Start a Conversation

Unsolved

This post is more than 5 years old

2779

October 23rd, 2014 06:00

We want your feedback on our draft LDAP configuration GUI


In ViPR SRM, you have had to edit an XML file in the past in order to configure LDAP. We are thinking of adding a GUI to make it easier to configure. (Please understand that this posting is NOT A PROMISE that the feature will make it into the next release.)

I have a few quick mock-ups below to show the GUI we are thinking of creating. The idea is that in the GUI you should be able to

· c  specify at least one realm with the following attributes:

  • Server URL  (And alternate)
  • Manager logon on password
  • Search scope, base and filter.

§  User search

§  Role based search

  • Specify more realms
  • Set the order of which realm to use for authentication
  • Have a way to specify n-number of additional parameters.

·   

You get to the LDAP configuration from the Centralized Administration page, a Configuration drop-down menu (In the current version there is just a Configuration button that takes you to a dialog to configure servers.)

ConfigDropdown.png

Choosing "Directory Services" launches the following dialog:

DirectoryServicces1.png

If you click "Add New Name/Value Pair", the dialog changes as follows:

DirectoryServicces2.png

This is what the labels map to in the XML File:

Label

Maps to in XML file

Hover help

Comments/info

Name:

Realm

Server URL:

connectionURL

The host URL (connectionURL)

Manager DN:

connectionName

The username (connectionName) the realm uses to authenticate with the directory service.

Manager password:

connectionPassword

The password  (connectionPassword) for the user specified as the Manager DN. Password is encrypted automatically.

Search scope:

userSubtree

Choose “True” to search for users in subtrees below the Search base (userBase)

(True = subtree, False = one level)

Defaults should be True

Search base:

userbase

Specify where you want to start the user search (userBase) from. If this is blank the search starts from the top level element in the directory. For example OU=location,DC=domain,DC=com.

Search filter:

userSearch

Filter expression used to search for users in the directory, for example, usersearch=U(uid={0}) “

Role base:

roleBase

Defines the base entry for role searches

Role scope:

roleSubtree

Dropdown with

true = subtree,

false = one level

Not applicable

“Not applicable” is the default

Role name:

roleName

The attribute that contains the role name. For example, CN

Role search:

RoleSearch

Used to filter on selected role entries. For example, {0} for DN, {1} for the user’s login name

User role name:

UserRoleName

In the directory, the attribute with the name of the role. For example, memberOf

Adding a Realm

Adding a Realm works similar to the way you add a Server. Click the “Add Realm” dialog and  a new “twisty section” appears with all the Directory services fields. The already- configured directory services is “pushed down” in a new twisty section.  Each twisty section can be collapsed. This make it easy for  you to see how many Realms you have configured and to re-order them.

We've tried to use the same or similar lables to the ViPR Controller LDAP GUI.

We appreciate any feedback on where/how you get to this dialog, the fields, labels, or layout.

9 Posts

October 23rd, 2014 11:00

DPA is the about the only EMC tool that correctly integrates to our AD environment.

Things that work:

We can specify the parent domain and it "finds" users in any of multiple child domains without having to define the child domains.

Users can be automatically added and roles assigned via group/role mapping without having to add the users to the tool.

FYI - the VIPR windows authentication did not work correctly in our environment - it could only work with one domain.(2.0 EAP version)

1 Rookie

 • 

19 Posts

October 24th, 2014 07:00

Good idea, I'll check into that.

1 Rookie

 • 

19 Posts

October 28th, 2014 10:00

Hi Andreas,

Yes i was thiking the same thing- make it as similar to the ViPR config as possible.

To that end - is the Description necessary? (we were thinkign of not having a description in the SRM config)

Also, is the terminology  "Configure Authentication Provider"  good? I noticed htat other LDAP configs like in DPA,
call it "Directory Services"

(or shoudl we just follow ViPR for consistency, in your opinion?)
Thanks,

Mary Beth

48 Posts

October 28th, 2014 19:00

This screen and description look great, I would expect to see this under Admin->Portal->Authentication rather than Centralized Management

I could have more than one frontend and I may also use different realm config for each FE.

It would be nice if changes in here also did not break storage compliance (EMC000192523)

1 Rookie

 • 

19 Posts

October 29th, 2014 07:00

hi again, Andreas,

Thanks for answering. You are the second person to suggest changing to "bind user"... I was originally trying to say with the same labels as ViPR but maybe now I'll go with "Bind user" in SRM and try to get ViPR to change theirs in some future release... again.. I cannot PROMISE that this will happen but I'm working on it!

No Events found!

Top