92
MergePoint Service Processor Manager SP53XX Installer/User Guide
configures users as members of groups as described in this section, the users do not need to have
accounts configured on the MergePoint SP manager.
For example, user johnb is defined as a member of the admin group on a server, but
does not have a user account on the MergePoint SP manager. If the MergePoint SP manager is
configured for authentication, johnb can log into the MergePoint SP manager as an
adminstrator.
To support the use of groups with the authentication methods that support groups, the administrator
must configure local groups on the MergePoint SP manager using the same group names used on
the authentication servers, using the web interface or the CLI utility.
The admin group exists by default. User accounts do not need to be configured on the MergePoint
SP manager for the users in the authentication server defined groups.
Configuring group authorization for LDAP authentication
Group authorizations can be provided by either a Windows Active Directory (AD) server or a
server running OpenLDAP:
•
On an AD server, the info attribute can be used to define groups, but the memberOf attribute is
already used in the AD schema to denote domain membership and so it cannot be used to
defining groups.
•
On an OpenLDAP server, either the info attribute or memberof attribute can be used.
Configuring group authorizations on an AD server
Perform the following procedures for configuring support for group authorizations when a
Windows Active Directory server is used for LDAP authentication.
To install Windows Administration Pack tools and configure the snapin:
1.
On the server, install the tools from the Windows Administration Pack. The tools are found on
the Windows server installation CD.
2.
Go to the start menu and click Run.
3.
In the Open field, type
mmc /a
and click OK. A console window appears.
4.
Click Console in the console window menu bar and select Add/Remove Snapin. The Add/
Remove Snapin window appears.
5.
Click Add. The Add Standalone Snapins window appears.
6.
Select Active Directory Schema from the list of snapins and click Add.
7.
Select ADSI Edit from the list of snapins and click Add.
8.
Click Close, then click OK in the Add/Remove Snapin window.
To configure Active Directory schema:
1.
In the server’s console window, double-click Active Directory Schema. The paths Classes and
Attributes appear.
Содержание MERGEPOINT 53XX SP MANAGER
Страница 1: ...MERGEPOINT 53XX SP MANAGER Installer User Guide...
Страница 12: ...x MergePoint Service Processor Manager SP53XX Installer User Guide...
Страница 14: ...xii MergePoint Service Processor Manager SP53XX Installer User Guide...
Страница 22: ...8 MergePoint Service Processor Manager SP53XX Installer User Guide...
Страница 80: ...66 MergePoint Service Processor Manager SP53XX Installer User Guide...
Страница 96: ...82 MergePoint Service Processor Manager SP53XX Installer User Guide...
Страница 138: ...124 MergePoint Service Processor Manager SP53XX Installer User Guide...
Страница 160: ...146 MergePoint Service Processor Manager SP53XX Installer User Guide...
Страница 202: ...188 MergePoint Service Processor Manager SP53XX Installer User Guide...
Страница 203: ......
Страница 204: ...For Technical Support www avocent com support 590 839 501D...