Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Integrated Dell Remote Access Controller 9 Version 3.21.21.21 User's Guide

Prerequisites for Active Directory Single Sign-On or smart card login

The prerequisites to Active Directory based SSO or Smart Card logins are:

  • Synchronize iDRAC time with the Active Directory domain controller time. If not, kerberos authentication on iDRAC fails. You can use the Time zone and NTP feature to synchronize the time. To do this, see Configuring time zone and NTP.
  • Register iDRAC as a computer in the Active Directory root domain.
  • Generate a keytab file using the ktpass tool.
  • To enable Single Sign-On for Extended schema, make sure that the Trust this user for delegation to any service (Kerberos only) option is selected on the Delegation tab for the keytab user. This tab is available only after creating the keytab file using ktpass utility.
  • Configure the browser to enable SSO login.
  • Create the Active Directory objects and provide the required privileges.
  • For SSO, configure the reverse lookup zone on the DNS servers for the subnet where iDRAC resides.
    NOTE: If the host name does not match the reverse DNS lookup, Kerberos authentication fails.
  • Configure the browser to support SSO login. For more information, see Single Sign-On.
    NOTE: Google Chrome and Safari do not support Active Directory for SSO login.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\