Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

PowerScale OneFS 9.6.x.x CLI Administration Guide

PDF

Configure SSO in OneFS

You can configure OneFS to provide SSO service to users of the WebUI.

Prerequisites

Steps

  1. Define the ADFS instance in OneFS.
    1. Open an SSH on OneFS and login with ISI_PRIV_AUTH privilege.
    2. Create the IdP.
      isi auth ads create <name> <user> --password=<password> ...
      Where:
      • <name> is a fully qualified Active Directory domain name that identifies the ADFS server. For example, dtcscsaml.example.com.
      • <user> is the user account with permission to join machines to the given domain.
      • <password> is the password for <user>.
      Use the --help option on the command line to see additional parameters.
  2. Add the Active Directory IdP to OneFS zones.
    Each zone must have an associated Active Directory. The zones can all use the same Active Directory. The following example assigns the Active Directory to the system zone.
    isi zone zones modify <zone> --add-auth-providers <provider>    
    For example:
    isi zone zones modify system --add-auth-providers=lsa-activedirectory-provider:dtcscsaml.example.com  
  3. Verify that OneFS can find users in Active Directory.
    isi auth users view dtcscsaml.example.com\\<user-name> 
    In the output, ensure that an email address is displayed. If not, return to Active Directory and assign email addresses to users.
  4. Configure the OneFS hostname for SAML SSO.
    isi auth sso sp modify --hostname=<name>
    Where <name> is the name that SAML SSO can use to represent the OneFS cluster to ADFS. SAML redirects clients to this hostname.
  5. Get ADFS metadata and store it in OneFS.
    The ADFS metadata is in a well-known URL on the ADFS server.
    The following example issues an HTTPS GET request to obtain the metadata from the server and store it in the OneFS file system.
    curl -o /ifs/adfs.xml https://dtcscsaml.example.com/FederationMetadata/2007-06/FederationMetadata.xml
  6. Create the IdP on OneFS.
    isi auth sso idps create <idp-name> --metadata-location="/ifs/adfs.xml"
    Where:
    • <idp-name> is any name to identify ADFS on the cluster.
    • The value for --metadata-location is where you stored the xml file in the previous step.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\