Dell EqualLogic PS6210XS EqualLogic Group Manager Administrator s Guide PS Ser - Page 64

About LDAP Authorization and Active Directory, Add an Active Directory Server

Page 64 highlights

About LDAP Authorization and Active Directory LDAP is the abbreviation for Lightweight Directory Access Protocol, which provides a simplified protocol for authenticating users. An LDAP server typically contains a database of users, user names, passwords, and related information. LDAP clients are able to interrogate the server to authenticate these users and obtain the account characteristics. Active Directory is an LDAP-compliant database that contains objects (typically users, computers, and groups) and provides authentication and authorization mechanisms in which other related services can be deployed. If your environment uses Active Directory, you can authenticate administrator sessions using LDAP. Individual Active Directory users, or entire Active Directory groups, can be given group, pool, or volume administrator privileges. To use LDAP authentication, you must first configure the group to communicate with one or more LDAP servers. The Active Directory Configuration wizard enables you to configure NTP and DNS or modify the existing NTP or DNS configuration. You can also perform these tasks at a later time. See theDell EqualLogic PS Series Storage Arrays Release Notes for more information about NTP requirements for using Active Directory in a NAS cluster. To use Active Directory in a NAS cluster: • The Active Directory server and the PS Series group must use a common source of time. • You must configure the NAS cluster to use DNS. The DNS servers you specify must be the same DNS servers that your Active Directory domain controllers use. Add an Active Directory Server 1. Click Group → Group Configuration. 2. Click the Administration tab. 3. In the Authentication panel, select Active Directory as the authentication type. • If no Active Directory servers have been added yet, the Active Directory settings dialog box opens. • If one or more Active Directory servers have already been added, click AD settings to open the Active Directory settings dialog box. 4. In the Active Directory settings dialog box, click Add. The Add List Item dialog box opens and prompts you to enter the AD server's IP address. 5. Type in the IP address for the Active Directory server and click OK. The IP address appears in the list of Active Directory servers. Configure Active Directory Authentication To configure LDAP authentication for the group: 1. Click Group → Group Configuration. 2. Click the Administration tab. 3. In the Authentication panel, set the authentication type to Active Directory and click AD settings to display the Active Directory Settings dialog box. 4. In the Active Directory servers section, click Add. The Add List Item dialog box opens. 5. Type the IP address of the Active Directory server and click OK. 6. Repeat steps 3 to 5 to add up to three IP addresses. NOTE: Adding multiple Active Directory servers ensures continued authentication of Active Directory accounts even in the event of a resource outage. The group uses the first Active Directory server in the list for authenticating accounts; if the group cannot establish contact with the first server, it uses the other Active Directory servers to authenticate administrator logins. 7. Select the Active Directory server that you want to configure. 8. In the AD server settings section, select Secure protocol: and choose TLS or none. 64 About Group-Level Security

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355

About LDAP Authorization and Active Directory
LDAP is the abbreviation for Lightweight Directory Access Protocol, which provides a
simplified
protocol for authenticating users. An
LDAP server typically contains a database of users, user names, passwords, and related information. LDAP clients are able to
interrogate the server to authenticate these users and obtain the account characteristics.
Active Directory is an LDAP-compliant database that contains objects (typically users, computers, and groups) and provides
authentication and authorization mechanisms in which other related services can be deployed.
If your environment uses Active Directory, you can authenticate administrator sessions using LDAP. Individual Active Directory users,
or entire Active Directory groups, can be given group, pool, or volume administrator privileges.
To use LDAP authentication, you must
first
configure
the group to communicate with one or more LDAP servers.
The Active Directory
Configuration
wizard enables you to
configure
NTP and DNS or modify the existing NTP or DNS
configuration.
You can also perform these tasks at a later time. See the
Dell EqualLogic PS Series Storage Arrays Release Notes
for more
information about NTP requirements for using Active Directory in a NAS cluster.
To use Active Directory in a NAS cluster:
The Active Directory server and the PS Series group must use a common source of time.
You must
configure
the NAS cluster to use DNS. The DNS servers you specify must be the same DNS servers that your Active
Directory domain controllers use.
Add an Active Directory Server
1.
Click
Group
Group
Configuration
.
2.
Click the
Administration
tab.
3.
In the Authentication panel, select
Active Directory
as the authentication type.
If no Active Directory servers have been added yet, the Active Directory settings dialog box opens.
If one or more Active Directory servers have already been added, click
AD settings
to open the Active Directory settings
dialog box.
4.
In the Active Directory settings dialog box, click
Add
. The Add List Item dialog box opens and prompts you to enter the AD
server’s IP address.
5.
Type in the IP address for the Active Directory server and click
OK
. The IP address appears in the list of Active Directory
servers.
Configure
Active Directory Authentication
To
configure
LDAP authentication for the group:
1.
Click
Group
Group
Configuration
.
2.
Click the
Administration
tab.
3.
In the Authentication panel, set the authentication type to
Active Directory
and click
AD settings
to display the Active
Directory Settings dialog box.
4.
In the Active Directory servers section, click
Add
. The Add List Item dialog box opens.
5.
Type the IP address of the Active Directory server and click
OK
.
6.
Repeat steps 3 to 5 to add up to three IP addresses.
NOTE: Adding multiple Active Directory servers ensures continued authentication of Active Directory accounts even
in the event of a resource outage. The group uses the
first
Active Directory server in the list for authenticating
accounts; if the group cannot establish contact with the
first
server, it uses the other Active Directory servers to
authenticate administrator logins.
7.
Select the Active Directory server that you want to
configure.
8.
In the AD server settings section, select
Secure protocol:
and choose
TLS or none
.
64
About Group-Level Security