
4. Click Add a directory server.
5. Enter the data requested on the screen. Click “Help on this page” in the CloudSystem Console
for more information.
a. Specify the host name (not the IP address) of the directory server, and the server port
number.
The port is used to communicate with the LDAP server using the LDAPS protocol. The
default port for LDAP over SSL is 636.
b. Obtain the directory server certificate. Enter the following command:
openssl s_client –host <directory-server-FQDN> -port 636
NOTE: If you are using a load-balanced (round robin) solution for your directory server,
obtain the FQDN of one node in the server by entering the following commands.
nslookup <directory-server-FQDN>
A list of IP addresses is returned. Select one IP address and enter:
nslookup <directory-server-IP address>
Enter the FQDN returned for this IP address as the <directory-server-FQDN> in the
openssl command above.
c. Copy the X509 certificate for the server and paste it into the box on the screen.
6. Click Add to add the server and return to the Add Directory screen.
Add a directory group
You add a directory group that exists in the authentication directory service by which users will be
authenticated through the directory service. You assign the group full access to resources or a
subset of resources based on job responsibilities.
Prerequisites
• Minimum required privileges: Infrastructure administrator
• The group exists in the authentication directory service.
• You know the credentials of a directory service user.
The appliance uses these credentials to confirm the user’s permission to access it. The credentials
are not saved on the appliance.
• The directory service must be added to the appliance. For more information, see Add a
directory service (page 55).
Procedure 17 Adding a group with directory-based authentication
1. From the main menu, select Users and Groups→Actions→Add Directory Group.
2. Enter the data requested on the screen. Click “Help on this page” in the CloudSystem Console
for more information.
a. Select the authentication directory service.
b. Enter the credentials to log in to the directory service.
c. Click Connect.
You can use the same credentials that you specified on the Add Directory screen. You
can also use different credentials, if desired.
d. Select the group from the menu.
Configuring CloudSystem to use Active Directory or OpenLDAP directory authentication 59
Comentarios a estos manuales