◦ When the HighSecurity or FIPS security state is enabled, a 2048-bit certificate is required.
◦ When the SuiteB security state is enabled, a certificate containing a 3072-bit RSA key or a 384-
bit ECDSA key with NIST P-384 curve is required.
The list of trusted servers is not used when SSO is disabled. iLO does not enforce SSO server
certificate revocation.
Single Sign-On Trust Mode options
The
Single Sign-On Trust Mode
affects how iLO responds to HPE SSO requests.
•
Trust None (SSO disabled)
(default)—Rejects all SSO connection requests.
•
Trust by Certificate
(most secure)—Enables SSO connections from an HPE SSO-compliant
application by matching a certificate previously imported to iLO.
•
Trust by Name
—Enables SSO connections from an HPE SSO-compliant application by matching a
directly imported IP address or DNS name.
•
Trust All
(least secure)—Accepts any SSO connection initiated from any HPE SSO-compliant
application.
SSO user privileges
When you log in to an HPE SSO-compliant application, you are authorized based on your HPE SSO-
compliant application role assignment. The role assignment is passed to iLO when SSO is attempted.
SSO attempts to receive only the privileges assigned in the
Single Sign-On Settings
section. iLO
directory settings do not apply.
The default privilege settings follow:
•
User
—Login only
•
Operator
—Login, Remote Console, Virtual Power and Reset, Virtual Media, Host BIOS.
•
Administrator
—Login, Remote Console, Virtual Power and Reset, Virtual Media, Host BIOS,
Configure iLO Settings, Administer User Accounts, Host NIC, and Host Storage.
Adding trusted certificates
The certificate repository can hold five typical certificates. However, if typical certificates are not issued,
certificate sizes might vary. When all allocated storage is used, no more imports are accepted.
For information about how to extract a certificate from an HPE SSO-compliant application, see your HPE
SSO-compliant application documentation.
Prerequisites
Configure iLO Settings privilege
266
Single Sign-On Trust Mode options