
After you add an authentication directory service and server
You can:
• Allow local logins only, which is the default.
• Allow both local logins and logins for user accounts authenticated by the directory service.
• Disable local logins so that only users whose accounts are authenticated by the directory
service can log in. Local accounts are prevented from logging in.
HP does not recommend disabling local logins. If you disable local logins, Infrastructure
administrator users that are not part of a directory group cannot log into the CloudSystem
Portal.
Configuring CloudSystem to use Active Directory or OpenLDAP directory
authentication
If you want to use directory service authentication instead of the default local login to authenticate
users, you must first configure OpenLDAP or Microsoft Active Directory in the CloudSystem Console.
User authentication directories based on Lightweight Directory Access Protocol (LDAP) are used
by CloudSystem to:
• Authenticate a user's login to the CloudSystem Console and CloudSystem Portal
• Authenticate a user's access to information
When a user logs in to the CloudSystem Console or CloudSystem Portal, LDAP authenticates the
login credentials by verifying that the user name and password match an existing user in the LDAP
directory. The LDAP server that hosts the directory should already be configured.
To configure OpenLDAP or Active Directory in the CloudSystem Console, perform the following
configuration steps.
Add a directory service
A directory service contains a set of entries representing users. Each entry has a unique identifier:
its Distinguished Name (DN). The DN is constructed internally using the data you entered in the
search context fields on the Add Directory screen and the user name.
The distinguished name is defined by the following:
• CN (common name) or UID (user identifier)
Usually, the CN attribute identifies the user or group.
• OU (organizational unit) or CN (common name)
• DC (domain component)
The search context is the starting location that the authentication directory service uses to find users
in its database.
Prerequisites
• Minimum required privileges: Infrastructure administrator
• The authentication directory service must be configured, and must accept SSL connections.
• You have obtained an X509 certificate from the directory service provider. This certificate
ensures the integrity of communication between the appliance and the directory service.
Procedure 15 Adding an authentication directory service
1. From the main menu, select Settings.
2. Click the Edit icon in the Security area.
3. On the Edit Security screen, under Directories, click Add Directory.
Configuring CloudSystem to use Active Directory or OpenLDAP directory authentication 55
Comentarios a estos manuales