Configuring the Kerberos Parameters on the iBMC
Scenario
Configure the Kerberos function on User & Security > Kerberos of the iBMC WebUI.
The Kerberos function enables Kerberos users to access the iBMC.
- Kerberos is a network authentication protocol that provides powerful authentication services for client or server applications using the key system.
- The iBMC only provides an access interface for Kerberos user.
- The security policies (password complexity check, password validity period, minimum password age, previous passwords disallowed, and inactive timelimit, and user lockout policy) configured on the authentication server apply to the Kerberos users attempting to log in to the iBMC.
Prerequisites
Data
- Kerberos server information, including the Kerberos server address, realm name, and Kerberos user group name
- Key table file generated for the iBMC on the Windows AD. For details about how to generate a key table, see 8 in iBMC Configuring the Directory Server.
- Password for logging in to the iBMC WebUI
Procedure
- Configure the iBMC host name and domain name.
The host name and domain name must be the same as the host name and domain name configured for the AD domain service. For details about how to configure the host name for the AD domain service, see in 8 in iBMC Configuring the Directory Server.
- Log in to the iBMC WebUI. For details, see .
- Configure the iBMC host name and DNS settings. For details, see Configuring the DNS on the iBMC WebUI.
- Configure the iBMC time zone, which must be the same as the time zone of the Kerberos server.
- On the iBMC WebUI, choose .
- Select a value from Region and Time Zone.
- Click Save.
- Enable NTP.
Enable NTP to ensure time consistency between the iBMC and the Kerberos server.
- On the iBMC WebUI, choose .
- In the NTP Settings area, set NTP to Enable.
- Click Save.
- Configure the Kerberos server information.
- On the iBMC WebUI, choose User & Security > Kerberos.
- Set Kerberos to
to enable the Kerberos function.
- Set the Kerberos server parameters.
The following parameters must be configured.
- Realm: Enter the Kerberos server domain name, for example, ADMIN.COM. This domain name must be the same as the domain name set on the Kerberos server.
- Kerberos Server Address: Enter the Kerberos server IP address, for example, 192.168.66.66.
- Kerberos Port: Enter the port number of the Kerberos server.
- Import the Kerberos key table. For details, see Importing a Key Table in .
- Current User Password: Enter the password for logging in to the iBMC.
Set other parameters based on actual situation. For details about the parameters, see Enabling Kerberos and Configuring the Domain Server .
- Click Save.
- Configure the Kerberos group.
- On the iBMC WebUI, choose .
- In the Kerberos User Group area, click
or Add.
- In Current User Password, enter the iBMC user password.
- Configure Kerberos group parameters.
- Kerberos User Group: Enter the Kerberos user group name, for example info_group1 (the Kerberos group name set in iBMC Configuring the Directory Server).
- Kerberos Group Folder: Enter the name of the folder in which the Kerberos group applications are stored.
The Kerberos group folder must be the same as the organizational unit set on the Kerberos server, for example, company/department (the organizational unit set in iBMC Configuring the Directory Server).
- SID: Enter the SID.
- Role: Assign operation permissions to the user group.
- Login Rules: Set the login rules.
- Login Interfaces: Set the login interfaces.
- Click Save.
- Configure single sign-on (SSO) for the browser that supports this function. You do not need to configure SSO for Google Chrome.
Enabling SSO in Internet Explorer
The operations vary depending on the Internet Explorer version. The following uses Internet Explorer 11 as an example.- Enable authentication in Internet Explorer.
- Click
to open the Internet Options window.
- Choose .
- Select Enable Integrated Windows Authentication in Security.
- Click OK.
- Click
- Add the iBMC domain to the Internet zone.
- Choose .
- Click Advanced.
- In Add this website to the zone, enter the site, for example *.iBMC.com.
- Click Add.
- Click Close.
- Enable Automatic login only in Intranet zone.
- Choose .
- Click Custom level.
- In the User Authentication area, select Automatic login only in Intranet zone.
- Click OK.
- To close the Internet Options dialog box, click OK.
- Close and restart Internet Explorer to make the settings in 1 to 2 take effect.
Enabling SSO in Firefox
The operations vary depending on the Firefox version. The following uses Firefox 17.0 as an example.
- Enter about:config in the address box and press Enter.
- If "This might void your warranty!" is displayed, click I accept the risk!.
- In the Search box of the browser, enter network.negotiate.
- Double-click network.negotiate-auth.trusted-uris.
- Enter the iBMC DNS domain name (for example iBMC.com).
- Click OK.
- Enable authentication in Internet Explorer.
- Log in to the iBMC using a Kerberos domain account or SSO.
Log in to the iBMC using a Kerberos domain account:
- Enter the Kerberos user name and password, for example, HWinfo/Admin@9000.
The user name and password must have been configured on the Kerberos server.
- Choose the Kerberos server domain name, for example ADMIN.COM(KRB) , from the domain drop-down list.
- Click Log in.
Log in to the iBMC using SSO:
- Open the browser (with the configuration in 4 completed) and enter the iBMC FQDN, for example, https://Host name.Domain name.
- Click SSO.
- Enter the Kerberos user name and password, for example, HWinfo/Admin@9000.