworthy. iLO 2 provides support for the TPM mezzanine module in ProLiant 100, 300,
and 500 series servers.
On a supported system, iLO 2 decodes the TPM record and passes the configuration status to iLO
2, CLP, and XML interface. The System Status page displays the TPM configuration status. If the
host system or System ROM does not support TPM, TPM Status is not displayed in Status Summary
page. The Status Summary displays the following TPM status information:
Not Present – A TPM module is not installed.
Present – when:
A TPM module is installed but it is disabled.
A TPM module is installed and enabled.
A TPM module is installed, enabled, and Expansion ROM measuring is enabled. If
Expansion ROM measuring is enabled, the Update iLO 2 Firmware page displays a legal
warning message when you click Send firmware image.
User accounts and access
The iLO 2 firmware supports the configuration of up to 12 local user accounts. Each of these
accounts can be managed through the use of the following features:
“Privileges” (page 43)
“Login security” (page 44)
The iLO 2 firmware iLO 2 can be configured to use a directory to authenticate and authorize its
users. This configuration enables a virtually unlimited number of users, and easily scales to the
number of Lights-Out devices in an enterprise. Additionally, the directory provides a central point
of administration for Lights-Out devices and users, and the directory can enforce a stronger password
policy. iLO 2 enables you to use local users, directory users, or both.
Two configuration options are available:
To use a directory that has been extended with HP Schema, see “Setting up HP schema
directory integration” (page 136).
To use the directory default schema (schema-free), see “Setting up Schema-free directory
integration” (page 132).
Privileges
The iLO 2 firmware enables the administrator to control user account access to iLO 2 functions
through the use of privileges. When a user attempts to use a function, the iLO 2 system verifies
that the user has the privilege before the user is allowed to perform the function.
Each feature available through iLO 2 can be controlled through privileges, including Administer
User Accounts, Remote Console Access, Virtual Power and Reset, Virtual Media, and Configure
iLO 2 Settings. Privileges for each user can be configured on the User Administration page of the
Administration tab.
Security 43