Loading...
Loading...
HPE Integrated Lights-Out (iLO) users authenticated through Active Directory/LDAP may experience authentication session termination when the directory service closes idle connections based on its configured idle timeout policy. When iLO does not generate activity within the directory server’s idle timeout window, the LDAP authentication session may be closed, requiring the user to re-authenticate.
Any HPE system with the following HPE Integrated Lights-Out (iLO) platforms configured to use Active Directory/LDAP authentication:HPE iLO 5 firmware v3.18 (or earlier)HPE iLO 6 firmware v1.74 (or earlier)HPE iLO 7 firmware v1.20 (or earlier)
To address this issue, an iLO firmware release will periodically transmit LDAP session keep-alive messages to the configured directory service. When the keep-alive feature is enabled, the LDAP authentication session remains active and is not terminated due to directory service for idle connection timeouts. The authentication session persists until the authenticated user explicitly logs out of the iLO session.For iLO 7 update to firmware v1.21 (or later)For iLO 6 update to firmware v1.75 (or later)For iLO 5, this is targeted to be resolved in a future version of iLO 5.Redfish ConfigurationTo control this behavior, iLO firmware introduces the following Redfish OEM attributes under the AccountService resource:LDAPKeepAliveEnabled: true / false (default: false)LDAPPingIntervalSeconds: 30–120 seconds (default: 30 seconds)If LDAP authentication sessions to remain active is required, enable the LDAPKeepAliveEnabled attribute.Redfish resource:Example GET Request and PATCH request body:GET /redfish/v1/AccountService/PATCH /redfish/v1/AccountService/{"Oem": {"Hpe": {"LDAPKeepAliveEnabled": true,"LDAPPingIntervalSeconds": 30}}}The iLO LDAPKeepAliveEnabled feature will ship with a default setting of false in future release of iLO 5, iLO 6, and iLO 7 firmware. If an LDAP authentication session is required to remain active, perform a one-time enablement of the LDAP keep-alive feature using the Redfish OEM interface. Once enabled, no additional configuration is required for ongoing operation.As a workaround, increase the LDAP/AD server's idle connection timeout (MaxIdleConnTimeout on Microsoft Active Directory) to a value greater than 90 seconds. However, evaluate the setting before implementation. The permanent fix, a Redfish-configurable LDAP keep-alive feature in a future iLO firmware release, HPE recommends this long-term fix and does not require any directory server changes.To download iLO 7 v1.21 (or later) or iLO 6 v1.75 (or later), perform the following steps:Click the following link:http://www.hpe.com/support/ilo6orhttp://www.hpe.com/support/ilo7The page should refresh to display the "DRIVERS AND SOFTWARE" tab and the components that support the selected product. From the "DRIVERS AND SOFTWARE" expandable filter menus on the left side of the page:For further filtering if needed - Select the specific Operating System from the Operating Environment.Locate and select theHPE Integrated Lights-Out 6 v1.75 firmwareorHPE Integrated Lights-Out 7 v1.21 firmware.click the Revision History tab to locate the latest version.For more important information, review the Release Notes tab.Click theDownloadbutton.
Operating Systems Affected:Not Applicable
Click on a version to see all relevant bugs
Hewlett Packard Enterprise Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.