166
Fabric OS Administrator’s Guide
53-1002745-02
Remote authentication
5
Two operational modes exist in LDAP authentication: FIPS mode and non-FIPS mode. This section
discusses LDAP authentication in non-FIPS mode. For information on LDAP in FIPS mode, refer to
Chapter 7, “Configuring Security Policies”
. The following restrictions exist when using OpenLDAP in
non-FIPS mode:
•
You must use the Common-Name for OpenLDAP authentication. User-Principal-Name is not
supported in OpenLDAP.
•
OpenLDAP 2.4.23 is supported.
When a user is authenticated, the role of the user is obtained from the memberOf attribute, which
determines group membership. This feature is supported in OpenLDAP through the memberOf
overlay. You must use this overlay on the OpenLDAP server to assign membership information.
For OpenLDAP servers, you can use the ldapCfg
-–
maprole
ldap_role_name switch_role
command
to map LDAP server permissions to one of the default roles available on a switch. For more
information on RBAC roles, see
“Role-Based Access Control”
on page 134.
OpenLDAP server configuration overview
For complete details about how to install and configure an OpenLDAP server, refer to the OpenLDAP
user documentation at http://www.openldap.org/doc/. A few key steps for the Brocade
environment are outlined here.
1. If your OpenLDAP server needs to be verified by the LDAP client (that is, the Brocade switch),
then you must install a Certificate Authority (CA) certificate on the OpenLDAP server.
Follow OpenLDAP instructions for generating and installing CA certificates on an OpenLDAP
server.
2. Enable group membership through the memberOf mechanism by including the memberOf
overlay in the slapd.conf file.
3. Create entries (users) in the OpenLDAP Directory.
4. Assign users to groups by using the member attribute.
5. Use the ldapCfg
-–
maprole
ldap_role_name switch_role
command to map an LDAP server role
to one of the default roles available on the switch.
6. Add the user’s Administrative Domains or Virtual Fabrics to the user entry by performing the
following steps.
a. Add the brcdAdVfData attribute to the existing OpenLDAP schema,
b. Add the brcdAdVfData attribute to the user entry in the LDAP directory with a value that
identifies the Administrative Domains or Virtual Fabrics with which to associate the user.
Enabling group membership
Group membership in OpenLDAP is specified by an overlay called memberOf. Overlays are helpful
in customizing the backend behavior without requiring changes to the backend code. The
memberOf overlay updates the memberOf attribute whenever changes occur to the membership
attribute of entries of the groupOfNames objectClass. To include this overlay, add “overlay
memberof” to the slapd.conf file, as shown in the following example.
overlay memberof
Example file:
include /usr/local/etc/openldap/schema/core.schema
Содержание Fabric OS 7.1.0
Страница 1: ...53 1002745 02 25 March 2013 Fabric OS Administrator s Guide Supporting Fabric OS 7 1 0 ...
Страница 24: ...24 Fabric OS Administrator s Guide 53 1002745 02 ...
Страница 28: ...28 Fabric OS Administrator s Guide 53 1002745 02 ...
Страница 32: ...32 Fabric OS Administrator s Guide 53 1002745 02 ...
Страница 42: ...42 Fabric OS Administrator s Guide 53 1002745 02 ...
Страница 116: ...116 Fabric OS Administrator s Guide 53 1002745 02 Inter switch links 4 FIGURE 7 Virtual channels on a QoS enabled ISL ...
Страница 132: ...132 Fabric OS Administrator s Guide 53 1002745 02 Frame Redirection 4 ...
Страница 194: ...194 Fabric OS Administrator s Guide 53 1002745 02 Ports and applications used by switches 6 ...
Страница 254: ...254 Fabric OS Administrator s Guide 53 1002745 02 Brocade configuration form 8 ...
Страница 274: ...274 Fabric OS Administrator s Guide 53 1002745 02 Validating a firmware download 9 ...
Страница 302: ...302 Fabric OS Administrator s Guide 53 1002745 02 Creating a logical fabric using XISLs 10 ...
Страница 344: ...344 Fabric OS Administrator s Guide 53 1002745 02 Concurrent zone transactions 11 ...
Страница 374: ...374 Fabric OS Administrator s Guide 53 1002745 02 Setting up TI over FCR sample procedure 12 ...
Страница 432: ...432 Fabric OS Administrator s Guide 53 1002745 02 Access Gateway N_Port failover with FA PWWN 16 ...
Страница 462: ...462 Fabric OS Administrator s Guide 53 1002745 02 ...
Страница 490: ...490 Fabric OS Administrator s Guide 53 1002745 02 Ports on Demand 18 ...
Страница 498: ...498 Fabric OS Administrator s Guide 53 1002745 02 Supported topologies for ICL connections 19 ...
Страница 626: ...626 Fabric OS Administrator s Guide 53 1002745 02 Preparing a switch for FIPS B ...
Страница 630: ...630 Fabric OS Administrator s Guide 53 1002745 02 Hexadecimal Conversion C ...
Страница 666: ...666 Fabric OS Administrator s Guide 53 1002745 02 ...