Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

PowerScale OneFS 9.2.1.0 CLI Administration Guide

PDF

Create a user-mapping rule

You can create user-mapping rules to manage user identities on the cluster.

You can create the first mapping rule with the --user-mapping-rules option for the isi zone zones modify System command. If you try to add a second rule with the command above, however, it replaces the existing rule rather than adding the new rule to the list of rules. To add more rules to the list of rules, you must use the --add-user-mapping-rules option with the isi zone zones modify System command.
NOTE If you do not specify an access zone, user-mapping rules are created in the System zone.
  1. To create a rule to merge the Active Directory user with a user from LDAP, run the following command, where <user-a> and <user-b> are placeholders for the identities to be merged; for example, user_9440 and lduser_010, respectively:
    isi zone zones modify System --add-user-mapping-rules \
      "<DOMAIN> <user-a> &= <user-b>"
    Run the following command to view the rule:
    isi zone zones view System
    If the command runs successfully, the system displays the mapping rule, which is visible in the User Mapping Rules line of the output:
                    Name: System
              Cache Size: 4.77M
           Map Untrusted:
              SMB Shares: -
          Auth Providers: -
          Local Provider: Yes
            NetBIOS Name:
          All SMB Shares: Yes
      All Auth Providers: Yes
      User Mapping Rules: <DOMAIN>\<user_a> &= <user_b>
    Home Directory Umask: 0077
      Skeleton Directory: /usr/share/skel
                 Zone ID: 1
  2. To verify the changes to the token, run a command similar to the following example:
    isi auth mapping token <DOMAIN>\\<user-a>
    If the command runs successfully, the system displays output similar to the following example:
             User
                 Name : <DOMAIN>\<user-a>
                  UID : 1000201
                  SID : S-1-5-21-1195855716-1269722693-1240286574-11547
              ZID: 1
             Zone: System
       Privileges: -
    Primary Group
                 Name : <DOMAIN>\domain users
                  GID : 1000000
                  SID : S-1-5-21-1195855716-1269722693-1240286574-513
    Supplemental Identities
                 Name : Users
                  GID : 1545
                  SID : S-1-5-32-545
    
                 Name : lduser_010
                  UID : 10010
                  SID : S-1-22-1-10010
    
                 Name : example
                  GID : 10000
                  SID : S-1-22-2-10000
    
                 Name : ldgroup_20user
                  GID : 10026
                  SID : S-1-22-2-10026

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\