Creating Active Directory Objects and Providing Privileges
Perform the following steps for Active Directory Extended schema based SSO login:
1.
Create the device object, privilege object, and association object in the Active Directory server.
2.
Set access privileges to the created privilege object. It is recommended not to provide administrator privileges as
this could bypass some security checks.
3.
Associate the device object and privilege object using the association object.
4.
Add the preceding SSO user (login user) to the device object.
5.
Provide access privilege to
Authenticated Users
for accessing the created association object.
Related Links
Adding iDRAC7 Users and Privileges to Active Directory
Configuring Browser to Enable Active Directory SSO
This section provides the browser settings for Internet Explorer and Firefox to enable Active Directory SSO.
NOTE: Google Chrome and Safari do not support Active Directory for SSO login.
Configuring Internet Explorer to Enable Active Directory SSO
To configure the browser settings for Internet Explorer:
1.
In Internet Explorer, navigate to Local Intranet and click Sites.
2.
Select the following options only:
– Include all local (intranet) sites not listed on other zones.
– Include all sites that bypass the proxy server.
3.
Click Advanced.
4.
Add all relative domain names that will be used for iDRAC7 instances that is part of the SSO configuration (for
example, myhost.example.com.)
5.
Click Close and click OK twice.
Configuring Firefox to Enable Active Directory SSO
To configure the browser settings for Firefox:
1.
In Firefox address bar, enter
about:config
.
2.
In Filter, enter
network.negotiate
.
3.
Add the iDRAC7 name to network.negotiate-auth.trusted-uris (using comma separated list.)
4.
Add the iDRAC7 name to network.negotiate-auth.delegation-uris (using comma separated list.)
Configuring iDRAC7 SSO Login for Active Directory Users
Before configuring iDRAC7 for Active Directory SSO login, make sure that you have completed all the prerequisites.
You can configure iDRAC7 for Active Directory SSO when you setup an user account based on Active Directory.
Related Links
Prerequisites for Active Directory Single Sign-On or Smart Card Login
Configuring Active Directory With Standard Schema Using iDRAC7 Web Interface
Configuring Active Directory With Standard Schema Using RACADM
147
Summary of Contents for iDRAC7
Page 1: ...Integrated Dell Remote Access Controller 7 iDRAC7 Version 1 50 50 User s Guide ...
Page 14: ...14 ...
Page 36: ...36 ...
Page 66: ...66 ...
Page 92: ...92 ...
Page 144: ...144 ...
Page 165: ...165 ...
Page 166: ...166 ...
Page 172: ...172 ...
Page 184: ...184 ...
Page 196: ...196 ...
Page 208: ...208 ...
Page 216: ...216 ...
Page 220: ...220 ...
Page 234: ...234 ...
Page 248: ...248 ...