If you previously configured a directory server in Access Management, you can change its settings at any time. Settings include the server connection information and the group-to-role mappings.
Before you begin
A directory server must be defined.
Setting | Description |
---|---|
Configuration settings | |
Domain(s) | The domain name(s) of the LDAP server(s). For multiple domains, enter the domains in a comma-separated list. The domain name is used in the login ( username @ domain ) to specify which directory server to authenticate against. |
Server URL | The URL for accessing the LDAP server
in the form of ldap[s]:// host : port
. |
Bind account (optional) | The read-only user account for search queries against the LDAP server and for searching within the groups. |
Bind password (optional) | The password for the bind account. (This field appears when a bind account is entered.) |
Test server connection before saving | Checks that the system can communicate with the LDAP server configuration. The test occurs after you click Save . If this checkbox is selected and the test fails, the configuration is not changed. You must resolve the error or clear the checkbox to skip the testing and re-edit the configuration. |
Privilege settings | |
Search base DN | The LDAP context to search for users,
typically in the form of CN=Users,
DC=copc, DC=local . |
Username attribute | The attribute that is bound to the
user ID for authentication. For example: sAMAccountName
. |
Group attribute(s) | A list of group attributes on the
user, which is used for group-to-role mapping. For example: memberOf, managedObjects .
|
Setting | Description |
---|---|
Mappings | |
Group DN | The domain name for the LDAP user group to be
mapped. Regular expressions are supported. These special regular expression
characters must be escaped with a backslash ( \ )
if they are not part of a regular expression pattern:
|
Roles | The roles to be mapped to the Group
DN. You must individually select each role you want to include for
this group. The Monitor role is required in combination with the other
roles to log in to ThinkSystem SAN Manager . The roles include the following:
|