Oracle ZFS Storage Appliance Administration Manual page 291

Hide thumbs Also See for ZFS Storage Appliance:
Table of Contents

Advertisement

Authentication method - Method used to authenticate the appliance to the LDAP server.
You can only configure this setting if authenticating as Proxy.
LDAP Servers
Servers- List of LDAP servers to use. If only one server is specified, the appliance uses
only that server and LDAP services are unavailable if that server fails. If multiple servers
are specified, any functioning server can be used at any time without preference. If any
server fails, another server in the list is used. LDAP services remain available unless all
specified servers fail.
Related Topics
"Configuring LDAP Security Settings (BUI)" on page 287
"Configuring LDAP Security Settings (CLI)" on page 288
LDAP Custom Mappings
To look up users and groups in the LDAP directory, the appliance uses a search descriptor
and must know which object classes correspond to users and groups and which attributes
correspond to the properties needed. By default, the appliance uses object classes specified
by RFC 2307 (posixAccount and posixGroup) and the default search descriptors shown in the
following list, but this can be customized for different environments. The base search DN used
in the examples below is dc=example,dc=com:
LDAP Custom Mappings
TABLE 76
Search descriptor
users
groups
netgroups
The search descriptor, object classes, and attributes used can be customized using the Schema
definition property. To override the default search descriptor, enter the entire DN you wish to
use. The appliance will use this value unmodified, and will ignore the values of the Base search
DN and Search scope properties. To override user, group, and netgroup attributes and objects,
choose the appropriate tab ("Users", "Groups", or "Netgroups") and specify mappings using the
default = new syntax, where default is the default value and new is the value you want to use.
For examples:
To use unixaccount instead of posixAccount as the user object class, enter posixAccount =
unixaccount in Object class mappings on the Users tab.
Default value
ou=people,base search DN
ou=group,base search DN
ou=netgroup,base search DN
Configuring LDAP Security Settings (CLI)
Example
ou=people,dc=example,dc=com
ou=group,dc=example,dc=com
ou=netgroup,dc=example,dc=com
Appliance Services
291

Advertisement

Table of Contents
loading

Table of Contents