Cyclades AlterPath BladeManager Manuál s instrukcemi Strana 147

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 240
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 146
Chapter 6: Administration Tasks Not Performed in the Web Manager 133
Configuring Groups for Use with Authentication Servers
This information applies when an authentication method that relies on an authentication server is
configured either for the SP manager or for a target device. If the administrator of an authentication
server configures users as members of groups as described in this section, the users do not need to
have accounts configured on the SP manager.
For example, if user johnb is defined as a member of the admin group on a TACACS+ server,
johnb can log into the SP manager as an administrative user when TACACS+ authentication is
configured for the SP manager, even though no user account is configured for johnb on the SP
manager.
To support the use of groups with the authentication methods that support groups, the administrator
must configure local groups on the SP manager using the same group names used on the
authentication servers, using the Web Manager or the cli utility.
The admin group exists by default. User accounts do not need to be configured on the SP manager
for the users in the authentication
-server-defined groups.
Configuring group authorization for LDAP authentication
Group authorizations can be provided by either a Windows Active Directory (AD) server or a
server running OpenLDAP:
On an AD server, the info attribute can be used to define groups, but the memberOf attribute is
already used in the AD schema to denote domain membership and so it cannot be used to
defining groups.
On an OpenLDAP server, either the info attribute or memberof attribute can be used.
Configuring group authorizations on an AD server
Perform the following procedures for configuring support for group authorizations when a
Windows Active Directory server is used for LDAP authentication.
To install Windows Administration Pack tools and configure the snap
-in:
1. On the server, install the tools from the Windows Administration Pack. The tools are found on
the Windows server installation CD.
2. Go to the start menu and click Run.
3. In the Open field, type
mmc /a and click OK. A console window appears.
4. Click Console in the console window menu bar and select Add/Remove Snap
-in.... The Add/
Remove Snap
-in window appears.
5. Click Add. The Add Standalone Snap
-ins window appears.
6. Select Active Directory Schema from the list of snap
-ins and click Add.
7. Select ADSI Edit from the list of snap
-ins and click Add.
8. Click Close.
Zobrazit stránku 146
1 2 ... 142 143 144 145 146 147 148 149 150 151 152 ... 239 240

Komentáře k této Příručce

Žádné komentáře