Installation Manual

To configure iDRAC7 for smart card login:
1. In iDRAC7 Web interface, while configuring Active Directory to set up an user account based on standard schema
or extended schema, on the Active Directory Configuration and Management Step 1 of 4 page:
Enable certificate validation.
Upload a trusted CA-signed certificate.
Upload the keytab file.
2. Enable smart card login. For information about the options, see the
iDRAC7 Online Help
.
Related Links
Enabling or Disabling Smart Card Login
Obtaining Certificates
Generating Kerberos Keytab File
Configuring Active Directory With Standard Schema Using iDRAC7 Web Interface
Configuring Active Directory With Standard Schema Using RACADM
Configuring Active Directory With Extended Schema Using iDRAC7 Web Interface
Configuring Active Directory With Extended Schema Using RACADM
Enabling or Disabling Smart Card Login
Before enabling or disabling smart card login for iDRAC7, make sure that:
You have configure iDRAC7 permissions.
iDRAC7 local user configuration or Active Directory user configuration with the appropriate certificates is complete.
NOTE: If smart card login is enabled, then SSH, Telnet, IPMI Over LAN, Serial Over LAN, and remote RACADM are
disabled. Again, if you disable smart card login, the interfaces are not enabled automatically.
Related Links
Obtaining Certificates
Configuring iDRAC7 Smart Card Login for Active Directory Users
Configuring iDRAC7 Smart Card Login for Local Users
Enabling or Disabling Smart Card Login Using Web Interface
To enable or disable the Smart Card logon feature:
1. In the iDRAC7 Web interface, go to OverviewiDRAC SettingsUser AuthenticationSmart Card .
The Smart Card page is displayed.
2. From the Configure Smart Card Logon drop-down menu, select Enabled to enable smart card logon or select
Enabled With Remote RACADM. Else, select Disabled.
For more information about the options, see the
iDRAC7 Online Help
.
3. Click Apply to apply the settings.
You are prompted for a Smart Card login during any subsequent logon attempts using the iDRAC7 Web interface.
Enabling or Disabling Smart Card Login Using RACADM
To enable smart card login, use one of the following:
Use the objects in the cfgSmartCard group with the config command.
152