![NetApp AltaVault AVA400 Administration Manual Download Page 87](http://html.mh-extra.com/html/netapp/altavault-ava400/altavault-ava400_administration-manual_1669933087.webp)
NetApp AltaVault Cloud Integrated Storage Administration Guide
87
Beta Draft
Setting RADIUS servers
Configuring security settings
11.
Under Authentication Methods, select Kerberos/AD Only from the drop down menu and click
Apply
to save your
settings and enable management login from AD.
Note:
You must have joined the AD domain and have created an admin user account prior to setting the authentication method.
12.
Optionally, if your security policy requires that user passwords cannot be stored locally, choose Configure > User
permissions from the Management Console. Select the user you wish to edit, and check the box
External
Authentication Only
.
When this box is checked, the local password for this user is deleted from AltaVault and you must log in using
AD credentials.
13.
Optionally, to further limit AltaVault logins to use AD credentials only, disable SSH public key authentication in
the CLI:
no ssh server pub-key-auth
Login behavior using AD
After enabling Kerberos for Active Directory login, accessing AltaVault has the following behaviors:
Password authentication will be checked against Active Directory credentials, not local passwords.
If the user password is changed in Active Directory, that user must log in using the new Active Directory
password.
If user is disabled or deleted in Active Directory, that user will not be able to log in to the AltaVault. To avoid
losing access to the AltaVault, it is recommended that you configure more than one Admin user account for
Active Directory access.
AltaVault supports only individual Active Directory user accounts.
Setting RADIUS servers
You can optionally configure Remote Authentication Dial-in User Server (RADIUS) server authentication in the
Configure > RADIUS page.
RADIUS is an access control protocol that uses a challenge and response method for authenticating users.
To configure RADIUS server authentication
1.
Choose Configure > RADIUS.
2.
Under Default RADIUS Settings, complete the configuration as described in this table.
Control
Description
Set a Global Default Key
Enables a global server key for the RADIUS server.
Global Key
Specify the global server key.
Confirm Global Key
Confirm the global server key.
Summary of Contents for AltaVault AVA400
Page 2: ...Beta Draft ...
Page 10: ...Beta Draft Contents ...