Administrator Guide

Enable or Disable LDAP on Active Directory Extended Schema
Enable the extended schema option if Active Directory provides the LDAP database.
1. In the Storage view, select a FluidFS cluster.
2. Click the File System tab.
3. In the File System view, select Client Accessibility.
4. Click the Directory Services tab.
5. Click Edit Settings in the NFS User Repository section. The Edit External User Database dialog box opens.
6. Enable or disable LDAP on Active Directory extended schema:
To have Active Directory provide the LDAP database, select the Use LDAP on Active Directory Extended Schema
checkbox.
To have an LDAP server provide the LDAP database, clear the Use LDAP on Active Directory Extended Schema
checkbox.
7. Click OK.
Enable or Disable Authentication for the LDAP Connection
Enable authentication for the connection from the FluidFS cluster to the LDAP server if the LDAP server requires authentication.
1. In the Storage view, select a FluidFS cluster.
2. Click the File System tab.
3. In the File System view, select Client Accessibility.
4. Click the Directory Services tab.
5. Click Edit Settings in the NFS User Repository section. The Edit External User Database dialog box opens.
6. Enable or disable authentication for the LDAP connection:
To enable authentication for the LDAP connection, select the Non-Anonymous LDAP bind checkbox. Then, type the LDAP
bind distinguished name used to authenticate the connection in the Bind DN eld and type the LDAP bind password in the
Bind Password eld.
To disable authentication for the LDAP connection, clear the Use Non-Anonymous LDAP bind checkbox.
7. Click OK.
Enable or Disable TLS Encryption for the LDAP Connection
Enable TLS encryption for the connection from the FluidFS cluster to the LDAP server to avoid sending data in plain text. To validate
the certicate used by the LDAP server, you must export the LDAP SSL certicate and upload it to the FluidFS cluster.
1. In the Storage view, select a FluidFS cluster.
2. Click the File System tab.
3. In the File System view, select Client Accessibility.
4. Click the Directory Services tab.
5. Click Edit Settings in the NFS User Repository section. The Edit External User Database dialog box opens.
6. Enable or disable TLS encryption for the LDAP connection:
To enable TLS encryption for the LDAP connection, select the LDAP over TLS checkbox.
To disable TLS encryption for the LDAP connection, clear the LDAP over TLS checkbox.
7. If TLS encryption is enabled, enable or disable LDAP certicate validation.
To enable LDAP certicate validation, select the Install LDAP Certicate checkbox. Then, click Upload Certicate and
browse to and select the LDAP SSL certicate to upload to the FluidFS cluster.
To disable LDAP certicate validation, clear the Install LDAP Certicate checkbox.
8. Click OK.
388
FluidFS Account Management and Authentication