Administrator Guide

Table Of Contents
Enabling Directory Services Authentication
Before you can grant Storage Center access to directory users and directory user groups, you must first configure Storage
Center to communicate with one or more Active Directory/OpenLDAP servers. If you use Kerberos authentication, you must
also configure Storage Center to communicate with the Kerberos Key Distribution Center (KDC).
Prerequisites
An Active Directory or OpenLDAP directory service must be deployed in your environment.
Storage Center must have network connectivity to the directory service.
You must be familiar with the Active Directory/OpenLDAP configuration of the directory service.
Storage Center requires credentials from a directory service user that is allowed to query the directory service and who has
sufficient privileges to perform a bind operation.
(Active Directory only) Joining the controller to the domain requires credentials from a directory service user who is an
administrator and who has sufficient privileges to create a computer record in the directory.
(Active Directory only) To join the controller to the domain, forward and reverse DNS records for the Storage Center must
be created in the domain. For a single-controller Storage Center system, create DNS records for the controller IP address.
For a dual-controller Storage Center system, create DNS records for the management IP address.
(OpenLDAP only) To use password authentication with OpenLDAP, an SSL certificate is required to communicate with the
directory service using SSL/TLS.
Discover Directory Service Settings Automatically
Use the Configure Directory Service Automatic Discovery wizard to allow the Storage Center to discover available directory
services automatically.
Steps
1. If you are connected to a Data Collector, select a Storage Center from the drop-down list in the left navigation pane of
Unisphere Central.
2. Click
Summary.
The Summary view is displayed.
3. Click (Settings).
The Storage Center Settings dialog box opens.
4. Click the Directory Services tab.
5. Click Configure Directory Services Automatic Discovery.
The Storage Center automatically discovers directory server settings and displays the settings in the Directory Services
Auto Configuration Wizard.
6. Type a new value into the field of any setting you want to change.
In the URI field, type the uniform resource identifier (URI) for one or more servers to which Storage Center connects.
NOTE: Use the fully qualified domain name (FQDN) of the servers.
Example URIs for two servers:
ldap://server1.example.com ldap://server2.example.com:1234
NOTE:
Adding multiple servers ensures continued authorization of users in the event of a resource outage. If
Storage Center cannot establish contact with the first server, Storage Center attempts to connect to the remaining
servers in the order listed.
In the Directory Server Connection Timeout field, type the maximum time (in minutes) that Storage Center waits
while attempting to connect to an Active Directory server. This value must be greater than zero.
In the Base DN field, type the base distinguished name for the LDAP server. The Base DN is the starting point when
searching for users.
In the Storage Center Hostname field, type the fully qualified domain name (FQDN) of the Storage Center.
For a single-controller Storage Center system, this is the fully qualified host name for the controller IP address.
For a dual-controller Storage Center system, this is the fully qualified host name for the management IP address.
In the LDAP Domain field, type the LDAP domain to search.
150
Storage Center Maintenance