Start a Conversation

Unsolved

This post is more than 5 years old

839

November 15th, 2016 16:00

LDAP/Kerberos/ManagedServiceAccount Authentication for ReplayManager/StorageCenter Command Set

I am developing a database architecture that uses replay manager and storage center replays. In the Replay Manager Admin guide and Storage Center Command Set documentation, I see that Get-SCConnection and Add-RMSystemSettings require a username and password. 

With regard to the Replay Manager, I assume it would be a good practice to periodically change the password of the account that can connect to the Storage Center. This would get quite cumbersome as the number of servers using replay manager increases. Yes, I know I can use powershell to update the passwords, but I feel this is not ideal. It would be nice if the account running the replay manager service could directly authenticate to the compellent controller -- or even better if it could delegate the replay manager users' kerberos credentials for a better audit trail. Is this a possibility, or being considered in a future release?

With regard to Storage Center, it seems any powershell commands would need to read stored credentials from a file in order to run without operator interaction. Again, this would get quite cumbersome as the number of servers increases. Yes, I know I can use powershell to distribute the updated credential files, but again I feel this is not ideal. It would be nice if the account executing the powershell commands could directly authenticate to the compellent controller. Is this a possibility, or being considered in a future release?

No Responses!
No Events found!

Top