HP CloudSystem Foundation Guida Utente Pagina 58

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
Vedere la pagina 57
Limitations: Directory tree
Active Directory: Groups must be located under the user search base. Following are two
examples:
CN=Users
OU=US,OU=Users,OU=Accounts
OpenLDAP: Groups must be located under OU=Groups from the Base DN.
Limitations: Directory schema
An LDAP schema is a set of definitions and constraints about the structure of the directory information
tree.
Table 5 Limitations on user and group object classes in LDAP
Supported LDAP
schema object classes
for groups
Supported LDAP
schema object classes
for usersTo log in, user enters:User can log in to:Directory service
One of the following:N/AUser name, password,
and directory
CloudSystem ConsoleActive Directory
group
groupOfNames
One of the following:userUser name and
password
NOTE: Users in
authorized groups of
the default directory
can log in to the
CloudSystem Portal.
CloudSystem PortalActive Directory
group
groupOfNames
groupOfNamesN/AUser name, password,
and directory
CloudSystem ConsoleOpenLDAP
groupOfNamesinetOrgPersonUser name and
password
CloudSystem PortalOpenLDAP
Add a directory server
After you have added a directory service, you add the directory server. The directory server is the
physical or virtual machine that hosts the authentication directory service.
Prerequisites
Minimum required privileges: Infrastructure administrator
The authentication directory service must be configured, and must accept SSL connections.
You have obtained an X509 certificate from the directory service provider. This certificate
ensures the integrity of communication between the appliance and the directory service.
IMPORTANT: By default, the CloudSystem Console and CloudSystem Portal do not perform strong
LDAP server certificate validation. See Enabling strong certificate validation in the CloudSystem
Portal (page 189) for the steps you can perform to require a valid client CA certificate chain when
an OpenLDAP or Microsoft Active Directory service is used for authentication.
You can enable strong LDAP server certificate validation in the CloudSystem Portal only.
Procedure 16 Adding an authentication directory server
1. From the main menu, select Settings.
2. Click the Edit icon in the Security area.
3. On the Edit Security screen, under Directories, click Add Directory.
58 Manage users and groups
Vedere la pagina 57
1 2 ... 53 54 55 56 57 58 59 60 61 62 63 ... 210 211

Commenti su questo manuale

Nessun commento