92
Setting up authentication plug-ins for VCS One
Setting up LDAP authentication
■
-p
ldap_server_port
specifies the LDAP server port. The default
value is 389. To bind the server, the command uses the user name and
password. If you do not provide a user name and password, the
command prompts you to provide them.
■
-u
search_user
specifies the base search paths for users. This
option is required.
■
-g
search_group
specifies the base search paths for the group. This
option is required.
■
-f
attribute_list_file
specifies the name of the attribute list
file. By default, the name is AttributeList.txt. This file is placed in the
working directory.
■
-m
admin_username
specifies the user name of the connecting user.
When anonymous searches are disabled, this option is required to
make the initial connection to the LDAP server.
■
-w
admin_password
specifies the password of the connecting user.
When anonymous searches are disabled, this option is required to
make the initial connection to the LDAP server.
■
-l
loglevel
generates a log file named haldapconf.debug.
loglevel
determines the amount of information that goes into the log. The value
of
loglevel
ranges from 0 to 4.
The
haldapconf -d
command creates an attribute list file that contains
the valid values for all the attributes in descending order of priority. This
command also retrieves the valid values for the LDAP attributes that have
multiple values.
For example, to run
haldapconf -d
for an LDAP server named
ldapserver.com, a user named testuser, and a group named testgroup, enter
the following command:
#
/opt/VRTSvcsone/bin/
haldapconf -d -s ldapserver.com
\
-u testuser -g testgroup
2
Determine the highest priority attribute and create an authentication CLI
that includes
haat addldapdomain
by running the following command:
#
/opt/VRTSvcsone/bin/haldapconf -c -d domainname
\
[-i
attribute_list_file
] [-o
at_cli_file
] [-a FLAT|BOB]
\
[-s BASE|ONE|SUB] [-l
loglevel
]
where:
■
-d
domain_name
specifies the domain name. The domain name must
be unique.
■
-i
attribute_list_file
specifies the name of the attribute list
file. By default, the name is AttributeList.txt. The file is placed in the
working directory.
Summary of Contents for Veritas Cluster Server One
Page 1: ...Veritas Cluster Server One Installation Guide AIX HP UX Linux Solaris 5 0...
Page 3: ...Symantec Corporation 350 Ellis Street Mountain View CA 94043 http www symantec com...
Page 16: ...16 Contents...
Page 34: ...34 Getting ready to install VCS One Configuring ssh rsh or remsh before installing...
Page 82: ...82 Installing the Simulator Installing the Simulator...
Page 126: ...126 Upgrading from VCS One 2 0 1 to 5 0 Upgrading the client...
Page 148: ...148 Sample Policy Master upgrade scenarios Upgrade scenario details...
Page 194: ...194 Sample installation output Installing the VCS One client...
Page 210: ...210 Index...