Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell Unity™ Family Unisphere® Command Line Interface User Guide

Change LDAP settings

Update a configured LDAP setting.

NOTE:If you intend to use LDAP with SSL, you must upload the CA certificate of the LDAP server to the system by using the -upload command before configuring the LDAP settings. For example:
uemcli -d 10.0.0.1 -u admin -p MyPwd -upload -f /tmp/myldapservercertificate.cer
/sys/cert -type CA -service Mgmt_LDAP

Format

/net/ldap –id <value> set [{-name <value> | -autoDiscoveryEnabled}] [-port <value>] [-protocol {ldap | ldaps {-certFilePath <value>}}] [-bindDn <value>] [-bindPasswd <value> | -bindPasswdSecure] [-userSearchPath <value>] [-groupSearchPath <value>] [-userIdAttr <value>] [-groupNameAttr <value>] [-userObjectClass <value>] [-groupObjectClass <value>] [-groupMemberAttr <value>] [-timeout <value>]

Object qualifier

QualifierDescription
-idType the ID of the LDAP setting to change.

Action qualifier

QualifierDescription
-nameType the IP addresses or hostnames of the primary directory servers to use for authentication. The values you type depends on the format of the subject field entry in each directory server's certificate. Typically, this requires a hostname. Type the LDAP IP addresses or hostnames as a comma-separated string. If IP addresses are specified, the DNS Server for the LDAP domain must be configured with a reverse lookup so that it provides the FQDN for the specified IP addresses.
-autoDiscoveryEnabledSpecify to direct the system to obtain the LDAP server addresses or hostnames using DNS. DNS must be configured for this option to take effect.
NOTE:-autoDiscoveryEnabled is the default if you do not specify either -name or -autoDiscoveryEnabled.
-domainType the domain name for the LDAP server.
-portType the port number used by the directory server for LDAP communications. By default, LDAP uses port 389, and LDAP over an SSL uses port 636. For forest-level authentication, specify port 3268 for LDAP or port 3269 for LDAPS.
-protocolType whether the LDAP protocol uses SSL for secure network communication. SSL provides encryption and authentication capabilities. SSL encrypts data over the network and provides message and server authentication. Value is one of the following:
  • ldap (default) — LDAP without SSL.
  • ldaps — LDAP with SSL.
-certFilePathPath to (filename of) the trusted certificate file used for one way server authentication.
NOTE:If the value of -protocol is ldaps, this qualifier is required.
-bindDnType the distinguished name (DN) for a user with administrator privileges on the LDAP Server. The DN can be expressed in several formats. For example:

cn=Administrator,cn=Users,dc=mycompany,dc=com

Administrator@mycompany.com

mycompany.com/Administrator

-bindPasswdType the password to be used for binding to the LDAP server. This is the password for the user specified in the Bind DN attribute. It is required when the -bindDn qualifier is included.
-bindPasswdSecureSpecifies the password in secure mode - the user will be prompted to input the password.
-userSearchPathType the path to search for users on the directory server. For example: ou=People,dc=lss,dc=emc,dc=com.
NOTE:On an Active Directory server, a default search path is used.
-groupSearchPathType the path to search for groups on the directory server. For example: uid=<name>,ou=people,dc=<domaincomponent>,or dc=<domain component>.
NOTE:On an Active Directory server, a default search path is used.
-userIdAttrType the name of the LDAP attribute whose value indicates the user ID. Default value is uid.
-groupNameAttr Type the name of the LDAP attribute whose value indicates the group name. Default value is cn.
-userObjectClass Type the LDAP object class for users. Default value is user. In Active Directory, groups and users are stored in the same hierarchical directory path and the class is called group.
-groupObjectClassType the LDAP object class for groups. Default value is group. In Active Directory, groups and users are stored in the same directory path and the class is called group.
-groupMemberAttrName of the LDAP attribute whose value contains names of group members within a group. Default value is member.
-timeoutType the timeout for the LDAP server in milliseconds. If the system does not receive a reply from the LDAP server after the specified timeout, it stops sending requests. Default is 10000 milliseconds, or 10 seconds.

Example

The following command updates the configured LDAP settings:

uemcli -d 10.0.0.1 -u Local/joe -p MyPassword456! /net/ldap -id lDAP_1 set –server lpso242.lss.emc.com –port 389
Storage system address: 10.0.0.1
Storage system port: 443
HTTPS connection

ID = LDAP_1
Operation completed successfully.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\