Verifying the single sign-on (Zero Sign In) configuration
Procedure
1. Navigate to the iLO login page (for example, http://iloname.example.net).
2. Click the Zero Sign In button.
Verifying that login by name works
Procedure
1. Navigate to the iLO login page.
2. Enter the user name in the Kerberos UPN format (for example, user@EXAMPLE.NET).
3. Enter the associated domain password.
4. Click Log In.
Directory integration
Using a directory with iLO provides the following benefits:
• Scalability—The directory can be leveraged to support thousands of users on thousands of iLO
processors.
• Security—Robust user-password policies are inherited from the directory. User-password complexity,
rotation frequency, and expiration are policy examples.
• User accountability—In some environments, users share iLO accounts, which makes it difficult to
determine who performed an operation.
• Role-based administration (HPE Extended Schema configuration)—You can create roles (for
example, clerical, remote control of the host, complete control) and associate them with users or user
groups. A change to a single role applies to all users and iLO devices associated with that role.
• Single point of administration (HPE Extended Schema configuration)—You can use native
administration tools like MMC to administer iLO users.
• Immediacy—A single change in the directory rolls out immediately to associated iLO processors. This
feature eliminates the need to script this process.
• Simpler credentials—You can use existing user accounts and passwords in the directory without
having to record a new set of credentials for iLO.
• Flexibility (HPE Extended Schema configuration)—You can create a single role for a single user on a
single iLO processor, a single role for multiple users on multiple iLO processors, or a combination of
roles suited to your enterprise. With the HPE Extended Schema configuration, access can be limited
to a time of day or a certain range of IP addresses.
• Compatibility—iLO directory integration supports Active Directory and OpenLDAP.
• Standards—iLO directory support is based on the LDAP 2.0 standard for secure directory access. iLO
Kerberos support is based on LDAP v3.
312 Verifying the single sign-on (Zero Sign In) configuration