I have setup Microsoft Active Directory on iDRAC 7 with very basic options (no certificates, no Single Sign-On, no Kerberos Keytab, Standard Schema). All works well.
The problem is that we have 2 forests with full trust configured between them and iDRAC is not able to authenticate users from both of them.
Basically we have single domain security group on Forest1 and couple users from both forests (Forest1 and Forest2). If I add domain controllers' (DC) IPs for both domains-forests, authentication fails on the first DC if user is from different domain (check does not reach second DC's IP to check for the user). Error I get:
IDRAC active directory login will work only if SSL is enabled on domain controller i.e. domain controller certificate need to be installed on all domain controllers. Uploading root CA certificate to iDRAC is optional and only require if user need iDRAC to verify the certificate from domain controller during authentication.
You need to configure either standard schema or extended schema for iDRAC active directory authentication. Single sign on and keytabs are not required for basic authentication with active directory.
DELL-Shine K
6 Operator
•
3042 Posts
3486
1
Posted January 4th, 2016 08:00
iDRAC only support Active Directory Authentication for domains in single forest.