The following sections briefly describe each user-authentication method.
Microsoft Active Directory (AD)
With this method, the Microsoft Active Directory (AD) infrastructure authenticates
users. To join the Active Directory domain, these users must have Domain Admin
privileges. For information on configuring Storwize V7000 Unified systems with
active Directory, see Authentication using Microsoft Active Directory. The Active
Directory verifies the user credentials and supplies Storwize V7000 Unified with
the CIFS user security identifier (SID) and group information. By default, Storwize
V7000 Unified maps these SIDs to arbitrary internal UNIX IDs. This method
requires no maintenance. Use this method only if accessing the same data with the
same user names, through both CIFS and NFS, is not required.
Microsoft Active Directory can be combined with Microsoft Services for UNIX
(SFU) or NIS ID lookup to allow synchronizing the used UNIX IDs through both
CIFS and NFS. If you are considering or plan to consider implementing a disaster
recovery site using asynchronous replication, this method must be combined with
Microsoft SFU or NIS ID lookup.
Lightweight Directory Access Protocol (LDAP)
With this method, a Lightweight Directory Access Protocol (LDAP) user directory
authenticates users. The LDAP directory verifies the user credentials and supplies
Storwize V7000 Unified with the CIFS user ID and group information as SIDs. It
also supplies Storwize V7000 Unified with NFS UIDs so that additional Storwize
V7000 Unified mapping is not required. This method allows using the same user
names on both NFS and CIFS. Implementing this method might require additions
to the LDAP schema.
Netgroups, managed by an LDAP server, are enabled when the cfgldap command
is executed. You must define netgroups on the LDAP server, and create the NFS
export. When creating the NFS export for use by LDAP netgroups, the NFS option
must be specified in the format @
netgroup_name
(rw,root_squash).
Samba Primary Domain Controller (PDC) - NT4
With this method, a Samba Primary Domain Controller (PDC) infrastructure
authenticates users. The Samba PDC verifies the user credentials and supplies
Storwize V7000 Unified with the CIFS user SID and group information. By default,
Storwize V7000 Unified maps these IDs to arbitrary internal UNIX IDs. The
administrator maintains the NFS UIDs. Use this method only if accessing the same
data with the same user names, through both CIFS and NFS, is not required.
This method can be combined with NIS ID lookup to allow using the same user
names on both NFS and CIFS.
Network Information Service (NIS) - NFS NetGroup support
This method can be combined with the Microsoft Active Directory method to allow
using the same user names on both NFS and CIFS. To translate CIFS user IDs into
NFS UIDs, Storwize V7000 Unified matches the user name and queries the NIS to
retrieve the NFS UID. A set of restriction and mapping rules is available to
customize the lookup process. Examples of these rules include which NIS domain
to use for looking up an Active Directory user and what happens to users that are
unknown to one of the directories. The administrator maintains the NFS UIDs.
20
IBM Storwize V7000 Unified: Adding Storwize V7000 File Modules to an existing Storwize V7000 system 2073-720
Содержание Storwize V7000
Страница 20: ...xx IBM Storwize V7000 Unified Adding Storwize V7000 File Modules to an existing Storwize V7000 system 2073 720...
Страница 60: ...40 IBM Storwize V7000 Unified Adding Storwize V7000 File Modules to an existing Storwize V7000 system 2073 720...
Страница 88: ...68 IBM Storwize V7000 Unified Adding Storwize V7000 File Modules to an existing Storwize V7000 system 2073 720...
Страница 128: ...108 IBM Storwize V7000 Unified Adding Storwize V7000 File Modules to an existing Storwize V7000 system 2073 720...
Страница 132: ...112 IBM Storwize V7000 Unified Adding Storwize V7000 File Modules to an existing Storwize V7000 system 2073 720...
Страница 138: ...118 IBM Storwize V7000 Unified Adding Storwize V7000 File Modules to an existing Storwize V7000 system 2073 720...
Страница 142: ...122 IBM Storwize V7000 Unified Adding Storwize V7000 File Modules to an existing Storwize V7000 system 2073 720...
Страница 150: ...130 IBM Storwize V7000 Unified Adding Storwize V7000 File Modules to an existing Storwize V7000 system 2073 720...
Страница 151: ......
Страница 152: ...Part Number 00MJ333 Printed in USA SC27 4223 05 1P P N 00MJ333...