Access Control:
User Category Permission
Storage administrator Allowed
Storage integration administrator Disallowed
Application administrator Disallowed
Security administrator Disallowed
Read-only users Disallowed
Technicians Disallowed
Configuring LDAP in the System
Configures general system parameters governing user authentication against LDAP
servers
ldap_config_set
[ user_name_attrib=LdapAttrib ]
[ xiv_group_attrib=LdapAttrib ]
[ storage_admin_role=LdapRole ]
[ read_only_role=LdapRole ]
[ security_admin_role=LdapRole ]
[ use_ssl=<yes|no> ]
[ user_id_attrib=LdapAttrib ]
[ session_cache_period=Minutes ]
[ bind_time_limit=Seconds ]
[ first_expiration_event=Days ]
[ second_expiration_event=Days ]
[ third_expiration_event=Days ]
[ version=LdapVersion ]
[ xiv_user=LdapAttrib ]
[ xiv_password=LdapAttrib ]
[ server_type=<SUN DIRECTORY|MICROSOFT ACTIVE DIRECTORY|OPEN LDAP> ]
[ group_search_depth=Depth ]
[ group_search_max_queries=Number ]
[ group_search_stop_when_found=<yes|no> ]
Parameters:
Name Type Description Mandatory Default
user_name_
attrib
String User name
attribute for
queries. If not
specified, it is set
to uid for Sun
Directory servers
and
userPrincipalName
for Microsoft
Active Directory
servers.
N according to server
type
xiv_group_
attrib
String LDAP attribute
designated to hold
XIV-mapped roles
N none
366 IBM XIV Storage System User Manual