1. Follow the procedure for “Configuring LDAP Extended Schema” (page 74), but omit Step
8. It is not necessary to enter a new port number.
2. Set up directory security groups.
Setting Up Directory Security Groups
The following procedure describes how to set up directory security groups in schema-free LDAP
using the iLO 2 MP TUI. To use the web interface, see “Group Accounts” (page 140).
NOTE: Due to command syntax changes in schema-free LDAP, some customer-developed
scripts may not run. You must change any scripts you developed to enable them to run with the
new schema-free LDAP syntax.
NOTE: You must select the default schema from the LDAP command for the schema-free LDAP
settings to work.
To set up directory security groups, follow these steps.
1. At the MP:CM> prompt, enter LDAP. The screen displays the current LDAP options.
[hqgstlb3] MP:CM> ldap
LDAP
Current LDAP options:
D - Directory settings
G - Security Group Administration
2. Enter G. The current group configuration appears.
Enter menu item or [Q] to Quit:G
Current Group Configuration:
Group Names Group Distinguished Names Access Rights
--------------------------------------------------------------------------
1 - Administrator C, P, M, U
2 - User C, P
3 - Custom1 None
4 - Custom2 None
5 - Custom3 None
6 - Custom4 None
Only the first 30 characters of the Group Distinguished Names are displayed.
Enter number to view or modify, or [Q] to Quit:
3. Enter the number for the group you want to view or modify. The current LDAP group
settings appear.
4. Set up a group distinguished name.
5. Select rights for the group.
6. Enter Y to confirm.
Login Process Using Directory Services Without Schema Extensions
You can control access to iLO 2 using directories without schema extensions. iLO 2 acquires the
user name to determine group membership from the directory. iLO 2 then cross-references the
group names with its locally stored names to determine user privilege level. iLO 2 must be
configured with the appropriate group names and their associated privileges. To configure iLO
2, use one of the following methods:
• Web GUI (Administration > Directory Settings > Group Administration page)
• iLO 2 MP TUI (LDAP command)
Configuring Schema-Free LDAP 77