Figure 2. Configuration of CMC with Generic LDAP
Configuring the Generic LDAP Directory to Access CMC
The CMC's Generic LDAP implementation uses two phases in granting access to a user—user authentication and then
user authorization.
Authentication of LDAP Users
Some directory servers require a bind before any searches can be performed against a specific LDAP server.
To authenticate a user:
1.
Optionally bind to the Directory Service. The default is an anonymous bind.
2.
Search for the user based upon their user login. The default attribute is
uid
.
3.
If more than one object is found, then the process returns an error.
4.
Unbind and perform a bind with the user's DN and password.
5.
If the bind fails, then the login fails.
If these steps succeed, the user is authenticated.
Authorization of LDAP Users
To authorize a user:
1.
Search each configured group for the user's domain name within the
member or uniqueMember
attributes.
An administrator can configure this field.
2.
For every group the user is a member of, add their privileges together.
Configuring Generic LDAP Directory Service Using CMC Web-Based Interface
To configure the generic LDAP directory service using Web interface:
NOTE: You must have Chassis Configuration Administrator privilege.
127
Содержание Chassis Management Controller
Страница 1: ...Dell Chassis Management Controller Firmware Version 4 3 User s Guide ...
Страница 42: ...42 ...
Страница 56: ...56 ...
Страница 84: ...84 ...
Страница 98: ...98 ...
Страница 104: ...104 ...
Страница 130: ...130 ...
Страница 136: ...136 ...
Страница 200: ...200 ...
Страница 214: ...214 ...