Servers - General
1758418 Members
2763 Online
108870 Solutions
New Discussion юеВ

Re: iLO 5 Directory Authentication with Smartcards/Certificates

 
blainemiller
Occasional Visitor

iLO 5 Directory Authentication with Smartcards/Certificates

Hello all,

I can find documentation about how to use LDAP Directory authentication for iLO 5. I can find documentation about how to use a smart card/certificate to login to a local account in iLO 5. There is almost no documentation about how to use smart cards/certificates to authenticate to a Directory account.

Does anyone have experience setting up LDAP Directory authentication in a passwordless directory? Any information would be helpful. I have been to verify that LDAP communication is working, but when I try to log in with a certificate, it just get a non-descript error. 

I see that in the LDAP settings there is a spot for a name and password. Is this required for smart card auth?

6 REPLIES 6
support_s
System Recommended

Query: iLO 5 Directory Authentication with Smartcards/Certificates

System recommended content:

1. HPE iLO 5 3.03 User Guide | Directory authentication and authorization settings in iLO

2. HPE iLO 6 1.58 User Guide | Directory authentication and authorization settings in iLO

 

Please click on "Thumbs Up/Kudo" icon to give a "Kudo".

 

Thank you for being a HPE valuable community member.


Accept or Kudo

shuff
Frequent Advisor

Re: iLO 5 Directory Authentication with Smartcards/Certificates

To set up LDAP Directory authentication with smart cards/certificates, you need to configure schema-free directory settings in iLO: https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00105236en_us&page=GUID-D7147C7F-2016-0901-06D0-000000000D16.html

blainemiller
Occasional Visitor

Re: iLO 5 Directory Authentication with Smartcards/Certificates

This page is helpful but it does not explain how to set up the iLO Object Distinguished Name CAC LDAP Service Account. Do you know what is involved in setting it up? Can it be any service account or does it need cert-specific delegation enabled?

shuff
Frequent Advisor

Re: iLO 5 Directory Authentication with Smartcards/Certificates

I've only ever used a CAC LDAP service account and password for iLO Object Distinguished Name CAC LDAP Service Account and iLO Object Password boxes

blainemiller
Occasional Visitor

Re: iLO 5 Directory Authentication with Smartcards/Certificates

How did you create the service account that you listed in the iLO Object Distinguished Name CAC LDAP Service Account box?

shuff
Frequent Advisor

Re: iLO 5 Directory Authentication with Smartcards/Certificates

no idea since I don't have permissions to create it in our env, just use it