this server because your skilled people will best be able to customize and tune the
server. your experts will be able to provide the most reliable and highly available
implementation for the LDAP infrastructure.
Role mapping
Before any LDAP user can be granted access to the storage system, the user must
be a member of an appropriate LDAP group.
Important:
An LDAP user cannot be a member of more than one LDAP group, so
it cannot be associated with more than one storage system role mapping.
When initially planning to use LDAP-based authentication with your storage
system, the LDAP attribute can be used for role mapping. The type of LDAP object
classes used to create a user account for system authentication depends on the type
of LDAP server being used.
The Oracle Directory server and Open LDAP use the
inetOrgPerson
LDAP object
class, and Active Directory uses the
organizationalperson
LDAP object class for
definition of user accounts for storage system authentication.
For a definition of the
inetOrgPerson
LDAP object class and list of attributes, see
the Internet FAQ archive website:
www.faqs.org/rfcs/rfc2798.html
For a definition of the
organizationalperson
LDAP object class and list of
attributes, see the Microsoft website:
msdn.microsoft.com/en-us/library/ms683883 (VS.85).aspx
The role mapping can be done by either assigning the appropriate attribute value
through the
ldap_config_set
CLI command, or through the IBM Hyper-Scale
Manager UI.
Managing multiple systems in LDAP authentication mode and
single sign-on (SSO)
The task of managing multiple IBM FlashSystem A9000 and A9000R systems can
be simplified by using LDAP authentication mode.
As a result of all user credentials being stored centrally in the LDAP directory, it is
no longer necessary to synchronize user credentials among multiple storage
systems. After a user account is registered in LDAP, multiple storage systems can
use credentials stored in LDAP directory for authentication.
Because the user's password is stored in the LDAP directory, all connected storage
systems authenticate the user with the password. If the password is changed, all
storage systems automatically accept the new password.
This mode of operation is often referred to as single sign-on (SSO). SSO allows for
quick transitions between systems in the IBM Hyper-Scale Manager UI because the
password is only entered once.
This approach is especially useful in remote mirroring configurations, where the
storage administrator is required to frequently switch from source to target system.
Chapter 5. Network and host connectivity requirements
73
Summary of Contents for 9835-415
Page 1: ...IBM FlashSystem A9000R Models 9835 415 and 9837 415 Deployment Guide GC27 8565 03 IBM ...
Page 5: ...Index 99 Contents v ...
Page 6: ...vi IBM FlashSystem A9000R Models 9835 415 and 9837 415 Deployment Guide ...
Page 8: ...viii IBM FlashSystem A9000R Models 9835 415 and 9837 415 Deployment Guide ...
Page 10: ...x IBM FlashSystem A9000R Models 9835 415 and 9837 415 Deployment Guide ...
Page 22: ...xxii IBM FlashSystem A9000R Models 9835 415 and 9837 415 Deployment Guide ...
Page 26: ...4 IBM FlashSystem A9000R Models 9835 415 and 9837 415 Deployment Guide ...
Page 30: ...8 IBM FlashSystem A9000R Models 9835 415 and 9837 415 Deployment Guide ...
Page 84: ...62 IBM FlashSystem A9000R Models 9835 415 and 9837 415 Deployment Guide ...
Page 100: ...78 IBM FlashSystem A9000R Models 9835 415 and 9837 415 Deployment Guide ...
Page 110: ...88 IBM FlashSystem A9000R Models 9835 415 and 9837 415 Deployment Guide ...
Page 112: ...90 IBM FlashSystem A9000R Models 9835 415 and 9837 415 Deployment Guide ...
Page 120: ...98 IBM FlashSystem A9000R Models 9835 415 and 9837 415 Deployment Guide ...
Page 124: ...102 IBM FlashSystem A9000R Models 9835 415 and 9837 415 Deployment Guide ...
Page 125: ......
Page 126: ...IBM Printed in USA GC27 8565 03 ...