Enabling Kerberos Authentication
167
Enabling Kerberos Authentication
Kerberos is a network authentication protocol that allows systems to
communicate securely over a non-secure network. It achieves this by allowing
the systems to prove their authenticity. To keep with the higher
authentication enforcement standards, iDRAC6 now supports Kerberos based
Active Directory
®
authentication to support Active Directory Smart Card
and single sign-on (SSO) logins.
Microsoft
®
Windows
®
2000, Windows XP, Windows Server
®
2003,
Windows Vista
®
, and Windows Server 2008 use Kerberos as their default
authentication method.
iDRAC6 uses Kerberos to support two types of authentication mechanisms—
Active Directory single sign-on and Active Directory Smart Card logins. For
single-sign on login, iDRAC6 uses the user credentials cached in the
operating system after the user has logged in using a valid Active Directory
account.
For Active Directory smart card login, iDRAC6 uses smart card-based two
factor authentication (TFA) as credentials to enable an Active Directory
login.
Kerberos authentication on iDRAC6 fails if iDRAC6 time differs from the
Domain Controller time. A maximum offset of 5 minutes is allowed. To
enable successful authentication, synchronize the server time with the
Domain Controller time and then
reset
iDRAC6.
You can also use the following RACADM time zone offset command to
synchronize the time:
racadm config -g cfgRacTuning -o
cfgRacTuneTimeZoneOffset <offset value>
Содержание IDRAC6
Страница 1: ...Integrated Dell Remote Access Controller 6 iDRAC6 Enterprise for Blade Servers Version 2 1 User Guide ...
Страница 38: ...38 iDRAC6 Enterprise Overview ...
Страница 84: ...84 Configuring the Managed Server ...
Страница 120: ...120 Configuring iDRAC6 Enterprise Using the Web Interface ...
Страница 160: ...160 Using iDRAC6 With Microsoft Active Directory ...
Страница 166: ...166 Configuring Smart Card Authentication ...
Страница 222: ...222 Using GUI Console Redirection ...
Страница 228: ...228 Configuring the vFlash Media Card for Use With iDRAC6 ...
Страница 270: ...270 Using the RACADM Command Line Interface ...
Страница 308: ...308 Using iDRAC6 Configuration Utility ...
Страница 334: ...334 Recovering and Troubleshooting the Managed System ...
Страница 382: ...382 RACADM Subcommand Overview ...
Страница 452: ...452 iDRAC6 Enterprise Property Database Group and Object Definitions ...
Страница 462: ...462 Glossary ...
Страница 472: ...472 Index ...