HP 3PAR StoreServ 7400 2-node HP 3PAR Command Line Interface Administrator& - Page 37

groups, the, Although 3PARuser is also a member of

Page 37 highlights

3. Issue the checkpassword command to verify that the users have the roles you assigned for the desired groups. Use a member of a specific group to verify the role. Example: system1 cli% setauthparam -f super-map software system1 cli% setauthparam -f edit-map engineering system1 cli% setauthparam -f browse-map hardware In the example above: • Users belonging to the software group are configured to have Super rights within the system. • Users belonging to the engineering group are configured to have Edit rights within the system. • Users belonging to the hardware group are configured to have Browse rights within the system. system1 cli% checkpassword 3paruser password: + attempting authentication and authorization using system-local data + authentication denied: unknown username + attempting authentication and authorization using LDAP + connecting to LDAP server using URI: ldaps://192.168.10.13 + simple bind to LDAP user 3paruser for DN uid=3paruser,ou=people,dc=ldaptest,dc=3par,dc=com + searching LDAP using: search base: ou=people,dc=ldaptest,dc=3par,dc=com filter: (&(objectClass=posixAccount)(uid=3paruser)) for attributes: gidNumber + search result DN: uid=3paruser,ou=people,dc=ldaptest,dc=3par,dc=com + search result: gidNumber: 2345 + searching LDAP using: search base: ou=groups,dc=ldaptest,dc=3par,dc=com filter: (&(objectClass=posixGroup)(|(gidNumber=2345)(memberUid=3paruser))) for attributes: cn + search result DN: cn=software,ou=groups,dc=ldaptest,dc=3par,dc=com + search result: cn: software + search result DN: cn=engineering,ou=groups,dc=ldaptest,dc=3par,dc=com + search result: cn: engineering + search result DN: cn=hardware,ou=groups,dc=ldaptest,dc=3par,dc=com + search result: cn: hardware + mapping rule: super mapped to by software + rule match: super mapped to by software + mapping rule: edit mapped to by engineering + rule match: edit mapped to by engineering + mapping rule: browse mapped to by hardware + rule match: browse mapped to by hardware user 3paruser is authenticated and authorized In the example above: • User 3PARuser is found to be a member of the software group and is assigned Super rights within the system. • Although 3PARuser is also a member of the engineering and hardware groups, the Super rights associated with the Software group supersede the Edit and Browse rights associated with the engineering and software groups. • The mapping rules set for 3PARuser are applied to all members of the software, engineering, and hardware groups; all software group members have Super Configuring LDAP Connections 37

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204

3.
Issue the
checkpassword
command to verify that the users have the roles you assigned for
the desired groups. Use a member of a specific group to verify the role.
Example
:
system1 cli% setauthparam -f super-map software
system1 cli% setauthparam -f edit-map engineering
system1 cli% setauthparam -f browse-map hardware
In the example above:
Users belonging to the
software
group are configured to have Super rights within the
system.
Users belonging to the
engineering
group are configured to have Edit rights within
the system.
Users belonging to the
hardware
group are configured to have Browse rights within the
system.
system1 cli% checkpassword 3paruser
password:
+ attempting authentication and authorization using system-local data
+ authentication denied: unknown username
+ attempting authentication and authorization using LDAP
+ connecting to LDAP server using URI: ldaps://192.168.10.13
+ simple bind to LDAP user 3paruser for DN
uid=3paruser,ou=people,dc=ldaptest,dc=3par,dc=com
+ searching LDAP using:
search base:
ou=people,dc=ldaptest,dc=3par,dc=com
filter:
(&(objectClass=posixAccount)(uid=3paruser))
for attributes: gidNumber
+ search result DN: uid=3paruser,ou=people,dc=ldaptest,dc=3par,dc=com
+ search result:
gidNumber: 2345
+ searching LDAP using:
search base:
ou=groups,dc=ldaptest,dc=3par,dc=com
filter:
(&(objectClass=posixGroup)(|(gidNumber=2345)(memberUid=3paruser)))
for attributes: cn
+ search result DN: cn=software,ou=groups,dc=ldaptest,dc=3par,dc=com
+ search result:
cn: software
+ search result DN: cn=engineering,ou=groups,dc=ldaptest,dc=3par,dc=com
+ search result:
cn: engineering
+ search result DN: cn=hardware,ou=groups,dc=ldaptest,dc=3par,dc=com
+ search result:
cn: hardware
+ mapping rule: super mapped to by software
+ rule match: super mapped to by software
+ mapping rule: edit mapped to by engineering
+ rule match: edit mapped to by engineering
+ mapping rule: browse mapped to by hardware
+ rule match: browse mapped to by hardware
user 3paruser is authenticated and authorized
In the example above:
User 3PARuser is found to be a member of the
software
group and is assigned Super
rights within the system.
Although 3PARuser is also a member of the
engineering
and
hardware
groups, the
Super rights associated with the
Software
group supersede the Edit and Browse rights
associated with the
engineering
and
software
groups.
The mapping rules set for 3PARuser are applied to all members of the
software
,
engineering
, and
hardware
groups; all
software
group members have Super
Configuring LDAP Connections
37