Manuals

Manuals
Enabling Kerberos Authentication : Dell Remote Access Controller 5 Firmware Version 1.40 User's Guide

Back to Contents Page

Enabling Kerberos Authentication

Dell™ Remote Access Controller 5 Firmware Version 1.40 User's Guide

  Prerequisites for Single Sign-On and Active Directory Authentication Using Smart Card

  Configuring the DRAC 5 for Single Sign-On and Active Directory Authentication Using Smart Card

  Logging Into the DRAC 5 Using Single Sign-On


Kerberos is a network authentication protocol that allows systems to communicate securely over a non-secure network. It achieves this by allowing the systems to prove their authenticity.

Microsoft® Windows® 2000, Windows XP, Windows Server® 2003, Windows Vista®, and Windows Server 2008 use Kerberos as their default authentication method.

Starting with DRAC 5 version 1.40, the DRAC 5 uses Kerberos to support two types of authentication mechanisms—single sign-on and Active Directory Smart Card login.

For the single-sign on, the DRAC 5 uses the user credentials cached in the operating system after the user has logged in using a valid Active Directory account.

Starting with DRAC 5 version 1.40, Active Directory authentication will use the Smart Card-based two factor authentication (TFA) in addition to the username-password combination, as valid credentials.


Prerequisites for Single Sign-On and Active Directory Authentication Using Smart Card

  • Configure the DRAC 5 for Active Directory login. For more information, see "Using Active Directory to Log Into the DRAC 5."

  • Register the DRAC 5 as a computer in the Active Directory root domain.

    1. Navigate to Remote AccessConfiguration tab→ Network subtab→ Network Settings.

    1. Provide a valid Preferred/Static DNS Server IP address. This value is the IP address of the DNS that is part of the root domain, which authenticates the Active Directory accounts of the users.

    2. Select Register DRAC on DNS.

    3. Provide a valid DNS Domain Name.

See the DRAC 5 Online Help for more information.

Since the DRAC 5 is a device with a non-Windows operating system, run the ktpass utility—part of Microsoft® Windows®—on the Domain Controller (Active Directory server) where you want to map the DRAC 5 to a user account in Active Directory. For example,

C:\>ktpass -princ HOST/dracname.domain-name.com@domain-name.COM -mapuser dracname -crypto DES-CBC-MD5 -ptype KRB5_NT_PRINCIPAL -pass * -out c:\krbkeytab

NOTE: The cryptography type that DRAC 5 supports for Kerberos authentication is DES-CBC-MD5.

This procedure will produce a keytab file that you should upload to the DRAC 5.

NOTE: The keytab contains an encryption key and should be kept secure.

For more information on the ktpass utility, see the Microsoft website at: http://technet2.microsoft.com/windowsserver/en/library/64042138-9a5a-4981-84e9-d576a8db0d051033.mspx?mfr=true

  • The DRAC 5 time should be synchronized with the Active Directory domain controller.


Configuring the DRAC 5 for Single Sign-On and Active Directory Authentication Using Smart Card

Upload the keytab obtained from the Active Directory root domain, to the DRAC 5:

  1. Navigate to Remote AccessConfiguration tab→ Active Directory subtab.

  2. Select Upload Kerberos Keytab and click Next.

  3. On the Kerberos Keytab Upload page, navigate to the folder where you saved the keytab and click Upload.


Logging Into the DRAC 5 Using Single Sign-On

NOTE: To log into the DRAC 5, ensure that you have the latest runtime components of Microsoft Visual C++ 2005 Libraries. For more information, see the Microsoft website.
  1. Log into your system using a valid Active Directory account.

  2. Type the web address of the DRAC 5 in the address bar of your browser.

NOTE: Depending on your browser settings, you may be prompted to download and install the Single Sign-On ActiveX plug-in when using this feature for the first time.

You are logged into the DRAC 5.


Back to Contents Page

 

Laptops | Desktops | Business Laptops | Business Desktops | Workstations | Servers | Storage | Services | Monitors | Printers | LCD TVs | Electronics
© 2012 Dell | About Dell | Terms & Conditions | Unresolved Issues | Privacy Statement | Ads and Emails | Dell Recycling | Contact | Site Map | Feedback
AT | AU | BE | BR | CA | CH | CL | CN | CO | DE | DK | ES | FR | HK | IE | IN | IT | JP | KR | ME | MX | MY | NL | NO | PA | PR | RU | SE | SG | UK | VE | ALL

snEB14