ViPR Controller -Configuring AD Authentication
The default built-in administrative accounts may not be granular enough to meet your business needs, if this is the case then adding an authentication provider such as Active Directory which […]
Virtualization & Storage
The default built-in administrative accounts may not be granular enough to meet your business needs, if this is the case then adding an authentication provider such as Active Directory which […]
The default built-in administrative accounts may not be granular enough to meet your business needs, if this is the case then adding an authentication provider such as Active Directory which we highlight as part of this configuration allows you to assign users or groups to specific roles.
The example configuration provided here was part of an Enterprise Hybrid Cloud solution.
Name: Enter a suitable name for the authentication provider. (You can have multiple providers for different domains.)
Type: Select Active Directory or LDAP
Description: description of the authentication provider.
Domain: Enter the domain being used e.g. domain.local
Server URLs: Enter the ldap or ldaps (secure LDAP) IP address of the domain controller. The default port for ldap is 389 and is 636 for ldaps. Enter the port number if not using the default port e.g. ldap://<domain controller IP>:<port>
Manager DN: Enter the user account that ViPR uses to connect to Active Directory or LDAP server e.g. CN=adbind_vipr,OU=EHC,DC=domain,DC=local
Password: Enter the password for the adbind user
4. The Group Attribute can remain at default CN. Indicates the Active Directory attribute that is used to identify a group. Used for searching the directory by groups.
5. The Group Whitelist should contain the Active Directory User Groups that will contain members requiring ViPR privileges.
6. In the Search section, ensure the search filter is userPrincipalName=%u, set the Scope to Subtree and enter the Search Base (e.g. OU=EHC,DC=domain,DC=local), then click Save.
7. To verify the configuration, add a user from the authentication provider at Security > VDC Role Assignments, then try to log in as the new user. (ViPR usernames should be in the format user@domain)
Ramblings by Keith Lee
Discussions about all things VxRail.
Random Technology thoughts from an Irish Virtualization Geek (who enjoys saving the world in his spare time).
Musings of a VMware Cloud Geek
Converged and Hyper Converged Infrastructure
'Scamallach' - Gaelic for 'Cloudy' ...
Storing data and be awesome
Best Practices et alia
Every Cloud Has a Tin Lining.