Start a Conversation

Unsolved

Z

1 Rookie

 • 

41 Posts

23

August 2nd, 2024 11:31

Two ActiveDirectory providers on same data possible?

Hi.  We are moving from one ActiveDirectory instance to a completely different ActiveDirectory instance.  We would like to have both authenticate the same data shares during the long transition.  Is this possible?  It seems you can only have one ActiveDirectory provider per access zone.  Also it appears each access zone has to have a different data path in /ifs/ that doesn't conflict with other access zones.  Is there any way to accomplish this?  Thanks!

Moderator

 • 

8.7K Posts

August 2nd, 2024 19:32

Hi,

Thanks for your question.

Which version of OneFS are you using? I don’t think it is possible but there might be something with multiprotocol that will work. https://dell.to/3Aaf1dk

 

Let us know if you have any additional questions.

1 Rookie

 • 

41 Posts

August 5th, 2024 11:09

@DELL-Josh Cr​ Hi Josh.  Thanks for the document.  Currently running OneFS 9.4.

Moderator

 • 

8.7K Posts

August 5th, 2024 12:45

Page 88 https://dell.to/3SCmwzY See if you can add the 2nd one.

1 Rookie

 • 

41 Posts

August 5th, 2024 13:01

@DELL-Josh Cr​ I have already added the other AD provider, that is not an issue.  I would have no issue sharing two different data paths with different access zones/ActiveDirectory providers. 

My issue is sharing the same data path with two ActiveDirectory providers simultaneously.  I have a trust between the two AD environments and permissions are not an issue.  I just can't seem to use both AD providers to authenticate to the smb share.

Moderator

 • 

8.7K Posts

August 5th, 2024 13:35

I don't see a way to do it, needs to be separate zones and paths like you found. 

3 Apprentice

 • 

592 Posts

August 20th, 2024 16:24

@ZBoT .

check out 

000079211 : https://www.dell.com/support/kbdoc/en-us/000079211/onefs-how-to-include-trusted-active-directory-domains-in-user-identity-mapping

isi auth ads modify --lookup-domains=<trusteddomain> <primarydomain>

EXAMPLE
isi710x-1# isi auth ads modify --lookup-domains=MNTEST.PRIV MNELITE.PRIV

No Events found!

Top