Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

PowerScale OneFS 9.3.0.0 CLI Administration Guide

Configure the LDAP provider to use TLS connections

This procedure describes how to configure LDAP to use TLS connections. This requires some manual setup by a cluster administrator.

  1. Obtain the X.509 Certificate Authority (CA) file for the LDAP server and upload it to the cluster.
  2. Move the CA file to a directory under /ifs to distribute the file, such as /ifs/ldap-ca.pem.
  3. Run the following command to copy the CA file locally to every node in the cluster, assuming the file is in the /ifs/ldap-ca.pem directory:
    isi_for_array cp /ifs/ldap-ca.pem /etc/ssl/ldap-ca.pem
  4. Optional: Run the following command to remove the ldap-ca.pem file that was created under /ifs since it is no longer needed:
    rm /ifs/ldap-ca.pem
  5. Configure the LDAP provider to use the X.509 CA, where <LDAP URL> is the LDAP server:
    isi auth ldap {create | modify} --certificate-authority-file=/etc/ssl/ldap-ca.pem
    isi auth ldap create --name=tlsldap \
        --server-uris=ldaps://<LDAP URL>
        --base-dn=dc=example,dc=com \
        --bind-dn=cn=admin,dc=example,dc=com \
        --set-bind-password \
        --certificate-authority-file=/etc/ssl/ldap-ca.pem
    
  6. Test the new configuration by listing some LDAP users:
    isi auth users list --provider=ldap:tlsldap --limit=10

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\