HP BL480c User Manual

HP BladeSystem Onboard Administrator Command Line Interface User Guide
Version 3.00
Part Number 416217-404 February 2010 (Thirteenth Edition)
© Copyright 2006, 2010 Hewlett-Packard Development Company, L.P.
The information contained herein is subject to change without notice. The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein.
Confidential computer software. Valid license from HP required for possession, use or copying. Consistent with FAR 12.211 and 12.212, Commercial Computer Software, Computer Software Documentation, and Technical Data for Commercial Items are licensed to the U.S. Government under vendor’s standard commercial license.
Intended audience
This document is for the person who installs, administers, and troubleshoots servers and storage systems. HP assumes you are qualified in the servicing of computer equipment and trained in recognizing hazards in products with hazardous energy levels.
Contents
Accessing the command line interface ........................................................................................... 10
Remote access to the Onboard Administrator ................................................................................................ 10
Local access to the Onboard Administrator ................................................................................................... 10
Command line ............................................................................................................................ 12
Command line overview ............................................................................................................................. 12
Command line conventions ......................................................................................................................... 12
HP Integrity server blade restrictions ............................................................................................................. 13
Access level and privileges.......................................................................................................................... 13
Account authentication...................................................................................................................... 15
AutoLogin to iLO 2 ........................................................................................................................... 16
General commands ..................................................................................................................... 17
CLEAR SCREEN ......................................................................................................................................... 17
EXIT .......................................................................................................................................................... 17
HELP ......................................................................................................................................................... 17
LOGOUT ................................................................................................................................................... 17
QUIT ......................................................................................................................................................... 18
Rack commands ......................................................................................................................... 19
SET RACK NAME ....................................................................................................................................... 19
SHOW RACK NAME ................................................................................................................................. 19
SHOW TOPOLOGY ................................................................................................................................... 19
User account commands .............................................................................................................. 21
ADD USER ................................................................................................................................................. 21
ASSIGN .................................................................................................................................................... 21
ASSIGN OA .............................................................................................................................................. 22
DISABLE USER ........................................................................................................................................... 22
DISABLE STRONG PASSWORDS ................................................................................................................ 22
ENABLE STRONG PASSWORDS ................................................................................................................. 22
ENABLE USER ............................................................................................................................................ 23
HISTORY ................................................................................................................................................... 23
REMOVE USER .......................................................................................................................................... 23
SET MINIMUM PASSWORD LENGTH .......................................................................................................... 24
SET PASSWORD ........................................................................................................................................ 24
SET SESSION TIMEOUT ............................................................................................................................. 24
SET USER ACCESS ..................................................................................................................................... 25
SET USER CONTACT ................................................................................................................................. 25
SET USER FULLNAME ................................................................................................................................. 25
SET USER PASSWORD ............................................................................................................................... 26
SHOW PASSWORD SETTINGS .................................................................................................................. 26
SHOW SESSION TIMEOUT ........................................................................................................................ 27
SHOW USER ............................................................................................................................................. 27
SLEEP ........................................................................................................................................................ 28
UNASSIGN ............................................................................................................................................... 28
UNASSIGN OA
......................................................................................................................................... 28
Two-Factor Authentication commands ............................................................................................ 29
DISABLE CRL .............................................................................................................................................. 29
DISABLE TWOFACTOR............................................................................................................................... 29
DOWNLOAD CA CERTIFICATE ................................................................................................................... 29
DOWNLOAD USER CERTIFICATE ................................................................................................................ 30
REMOVE CA CERTIFICATE .......................................................................................................................... 30
REMOVE USER CERTIFICATE ....................................................................................................................... 30
SHOW CA CERTIFICATES .......................................................................................................................... 30
SHOW TWOFACTOR INFO ....................................................................................................................... 31
Directory commands ................................................................................................................... 32
ADD LDAP CERTIFICATE ............................................................................................................................. 32
ADD LDAP GROUP..................................................................................................................................... 32
ASSIGN for LDAP ...................................................................................................................................... 32
ASSIGN OA LDAP GROUP ......................................................................................................................... 33
DISABLE LDAP............................................................................................................................................ 33
DOWNLOAD LDAP CERTIFICATE ................................................................................................................ 33
ENABLE LDAP ............................................................................................................................................ 34
REMOVE LDAP CERTIFICATE ....................................................................................................................... 34
REMOVE LDAP GROUP .............................................................................................................................. 34
SET LDAP GROUP ACCESS ......................................................................................................................... 35
SET LDAP GROUP DESCRIPTION ................................................................................................................. 35
SET LDAP NAME MAP ................................................................................................................................ 35
SET LDAP PORT .......................................................................................................................................... 36
SET LDAP SEARCH ..................................................................................................................................... 36
SET LDAP SERVER ...................................................................................................................................... 36
SHOW LDAP CERTIFICATE ......................................................................................................................... 36
SHOW LDAP GROUP ................................................................................................................................. 37
SHOW LDAP INFO .................................................................................................................................... 37
TEST LDAP ................................................................................................................................................. 38
UNASSIGN for LDAP ................................................................................................................................. 38
UNASSIGN OA LDAP GROUP .................................................................................................................... 38
HP SIM commands ...................................................................................................................... 40
ADD HPSIM CERTIFICATE ........................................................................................................................... 40
DOWNLOAD HPSIM CERTIFICATE .............................................................................................................. 40
REMOVE HPSIM CERTIFICATE ..................................................................................................................... 40
SET HPSIM TRUST MODE ........................................................................................................................... 41
SHOW HPSIM INFO .................................................................................................................................. 41
General management commands ................................................................................................. 42
DOWNLOAD OA CERTIFICATE .................................................................................................................. 42
FORCE TAKEOVER ..................................................................................................................................... 42
GENERATE CERTIFICATE ............................................................................................................................ 42
Generate certificate prompts ............................................................................................................. 43
PING ................................................................
SET DEVICE SERIAL_NUMBER BLADE ........................................................................................................... 45
SET FACTORY ........................................................................................................................................... 45
SET SCRIPT MODE ..................................................................................................................................... 45
SHOW ALL ................................................................................................................................................ 46
SHOW DEVICE SERIAL_NUMBER BLADE ..................................................................................................... 72
SHOW INTERCONNECT SESSIONS ........................................................................................................... 72
........................................................................................ 44
Enclosure Bay IP Addressing commands ........................................................................................ 74
ADD EBIPA ................................................................................................................................................ 74
DISABLE EBIPA ........................................................................................................................................... 74
ENABLE EBIPA ........................................................................................................................................... 74
REMOVE EBIPA ......................................................................................................................................... 75
SET EBIPA ................................................................................................................................................. 75
SET EBIPA SERVER ........................................................................................................................... 76
SET EBIPA INTERCONNECT ............................................................................................................. 76
SHOW EBIPA ............................................................................................................................................ 76
Enclosure network configuration commands ................................................................................... 79
ADD OA ADDRESS IPV6 ............................................................................................................................ 79
ADD OA DNS ........................................................................................................................................... 79
ADD OA DNS IPV6 .................................................................................................................................... 79
ADD SNMP TRAPRECEIVER ......................................................................................................................... 80
ADD SSHKEY ............................................................................................................................................ 80
ADD TRUSTED HOST .................................................................................................................................. 81
CLEAR NTP ................................................................................................................................................ 81
CLEAR SSHKEY .......................................................................................................................................... 81
CLEAR VCMODE ....................................................................................................................................... 82
DISABLE ALERTMAIL ................................................................................................................................... 82
DISABLE DHCPV6 ...................................................................................................................................... 82
DISABLE ENCLOSURE_IP_MODE ................................................................................................................. 83
DISABLE HTTPS .......................................................................................................................................... 83
DISABLE IPV6 ............................................................................................................................................ 83
DISABLE NTP ............................................................................................................................................. 84
DISABLE ROUTER ADVERTISEMENTS ........................................................................................................... 84
DISABLE SECURESH ................................................................................................................................... 84
DISABLE SNMP .......................................................................................................................................... 84
DISABLE TELNET ........................................................................................................................................ 85
DISABLE TRUSTED HOST ............................................................................................................................ 85
DISABLE XMLREPLY..................................................................................................................................... 85
DOWNLOAD CONFIG .............................................................................................................................. 86
DOWNLOAD SSHKEY ............................................................................................................................... 86
ENABLE ALERTMAIL ................................................................................................................................... 86
ENABLE DHCPV6 ....................................................................................................................................... 87
ENABLE ENCLOSURE_IP_MODE ................................................................................................................. 87
ENABLE HTTPS .......................................................................................................................................... 87
ENABLE IPV6 ............................................................................................................................................. 88
ENABLE NTP ............................................................................................................................................. 88
ENABLE ROUTER ADVERTISEMENTS ........................................................................................................... 88
ENABLE SECURESH ................................................................................................................................... 88
ENABLE SNMP .......................................................................................................................................... 89
ENABLE TELNET ......................................................................................................................................... 89
ENABLE TRUSTED HOST ............................................................................................................................. 89
ENABLE XMLREPLY ..................................................................................................................................... 90
REMOVE OA ADDRESS IPV6 ...................................................................................................................... 90
REMOVE OA DNS ..................................................................................................................................... 90
REMOVE OA DNS IPV6 ............................................................................................................................. 91
REMOVE SNMP TRAPRECEIVER .................................................................................................................. 91
REMOVE TRUSTED HOST ........................................................................................................................... 91
SET ALERTMAIL MAILBOX ........................................................................................................................... 92
SET ALERTMAIL SENDERDOMAIN ............................................................................................................... 92
SET ALERTMAIL SMTPSERVER ...................................................................................................................... 92
SET ENCRYPTION ...................................................................................................................................... 93
SET OA GATEWAY ................................................................................................................................... 93
SET OA NAME .......................................................................................................................................... 93
SET OA UID .............................................................................................................................................. 94
SET IPCONFIG .......................................................................................................................................... 94
SET NTP POLL ............................................................................................................................................ 94
SET NTP PRIMARY ...................................................................................................................................... 95
SET NTP SECONDARY ............................................................................................................................... 95
SET SNMP CONTACT ................................................................................................................................ 95
SET SNMP COMMUNITY ........................................................................................................................... 96
SET SNMP LOCATION ............................................................................................................................... 96
SHOW ENCRYPTION ................................................................................................................................ 96
SHOW NETWORK .................................................................................................................................... 97
SHOW SNMP ........................................................................................................................................... 98
SHOW SSHFINGERPRINT .......................................................................................................................... 99
SHOW SSHKEY ......................................................................................................................................... 99
TEST ALERTMAIL ........................................................................................................................................ 99
TEST SNMP ............................................................................................................................................. 100
Enclosure management commands ............................................................................................. 101
CLEAR SYSLOG ....................................................................................................................................... 101
DISABLE GUI_LOGIN_DETAIL .................................................................................................................... 101
DISABLE LLF ............................................................................................................................................. 101
ENABLE GUI_LOGIN_DETAIL .................................................................................................................... 102
ENABLE LLF ............................................................................................................................................. 102
RESTART OA ........................................................................................................................................... 102
SET DATE ................................................................................................................................................ 102
SET DISPLAY EVENTS ............................................................................................................................... 103
SET ENCLOSURE ASSET ........................................................................................................................... 103
SET ENCLOSURE NAME .......................................................................................................................... 104
SET ENCLOSURE PART_ NUMBER ............................................................................................................. 104
SET ENCLOSURE PDU_TYPE ..................................................................................................................... 104
SET ENCLOSURE SERIAL_NUMBER ........................................................................................................... 105
SET ENCLOSURE UID ............................................................................................................................... 105
SET LLF INTERVAL..................................................................................................................................... 105
SET OA USB ............................................................................................................................................ 106
SET POWER MODE ................................................................................................................................. 106
SET POWER LIMIT .................................................................................................................................... 106
SET POWER SAVINGS ............................................................................................................................. 107
SET TIMEZONE........................................................................................................................................ 107
SHOW CONFIG ..................................................................................................................................... 107
SHOW DATE........................................................................................................................................... 108
SHOW DISPLAY EVENTS .......................................................................................................................... 109
SHOW ENCLOSURE FAN ........................................................................................................................ 109
SHOW ENCLOSURE INFO ....................................................................................................................... 110
SHOW ENCLOSURE LCD
SHOW ENCLOSURE POWER_SUMMARY ................................................................................................. 111
SHOW ENCLOSURE POWERSUPPLY ........................................................................................................ 112
SHOW ENCLOSURE STATUS ................................................................................................................... 113
SHOW ENCLOSURE TEMP ....................................................................................................................... 113
SHOW FRU ............................................................................................................................................. 114
SHOW OA ............................................................................................................................................. 116
SHOW OA CERTIFICATE .......................................................................................................................... 116
SHOW OA INFO .................................................................................................................................... 117
SHOW OA NETWORK ............................................................................................................................ 117
SHOW OA STATUS ................................................................................................................................. 118
......................................................................................................................... 110
SHOW OA USB ...................................................................................................................................... 119
SHOW POWER ....................................................................................................................................... 119
SHOW SYSLOG ...................................................................................................................................... 120
SHOW SYSLOG OA ................................................................................................................................ 120
SHOW VCMODE .................................................................................................................................... 121
UPDATE .................................................................................................................................................. 122
UPDATE ILO ............................................................................................................................................ 122
UPDATE IMAGE ....................................................................................................................................... 123
UPLOAD CONFIG ................................................................................................................................... 123
UPLOAD DEBUG ...................................................................................................................................... 124
Blade management commands ................................................................................................... 125
CONNECT SERVER .................................................................................................................................. 125
DISABLE URB ........................................................................................................................................... 125
ENABLE URB ........................................................................................................................................... 125
HPONCFG .............................................................................................................................................. 126
POWEROFF SERVER ................................................................................................................................ 126
POWERON SERVER ................................................................................................................................. 127
REBOOT SERVER ..................................................................................................................................... 127
SET NIC .................................................................................................................................................. 128
SET SERVER BOOT ................................................................................................................................... 128
SET SERVER BOOT ONCE ........................................................................................................................ 128
SET SERVER POWERDELAY ....................................................................................................................... 129
SET SERVER UID ....................................................................................................................................... 129
SET URB .................................................................................................................................................. 129
SHOW SERVER BOOT ............................................................................................................................. 130
SHOW SERVER INFO .............................................................................................................................. 131
SHOW SERVER LIST ................................................................................................................................. 132
SHOW SERVER NAMES ........................................................................................................................... 132
SHOW SERVER PORT MAP ....................................................................................................................... 133
SHOW SERVER POWERDELAY ................................................................................................................. 134
SHOW SERVER STATUS ........................................................................................................................... 135
SHOW SERVER TEMP .............................................................................................................................. 137
SHOW SYSLOG SERVER .......................................................................................................................... 138
UNASSIGN SERVER ................................................................................................................................. 139
Interconnect management commands .......................................................................................... 140
ASSIGN INTERCONNECT ........................................................................................................................ 140
CLEAR INTERCONNECT SESSION ............................................................................................................ 140
SHOW URB ............................................................................................................................................ 140
TEST URB ................................................................................................................................................ 141
CONNECT INTERCONNECT .................................................................................................................... 141
POWEROFF INTERCONNECT .................................................................................................................. 141
POWERON INTERCONNECT ................................................................
RESTART INTERCONNECT ....................................................................................................................... 142
SET INTERCONNECT POWERDELAY ......................................................................................................... 142
SET INTERCONNECT UID......................................................................................................................... 143
SHOW INTERCONNECT INFO ................................................................................................................ 143
SHOW INTERCONNECT LIST ................................................................................................................... 145
SHOW INTERCONNECT PORT MAP......................................................................................................... 145
SHOW INTERCONNECT POWERDELAY ................................................................................................... 146
SHOW INTERCONNECT STATUS ............................................................................................................. 146
Enclosure DVD commands ......................................................................................................... 148
................................................... 142
SET SERVER DVD ..................................................................................................................................... 148
SHOW SERVER DVD ................................................................................................................................ 148
Remote syslog commands .......................................................................................................... 150
DISABLE SYSLOG REMOTE ....................................................................................................................... 150
ENABLE SYSLOG REMOTE ....................................................................................................................... 150
SET REMOTE SYSLOG PORT ..................................................................................................................... 150
SET REMOTE SYSLOG SERVER .................................................................................................................. 151
SHOW SYSLOG SETTINGS ...................................................................................................................... 151
TEST SYSLOG .......................................................................................................................................... 151
Remote syslog example ............................................................................................................................. 152
USB support commands ............................................................................................................. 153
DOWNLOAD CONFIG using USB key ...................................................................................................... 153
SET SERVER DVD for USB key ................................................................................................................... 153
SHOW USBKEY ....................................................................................................................................... 153
UPDATE IMAGE using USB key ................................................................................................................. 154
UPLOAD CONFIG using USB key .............................................................................................................. 155
VLAN commands ...................................................................................................................... 156
ADD VLAN .............................................................................................................................................. 156
DISABLE VLAN ......................................................................................................................................... 156
EDIT VLAN .............................................................................................................................................. 156
ENABLE VLAN ......................................................................................................................................... 157
REMOVE VLAN ....................................................................................................................................... 157
SAVE VLAN ............................................................................................................................................. 157
SET VLAN DEFAULT .................................................................................................................................. 157
SET VLAN FACTORY ................................................................................................................................ 158
SET VLAN INTERCONNECT ..................................................................................................................... 158
SET VLAN IPCONFIG ............................................................................................................................... 158
SET VLAN IPCONFIG DHCP ..................................................................................................................... 159
SET VLAN IPCONFIG SAVE ...................................................................................................................... 159
SET VLAN IPCONFIG STATIC .................................................................................................................... 159
SET VLAN OA ......................................................................................................................................... 160
SET VLAN REVERT .................................................................................................................................... 160
SET VLAN SERVER ................................................................................................................................... 160
SHOW VLAN .......................................................................................................................................... 161
Enclosure Dynamic Power Cap commands .................................................................................. 162
SET ENCLOSURE POWER_CAP ................................................................................................................. 162
SET ENCLOSURE POWER_CAP_BAYS_TO_EXCLUDE .................................................................................. 162
SHOW ENCLOSURE POWER_CAP ........................................................................................................... 163
SHOW ENCLOSURE POWER_CAP_BAYS_TO_EXCLUDE ............................................................................ 163
Event notifications ..................................................................................................................... 165
Enclosure event notifications ...................................................................................................................... 165
Command line event notifications............................................................................................................... 165
Technical support ...................................................................................................................... 168
Before you contact HP .............................................................................................................................. 168
HP contact information .............................................................................................................................. 168
Time zone settings .................................................................................................................... 169
Universal time zone settings ...................................................................................................................... 169
Africa time zone settings ........................................................................................................................... 169
Americas time zone settings ...................................................................................................................... 170
Asia time zone settings ............................................................................................................................. 171
Oceanic time zone settings ....................................................................................................................... 172
Europe time zone settings .......................................................................................................................... 173
Polar time zone settings ............................................................................................................................ 173
Acronyms and abbreviations ...................................................................................................... 174
Index ....................................................................................................................................... 177
Accessing the command line interface
Remote access to the Onboard Administrator
The Onboard Administrator CLI can be accessed remotely through any Telnet or SSH session.
Telnet session
1. Open a command-line window from a network-connected client.
2. At the prompt, telnet to the IP address of the Onboard Administrator and press Enter.
For example, telnet 192.168.100.130, where the IP address is the address of your Onboard Administrator.
3. Enter a valid user name and press Enter.
4. Enter a valid password and press Enter. The CLI command prompt displays.
5. Enter commands for the Onboard Administrator.
6. To terminate the remote access telnet session, enter Exit, Logout, or Quit at the CLI command
prompt.
SSH session
1. Start a SSH session to the Onboard Administrator using any SSH client application.
2. When prompted, enter the assigned IP address or DNS name of the Onboard Administrator and
press Enter.
3. Enter a valid user name and press Enter.
4. Enter a valid password and press Enter. The CLI command prompt displays.
5. Enter commands for the Onboard Administrator.
6. To terminate the remote access SSH session, close the communication software or enter Exit,
Logout, or Quit at the CLI command prompt.
Local access to the Onboard Administrator
The Onboard Administrator can be accessed locally through a serial port connector on the rear of the Onboard Administrator module. Use a laptop or another computer as a serial console to communicate with the Onboard Administrator. A laptop or PC connected to the Onboard Administrator serial port requires a null-modem cable. The minimum connection to an external console is pins 2, 3, and 5.
1. Connect a serial cable between the serial port on the computer and the corresponding serial port on
the Onboard Administrator module. The following table is for the DB9 serial (RS232) port and shows the pinout and signals for the RS232 connector. The signal direction is DTE (computer) relative to the DCE (modem).
Pin Name Signal direction Description
1 CD <<-- Carrier detect
2 RXD <<-- Receive data
Accessing the command line interface 10
Pin Name Signal direction Description
3 TXD -->> Transmit data
4 DTR -->> Data terminal ready
5 GND
System ground
6 DSR <<-- Data set ready
7 RTS -->> Request to send
8 CTS <<-- Clear to send
9 RI <<-- Ring indicator
2. Use any standard communication software to launch a terminal emulation session with the following
parameters:
Parameter Value
Transmission rate 9600 bps
Data bits 8
Parity None
Stop bits 1
Protocol None
3. When prompted, enter a valid user name, and then press Enter.
4. Enter a valid password, and press Enter. The CLI command prompt appears.
5. Enter commands for the Onboard Administrator.
6. To terminate the terminal session, enter Exit at the prompt.
Accessing the command line interface 11
Command line
SET ENCLOSURE UID OFF
Command line overview
The CLI can be used as an alternative method for managing the Onboard Administrator. Using the CLI can be useful in the following scenarios:
HP Management Applications (for example: Systems Insight Manager, Insight Control tools, and so
on) can query the Onboard Administrator for information these tools need to present a complete management view of HP BladeSystem enclosures and the devices contained within. This interface is also used by the Management tools to execute provisioning and configuration tasks to devices within the enclosure.
Users can develop tools that utilize Onboard Administrator functions for data collection and for
executing provisioning and configuration tasks.
When no browser is available or you prefer to use a Linux command line interface to access
management data and perform configuration tasks.
Command line conventions
CLI input is case-insensitive except when otherwise noted. Commands are organized into a tree, with approximately 30 base commands. Each of these commands can have any number of subcommands. Subcommands can also have further subcommands.
Each command used in this guide follows the conventions listed in the following table.
Symbol Description
<lower case> Denotes the variable within the symbols that must be substituted with a value, such
as a user name. Symbols must be removed.
UPPER CASE
|
{ }
[ ]
" "
Denotes input to be entered as shown. Unless noted, symbol is not case-sensitive.
Used to separate input options.
Denotes a list of mandatory choices that must be made. For example, SET ENCLOSURE UID {ON | OFF} must be in the form of either
of the following:
SET ENCLOSURE UID ON
Denotes an optional argument or set of characters.
Used to enclose command arguments that contain spaces.
Command line 12
HP Integrity server blade restrictions
HP Integrity server blades do not support all commands. See specific commands for restrictions on HP Integrity server blades.
The following commands are not applicable to HP Integrity server blades
Hponcfg
Set Server Boot
Set Server Boot Once
Show Server Boot
Show Syslog Server
Update iLO
Access level and privileges
Onboard Administrator accounts and privileges
Onboard Administrator accounts are created with a username, password, privilege level, and permissions to Device bays and Interconnect bays on the Onboard Administrator. You cannot delete or modify the privileges of the default Administrator account, on the Onboard Administrator. You can only change the password for the Administrator account. The following table indicates the capabilities of the user based on their privileges and permitted bays.
Command line 13
Account classification Capabilities
Administrator
All commands Local account, not
LDAP
Account name / Privilege level
Administrator / administrator
Bays selected for this account
All
Only account
remaining after a reset Onboard Administrator to factory defaults (account retains configured Administrator password)
Administrator
account password can be reset to factory default through the Onboard Administrator serial port using "L" lost password recovery option
Can download,
add, and clear SSHKey. This key only works with the Administrator account.
OA administrator
All commands Allows access to all
aspects of the HP BladeSystem Enclosure and Onboard Administrator including configuration, firmware updates, user management, and resetting default settings.
username / administrator
OA bays (all bays automatically selected)
Command line 14
Account classification Capabilities
administrator
Can perform all
operations to permitted device bays and interconnect bays including virtual power and console access
Account name / Privilege level
username / administrator
Bays selected for this account
No OA bays and only selected device bays and interconnect bays
administrator
permission on device iLO2
OA operator
Set rack name EBIPA
enable/disable permitted bays
Change OA
network settings
username / operator
OA bays and can have other bays selected, but the capabilities for the other bays are defined in operator
Perform enclosure
management commands
operator
Can perform all
operations to permitted device bays and interconnect bays including virtual power and console access
username / operator
Selected device bays and interconnect bays
operator
permission on device iLO2
user
Can view status
and information of selected bays
username / user
No OA bays and some device bays and interconnect bays
Can view CLI
history
Can set password
for own account
Can set user
contact information for own account
Can 'show' CLI
commands
Account authentication
Local users
Command line 15
This is the default setting. Local user accounts are directly authenticated against a password for each
account stored on the active Onboard Administrator.
Account modifications are automatically synchronized between both Onboard Administrator
modules if two are present.
Local users may be disabled if LDAP is enabled, leaving the Administrator account as the only local
account that cannot be disabled.
LDAP users
The Enable/Disable LDAP is an optional setting. LDAP enabled can be used with local users enabled
or disabled.
The Onboard Administrator will use configured LDAP server and search context to request account
authentication.
Configuration of the LDAP group will determine the privileges instead of the username.
If a user is configured for multiple groups with different privileges and bay permissions, then the user
will have the highest privileges and the combination of all permitted bays.
In version 2.10 or higher, if the user logged into the Onboard Administrator is an LDAP user then the
Onboard Administrator enforces the iLO license and requires that the iLO have a Select license before allowing the AutoLogin to iLO.
AutoLogin to iLO 2
The following table indicates Onboard Administrator account privileges mapped to iLO privileges when using Onboard Administrator AutoLogin.
iLO privileges administrator operator user
Administer user accounts X
Remote console access X X
Virtual power and reset X X
Virtual media X X
Configure iLO settings X
Login to iLO X X X
Command line 16
General commands
CLEAR SCREEN
Command:
CLEAR SCREEN
Description:
Clears the terminal screen
Access level:
EXIT
Command:
Description:
Access level:
HELP
Command:
Description:
Administrator, Operator, User
EXIT
Exits the command line interpreter
Administrator, Operator, User
HELP <command>
If you supply a command, the usage and help text for the command appears. If no argument is given, all base commands appear.
Access level:
Administrator, Operator, User
Example
OA-0018FE27577F> HELP ADD | ASSIGN | CLEAR | CONNECT | DISABLE | DISCOVER | DOWNLOAD | EDIT | ENABLE | EXIT | FORCE | GENERATE | HELP | HISTORY | HPONCFG | LOGOUT | PING | POWEROFF | POWERON | QUIT | REBOOT | REMOVE | RESET | RESTART | SAVE | SET | SHOW | SLEEP | TEST | UNASSIGN | UPDATE | UPLOAD
LOGOUT
Command:
General commands 17
LOGOUT
Description:
Exits the command line interpreter
Access level:
QUIT
Command:
Description:
Access level:
Administrator, Operator, User
QUIT
Exits the command line interpreter
Administrator, Operator, User
General commands 18
Rack commands
SET RACK NAME
Command:
SET RACK NAME <rack name>
Description:
Sets the rack name
Access level/Bay level:
OA administrator, OA operator
Restrictions:
The <rack name> must be a maximum of 32 characters long and includes all alphanumeric, the dash, and the underscore characters.
UnnamedRack is the default rack name.
SHOW RACK NAME
Command:
SHOW RACK NAME
Description:
Displays the user defined rack name setting for the enclosure
Access level/Bay level:
All
Restrictions:
None
Example:
OA-0018FE27577F> SHOW RACK NAME
Rack Name: UnnamedRack
SHOW TOPOLOGY
Command:
SHOW TOPOLOGY
Description:
o Displays the enclosures connected by the enclosure link
o Displays a table with the enclosure name, overall health of the enclosure, and the IP address
Access level/Bay level
Rack commands 19
All
Restrictions:
None
Example
SHOW TOPOLOGY
Detecting linked enclosures ....
Rack Topology (top-down) Rack UUID: 090987654321 Rack Name: UnnamedRack Enclosure Name Status Local IP Address UUID
-------------------------------- -------- ----- --------------- ------------­Shorty OK Yes 16.84.190.253 090987654321 OA-0018FE2F998B OK No 172.16.211.101 09USE644285C
Rack commands 20
User account commands
ADD USER
Command:
ADD USER "<user name>" ["<password>"]
Description:
Adds a user to the system. If you do not provide a password, you are prompted for one. If SCRIPT MODE is enabled and the password is not provided, the password is assigned an unmatched string. This unmatched string requires an enclosure administrator to change the password to allow the new user to access the system.
Access level/Bay level:
OA administrator
Restrictions:
o You can add a maximum of 30 users, including the reserved accounts.
o The <user name> is case sensitive and must be unique to all other user names and group names.
o The <user name> must begin with a letter.
o The <password> must be three to eight characters long for firmware 1.00 through 1.30 and 3 to
o Reserved user names are: ALL (case insensitive) ADMINISTRATOR (case insensitive), switch1,
ASSIGN
Command:
ASSIGN {SERVER | INTERCONNECT} {<bay number> | ALL | <bay number>-<bay number>} {"<user name>" | LDAP GROUP "<LDAP group name>"}
Description:
Assigns one or more bays to a user or group
Access level/Bay level:
The <user name> must be 1 to 40 characters long and can include all alphanumeric characters, the dash, and the underscore.
40 characters long for firmware 2.00 and later. The character set includes all printable characters. If you do not enter a password, you are prompted to enter one.
switch2, switch3, switch4, switch5, switch6, switch7, switch8, ldapuser, nobody, vcmuser, and root (for firmware 1.00 through 1.30).
OA administrator
Restrictions:
The <user name> is case sensitive. If a bay is presently assigned to a user, you must unassign the
bay first.
User account commands 21
ASSIGN OA
Command:
ASSIGN OA {"<user name>" | LDAP GROUP "<LDAP group name>"}
Description:
Assigns the Onboard Administrators specified to an existing user or group
Access level/Bay level:
OA administrator
Restrictions:
The <user name> is case sensitive.
DISABLE USER
Command:
DISABLE USER "<user name>"
Description:
Disables a user account. The system immediately logs out the user and prevents the user from logging in until the account is enabled. CLI sessions are terminated and all future SOAP web accesses fail.
Access level/Bay level:
OA administrator
Restrictions:
o The <user name> is case sensitive.
o You cannot disable the built-in Administrator account
DISABLE STRONG PASSWORDS
Command:
DISABLE STRONG PASSWORDS
Description:
Removes strong password requirements for user passwords
Access level/Bay level:
OA administrator
Restrictions:
Only Administrators with Onboard Administrator permission are allowed to manage strong passwords.
ENABLE STRONG PASSWORDS
Command:
User account commands 22
ENABLE STRONG PASSWORDS
Description:
When enabled, this command requires that a user's password contain at least one character from three of the four categories.
The four categories include:
o Uppercase
o Lowercase
o Numeric
o Nonalphanumeric
Access level/Bay level:
OA administrator
Restrictions:
Only Administrators with Onboard Administrator permission are allowed to manage strong passwords
ENABLE USER
Command:
ENABLE USER "<user name>"
Description:
Enables a user account that was previously disabled by the DISABLE USER command
Access level/Bay level:
OA administrator
Restrictions:
The <user name> is case sensitive.
HISTORY
Command:
HISTORY
Description:
Shows the history of commands for the current session
Access level/Bay level:
All
Restrictions:
None
REMOVE USER
Command:
User account commands 23
REMOVE USER {ALL | "<user name>" | CERTIFICATE "<user name>"}
Description:
Removes a user from the system and/or any certificate mapped to the user. If you specify ALL, then the command is run for all users except the default system accounts.
Access level/Bay level:
OA administrator
Restrictions:
o The <user name> is case sensitive.
o You cannot remove the Administrator account.
SET MINIMUM PASSWORD LENGTH
Command:
SET MINIMUM PASSWORD LENGTH <length>
Description:
Sets a minimum length for passwords. When set, a user's password must contain at least the number of characters specified.
Access level/Bay level:
OA administrator
Restrictions:
The minimum password length can be set between 3 and 40 characters.
SET PASSWORD
Command:
SET PASSWORD ["<password>"]
Description:
Sets the password of the user that executed the command. If you do not provide a password on the command line, you are prompted for one.
Access level/Bay level:
All
Restrictions:
The <password> must be three to eight characters long for firmware 1.00 through 1.30 and 3 to 40 characters long for firmware 2.00 and later. The character set includes all printable characters.
SET SESSION TIMEOUT
Command:
SET SESSION TIMEOUT <timeout>
Description:
Sets the number of minutes before inactive sessions are removed. The default setting is 1440.
User account commands 24
Access level/ Bay level:
OA administrator
Restriction:
Valid session timeout values range from 10 to 1440 minutes (24 hours).
SET USER ACCESS
Command:
SET USER ACCESS "<user name>" {ADMINISTRATOR | OPERATOR | USER}
Description:
Sets the user access level. Additionally, use the ASSIGN command to give the user access rights to the Onboard Administrator, server bays, and interconnect bays.
Access level/Bay level:
OA administrator
Restrictions:
None
SET USER CONTACT
Command:
SET USER CONTACT ["<user name>"] "<contact info>"
Description:
Sets the contact information field for the user. If there is no <user name>, the command modifies the contact information of the user who executed the command.
Access level/Bay level:
o All users can modify their own contact information.
o The OA administrator can modify all users.
Restrictions:
o The <user name> is case sensitive. The <contact info> must be a maximum of 20 characters long
and includes all alphanumeric characters, the dash, the underscore, and spaces.
o The default contact information is blank.
o You must use double quotes if the contact information contains any spaces.
SET USER FULLNAME
Command:
SET USER FULLNAME ["<user name>"] "<full name>"
Description:
Sets a user's full name. If you do not specify a <user name>, the command modifies the full name of the user who is currently logged in.
Access level/Bay level:
User account commands 25
o
OA administrator, OA operator
o All users can modify their own full name.
Restrictions:
o The <user name> is case sensitive. The <full name> must be a maximum of 20 characters long
and includes all alphanumeric, the dash, the underscore, and the space characters.
o The default full name is blank.
SET USER PASSWORD
Command:
SET USER PASSWORD "<user name>" ["<new password>"]
Description:
Sets a user's password. If you do not supply a password on the command line, you are prompted for one.
Access level/Bay level
OA administrator
OA operator and User access level users can change their own passwords.
Restrictions:
o Only OA administrators can modify another user's password. Only the Administrator account
can modify the password of the Administrator account.
o The <user name> is case sensitive.
o The <new password> must be three to eight characters long for firmware 1.00 through 1.30 and
3 to 40 characters long for firmware 2.00 and higher.
o The character set includes all printable characters.
SHOW PASSWORD SETTINGS
Command:
SHOW PASSWORD SETTINGS
Description:
Displays the current minimum password length and strong password settings
Access level/Bay level:
All users
Restrictions:
None
Example
OA-0018FE27577F>SHOW PASSWORD SETTINGS Strong Passwords: Disabled Minimum Password Length: 3
User account commands 26
SHOW SESSION TIMEOUT
Command:
SHOW SESSION TIMEOUT
Description:
Displays the current Onboard Administrator user session timeout. The session timeout is the number of minutes before inactive sessions are removed.
Access level/Bay level:
All
Restriction:
None
Example
>SHOW SESSION TIMEOUT Session Timeout: 1440 minutes
SHOW USER
Command:
SHOW USER [LIST | "<user name>"]
Description:
Displays the user's full name, contact information, whether the user has administrator rights, whether the account is enabled, the access level, whether the user has access to the Onboard Administrator, and the bays the user can access.
If you enter LIST and you are an OA administrator, the information for every user is listed. An asterisk before a user name denotes the current user.
Access level/Bay level:
All
Restrictions:
o The <user name> is case sensitive.
o Users who do not have OA administrator access levels can only view their user information.
Example
OA-0018FE27577F> SHOW USER Local User "Administrator" Information: Full name: System Administrator Contact Info: User Rights: Admin Account Status: Enabled Server Bay Access List: 1 1A 1B 2 2A 2B 3 3A 3B 4 4A 4B 5 5A 5B 6 6A 6B 7 7A 7B 8 8A 8B Interconnect Bay Access List: 1 2 3 4 OA Access: Yes
User account commands 27
SLEEP
Command:
Description:
Access level/Bay level:
Restrictions:
SLEEP <seconds>
Pauses the sessions for a fixed period of time. This command is useful for adding delays to scripts.
After the pause has started, you cannot continue the session before time runs out. However, you can terminate the session and start another session.
All
The <seconds> field must be a whole number from 1 to 86400.
UNASSIGN
Command:
UNASSIGN {SERVER | INTERCONNECT} {<bay number> | ALL | <bay number>-<bay number>} {"<user name>" | LDAP GROUP "<LDAP group name>"}
Description:
Removes a bay from the user
Access level/Bay level:
OA administrator
Restrictions:
The <user name> is case sensitive.
UNASSIGN OA
Command:
UNASSIGN OA {"<user name>" | LDAP GROUP "<LDAP group name>"}
Description:
Removes the Onboard Administrator from the control of the user that it is currently assigned
Access level/Bay level:
OA administrator
Restrictions:
The <user name> is case sensitive.
User account commands 28
Two-Factor Authentication commands
DISABLE CRL
Command:
DISABLE CRL
Description:
Disables certificate revocation checks
Access level/Bay level:
OA administrator
Restrictions:
None
DISABLE TWOFACTOR
Command:
DISABLE TWOFACTOR
Description:
Disables Two-Factor Authentication
Access level/Bay level:
OA administrator
Restrictions:
None
DOWNLOAD CA CERTIFICATE
Command:
DOWNLOAD CA CERTIFICATE "<url>"
Description:
Downloads a CA certificate to act as the trusted certification authority to validate user certificates when using Two-Factor Authentication.
Access level/Bay level:
OA administrator
Restrictions:
Allows the download of up to five different certificates
Two-Factor Authentication commands 29
DOWNLOAD USER CERTIFICATE
Command:
DOWNLOAD USER CERTIFICATE "<user name>" <url>
Description:
o Downloads an x.509 certificate for the user from <url>. The file at <url> must be a Base64 PEM
encoded file.
o Downloads a CA certificate used in Two-Factor Authentication
Access level/Bay level:
OA administrator
Restrictions:
None
REMOVE CA CERTIFICATE
Command:
REMOVE CA CERTIFICATE "<certificate name>"
Description:
Removes the trust certificate corresponding to the SHA1 <certificate name>. Any users having their
certificates issued by this CA can no longer login if Two-Factor Authentication is enabled.
Access level/Bay level:
OA administrator
Restrictions:
None
REMOVE USER CERTIFICATE
Command:
REMOVE USER CERTIFICATE "<user name>"
Description:
Removes the user certificate. If Two-Factor Authentication is enabled, this user no longer has access through HTTPS.
Access level/Bay level:
OA administrator
Restrictions:
None
SHOW CA CERTIFICATES
Command:
Two-Factor Authentication commands 30
Loading...
+ 153 hidden pages