Note: For LPARs running on a server blade in LP mode, to set the LPARs
whose LPAR numbers are 31 or higher as objects of the system failover
processing by the HA monitor, apply the management module firmware
version A0235 or later.
LDAP Server Linkage
This section describes authentication with LDAP servers.
Overview
The system unit searches the LDAP directory on the LDAP server by using the
Lightweight Directory Access Protocol (hereinafter called LDAP) to
authenticate users. With this function, you can perform the following:
•
Login to management modules and the server blades as a user registered
with the LDAP directory.
• Group authentication that allows only the account belonging to a specific
group in the LDAP directory to log in.
The following module supports LDAP.
• Server blade (SMASH-CLP and WS-Management of BMC)
• Management module
Management modules and server blades determine whether to allow a user to
log in based on the user account information registered in each module and
the user account information in the LDAP directory at user authentication.
Adding user account information to the LDAP directory on the LDAP server
allows all modules using the LDAP server to use the added user account
information. Besides, it is not necessary to register user account information
with each module.
Also, the group information in the LDAP directory is looked up and only the
user accounts belonging to the group are allowed to log in during user
authentication. By using the group authentication function, you can construct
an LDAP server linkage environment between management modules and
server blades without drastically changing the already constructed LDAP
directory.
If the modules are not linked with an LDAP server, users can only use their
account registered in each module to log into the module. If the modules are
linked with an LDAP server, you can select either of the following two
authentication methods:
• First, users are authenticated by using their accounts registered in each
module. If the authentication fails, users are authenticated by using their
accounts in the LDAP directory.
• Users are authenticated by using their accounts in the LDAP directory
only.
2-90
Functional detail
Hitachi Compute Blade 500 Series Management Module Setup Guide