![IBM System Storage TS3500 Manual Download Page 82](http://html2.mh-extra.com/html/ibm/system-storage-ts3500/system-storage-ts3500_manual_4089052082.webp)
This topic describes the Storage Authentication Service (SAS), which is an option for Web
login requests on the TS3500 Tape Library.
When the Storage Authentication Service (SAS) is enabled, the TS3500 Tape Library passes
user authentication requests to a centralized System Storage™ Productivity Center (SSPC)
or Tivoli® Storage Productivity Center (TPC) for verification. This authentication validates a
user's ID and password when logging in to one or more tape libraries.
The SSPC or TPC then accesses the customer's Lightweight Directory Access Protocol (LDAP)
server. The LDAP server is a central repository for storage and management of user IDs,
passwords, and roles. This central repository allows you to accomplish the following security
tasks from a single interface, without logging in to a TS3500 Tape Library:
•
Add or remove a user
•
Reset or change a password
•
Assign, change, or delete the LDAP group of a user
shows an overview of the Storage Authentication Service.
Figure 1. Storage Authentication Service overview
A central repository can also simplify the process of responding to new security
requirements for one or more tape libraries. For instance, rules for passwords can be
changed in one location without reconfiguring multiple, affected machines. By comparison,
when local authentication is employed, each individual machine maintains an internal
database of user IDs, with corresponding passwords and roles.
LDAP dependency
The SSPC or TPC receives authentication requests from the TS3500 Tape Library through
the Storage Authentication Service. The Storage Authentication Service passes userid and
password information to the LDAP server. The LDAP server returns authentication status to
the SSPC or TPC, which forwards the authentication status through the Storage
Authentication Service to the TS3500 Tape Library. The LDAP server attached to the SSPC
or TPC manages the following information: