This section describes how to configure an LDAP domain so that LDAP users can access shared account resources.
LDAP data is organized in a tree structure, which clearly shows the organizational information. A node on the tree is called an Entry. Each Entry has a distinguished name (DN). The DN of an Entry is composed of the base distinguished name (Base DN) and relative distinguished name (RDN). The Base DN refers to the position of the parent node where the Entry resides on the tree, and the RDN refers to an attribute that distinguishes the Entry from others.
A DN consists of the following parts:
The Configure LDAP Domain page is displayed on the right.
Click Restore to Initial to restore the configured basic and advanced parameters to their initial values.
Parameter |
Description |
|---|---|
Active Server Address |
IP address or domain name of the active LDAP domain server.
NOTE:
|
Standby Server Address 1 |
IP address or domain name of standby LDAP server 1.
NOTE:
|
Standby Server Address 2 |
IP address or domain name of standby LDAP server 2.
NOTE:
|
Protocol |
Protocol used by the storage system to communicate with the LDAP domain server.
|
Port |
Port used by the storage system to communicate with the LDAP domain server.
|
Base DN |
Root directory of the domain server. That is, the start DN of the domain server specified for searching. After the Base DN is configured, all users in the Base DN can be added to the account. Each entry stored in the LDAP domain directory database has a unique identification, which can uniquely identify an object and its location in the directory tree. The identification of each entry in the database is called distinguished name (DN). The top of the directory tree is the root directory, that is, the Base DN. A DN consists of three attributes: cn, ou, and dc. For example, cn=Common name,ou=Organization unit,dc=example,dc=com is used to identify a user in an LDAP domain and ,dc=example,dc=com is the Base DN. [Example] dc=example,dc=com |
Bind Level |
Authentication type of the bind DN.
|
Bind DN |
Binding is a process that a client initiates a connection request to establish a session to the LDAP server. If the LDAP server does not allow anonymous access, you need to specify the bind DN. A bind DN is used to query the directory server and must have the administrator permissions. [Example] cn=Manager,ou=people,dc=example,dc=com |
Bind Password |
Password of the bind DN.
NOTE:
A simple password may result in security issues. A complex password that contains uppercase letters, lowercase letters, digits, and special characters is recommended. |
Confirm Bind Password |
Enter the same bind DN password again. |
Parameter |
Description |
|---|---|
Bind Using AD Credential |
Determine whether to enable Bind Using the AD Credential. If this parameter is enabled when the system has been added to the AD domain, the AD domain account can be used as the LDAP bind DN. |
User Directory |
User DN configured on the LDAP domain server. |
User Search Scope |
Search scope for user queries.
|
User Group Directory |
User group DN configured on the LDAP domain server. |
User Group Search Scope |
Search scope for user group queries.
|
Network Group DN |
Network group DN. |
Network Group Search Scope |
Search scope for network group queries.
|
Search Timeout Duration (Seconds) |
Timeout duration that the client waits for the LDAP domain server to return the query result. The default value is 3. |
Connection Timeout Duration (Seconds) |
Timeout duration that the client establishes a connection with the LDAP domain server. The default value is 3. |
Idle Timeout Duration (Seconds) |
Timeout duration that the client has no communication with the LDAP domain server. The default value is 30. |
LDAP Schema Template |
Select an LDAP schema template.
NOTE:
|
RFC2307 User Object |
Name of the RFC2307 posixAccount object class defined by the schema. [Value range] The value contains 0 to 1024 characters. [Default value]
|
RFC2307 User Group Object |
Name of the RFC2307 posixGroup object class defined by the schema. [Value range] The value contains 0 to 1024 characters. [Default value]
|
RFC2307 Network Group Object |
Name of the RFC2307 nisNetgroup object class defined by the schema. [Value range] The value contains 0 to 1024 characters. [Default value] nisNetgroup |
RFC2307 uid Attribute |
Name of the RFC2307 uid attribute defined by the schema. [Value range] The value contains 0 to 1024 characters. [Default value] uid |
RFC2307 uidNumber Attribute |
Name of the RFC2307 uidNumber attribute defined by the schema. [Value range] The value contains 0 to 1024 characters. [Default value] uidNumber |
RFC2307 gidNumber Attribute |
Name of the RFC2307 gidNumber attribute defined by the schema. [Value range] The value contains 0 to 1024 characters. [Default value] gidNumber |
RFC2307cn (for Groups) Attribute |
Name of the RFC2307cn attribute for groups defined by the schema. [Value range] The value contains 0 to 1024 characters. [Default value] cn |
RFC2307cn (for Network Groups) Attribute |
Name of the RFC2307cn attribute for network groups defined by the schema. [Value range] The value contains 0 to 1024 characters. [Default value]
|
RFC2307 memberUid Attribute |
Name of the RFC2307 memberUid attribute defined by the schema. [Value range] The value contains 0 to 1024 characters. [Default value] memberUid |
RFC2307 memberNisNetgroup Attribute |
Name of the RFC2307 memberNisNetgroup attribute defined by the schema. [Value range] The value contains 0 to 1024 characters. [Default value] memberNisNetgroup |
RFC2307 nisNetgroupTriple Attribute |
Name of the RFC2307 nisNetgroupTriple attribute defined by the schema. [Value range] The value contains 0 to 1024 characters. [Default value] nisNetgroupTriple |
RFC2307bis Supported |
Whether to enable the RFC2307bis attribute for the schema. |
RFC2307bis groupOfUniqueNames Object |
Name of the RFC2307bis groupOfUniqueNames object class defined by the schema. This parameter is valid only when RFC2307bis Supported is enabled. [Value range] The value contains 0 to 1024 characters. [Default value] groupOfUniqueName |
RFC2307bis uniqueMember Object |
Name of the RFC2307bis uniqueMember attribute defined by the schema. This parameter is valid only when RFC2307bis Supported is enabled. [Value range] The value contains 0 to 1024 characters. [Default value] uniqueMember |