HP CloudSystem Foundation Betriebsanweisung Seite 4

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 7
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 3
Directory Services on CloudSystem
Figure 7 - Setting the “South America” as the default directory
Step 5. Create a directory group. Go to CloudSystem Console > User and Groups > Add Directory User or
Group. Connect to a pre-defined directory using a user account. Then select a group from the list and
assign a role to it. For instance:
Figure 8 - Assigning the "admins group" to the Full Infrastructure administrator role
OpenLDAP constraints. Below are listed the main constraints in CloudSystem Foundation for OpenLDAP:
Directory tree: groups must be located under the OU=groups from the Base DN
Directory schema
Users: supports the “inetOrgPersonobjectClass only
Groups: supports the groupOfNames” objectClass only
Summary about User Authorization
In a nutshell, the Foundation user permissions are:
User accounts from a directory group can log into the CloudSystem Console. Currently only Full
Infrastructure administrator and Read only roles are supported.
User accounts from the default directory that are assigned to an OpenStack project can log into the
CloudSystem Portal. By default, Full Infrastructure administrators are assigned to the
“administrator” project.
General Constrains
CloudSystem Portal. It is automatically configured based on the default directory and the first server
from the server list. In other words, the CloudSystem Portal does not support multiple directories nor
load balancing servers.
FQDN. Although CloudSystem Console accepts an IP address for the directory server, HP strongly
recommends the usage of FQDN.
Strong certificate validation. By default CloudSystem Foundation does not validate the directory server certificate
in a strict manner. To enable the strong SSL/TLS validation for the CloudSystem Portal, you must export the CA
certificate from the directory server and import it to the Foundation appliance through the appliance console. For
more information, see the Enabling strong certificate validation in the CloudSystem Portalappendix in the HP
CloudSystem Administrator Guide at
www.hp.com/go/cloudsystem/docs.
5900-3794, September 2014
4
Seitenansicht 3
1 2 3 4 5 6 7

Kommentare zu diesen Handbüchern

Keine Kommentare