Administrator Guide

Table Of Contents
The Directory Service Manual Configuration wizard opens.
5. From the Directory Type drop-down menu, select Active Directory or OpenLDAP.
6. Type the settings for the directory server.
In the URI field, type the uniform resource identifier (URI) for one or more servers to which Storage Center connects.
NOTE: Use the fully qualified domain name (FQDN) of the servers.
Example URIs for two servers:
ldap://server1.example.com ldap://server2.example.com:1234
NOTE: Adding multiple servers ensures continued authorization of users in the event of a resource outage. If
Storage Center cannot establish contact with the first server, Storage Center attempts to connect to the remaining
servers in the order listed.
In the Directory Server Connection Timeout field, type the maximum time (in minutes) that Storage Center waits
while attempting to connect to an Active Directory server. This value must be greater than zero.
In the Base DN field, type the base distinguished name for the LDAP server. The Base DN is the starting point when
searching for users.
In the Relative Base field, type the Relative Base information. A Relative Base is a list of Relative Distinguished Names
(RDN) prepended to the Base DN, indicating where the controller should be joined to the domain. An RDN contains an
attribute and a value, such as:
OU=SAN Controllers
OU is the attribute, and SAN Controllers is the value.
The following special characters used within an RDN value must be escaped using a backslash:
, + " \ < > ; = / CR and LF
For example:
Relative Base
: OU=SAN Controllers
(No escapes necessary)
Relative Base: OU=SAN\+Controllers
(The plus character is escaped)
Relative Base: OU=Buildings A\,B\,C,OU=SAN \+Controllers
(Commas and plus sign are escaped
except for the comma separating the
RDNs.)
In the Storage Center Hostname field, type the fully qualified domain name (FQDN) of the Storage Center.
For a single-controller Storage Center system, this is the fully qualified host name for the controller IP address.
For a dual-controller Storage Center system, this is the fully qualified host name for the management IP address.
In the LDAP Domain field, type the LDAP domain to search.
In the Authentication Bind DN field, type the Distinguished Name or User Principal Name of the user that the Storage
Center uses to connect to and search the LDAP server.
In the Authentication Bind Password field, type the password for the authentication bind Distinguished Name.
7. (Optional) Click Test Server to verify that the Storage Center can communicate with the specified directory servers using
the selected protocol.
8. (Optional) If Transport Layer Security (TLS) is enabled, upload a Certificate Authority PEM file.
a. Click Upload Certificate Authority PEM.
b. Browse to the location of the PEM file, select the file, and click Select. The Upload TLS Certificate dialog box opens.
NOTE:
If you select the wrong PEM file, click Upload Certificate in the Upload TLS Certificate dialog box to
select a new file.
c. Click OK to upload the certificate.
9. Click Next. The Kerberos Settings page opens.
240
Storage Center Maintenance