
The user profile:
• Indicates if the user is to be authenticated locally,or through a RADIUS
server.
• Specifies the user's access (privilege) level, meaning it specifies if the user
is a:
○
Global administrator.
○
Storage administrator.
○
Server administrator.
○
Storage administrator.
• Specifies the servers the user is allowed to access.
• Specifies if the user has CLI access (for RADIUS and Local Users).
Active Directory user authentication
Active Directory is an LDAP-compliant hierarchical database of objects. It is
very popular in enterprise environments and is becoming a de facto standard
for user authentication.
After Active Directory connection settings and groups have been configured
for the SMU, it will allow logins from enabled users who supply their Active
Directory name and password. This is typically the same name and password
that the user would use to log into Windows and other enterprise
applications. Unlike SMU local and RADIUS user names, Active Directory user
names are case-insensitive. Active Directory passwords are case-sensitive
and cannot be changed from the SMU; they are maintained in the Active
Directory server.
There are a number of benefits for SMU users. The administrator does not
need to maintain a separate set of user details, because the SMU can just
make use of the Active Directory enterprise user database. Users can login
using their usual name and password instead of having to remember a
separate set of credentials for the SMU. And instead of configuring access for
individual users, the SMU administrator just has to specify the Active
Directory
groups
whose members have login rights.
It is possible to assign more restrictive user levels and managed severs to
Active Directory users according to their group membership. So it is possible
to define a group of users who have only
server
level access, for example, or
access to a restricted set of managed HNAS servers.
Although the SMU supports RADIUS and Active Directory for external
authentication, they are mutually exclusive; it is not possible to have them
both configured for external authentication at the same time.
When a login attempt is made, the SMU first tries to authenticate the
credentials as a local user. If that fails, and Active Directory is configured,
they are authenticated as an Active Directory user.
Active Directory authentication requests are sent to servers in the configured
sequential order. If a successful connection cannot be made to the first
Setting up security
229
System Administrator Guide for VSP Gx00 models and VSP Fx00 models
Содержание VSP F400
Страница 10: ...10 System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Страница 16: ...16 Preface System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Страница 30: ...30 System administration overview System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Страница 136: ...136 Configuring the storage system System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Страница 210: ...210 User administration System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Страница 244: ...244 Setting up security System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Страница 256: ...256 Alert notifications System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Страница 270: ...270 Managing license keys System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Страница 280: ...280 Managing storage system reports System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Страница 350: ...350 Examples of storage configuration reports System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Страница 386: ...386 System option modes System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Страница 406: ...406 Glossary System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Страница 412: ...412 Index System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Страница 413: ...System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...