Veritas NetBackup™ Appliance Administrator's Guide
- Overview
- About NetBackup appliances
- About the Primary Server role
- About the media server role
- About accessing the NetBackup Appliance Web Console
- About the NetBackup Appliance Shell Menu
- About appliance console components
- About the NetBackup Appliance Web Console login page
- NetBackup appliance home page
- Common tasks in NetBackup appliance
- About the NetBackup appliance documentation
- Monitoring the NetBackup appliance
- About monitoring the NetBackup appliance
- About hardware monitoring and alerts
- About Symantec Data Center Security on the NetBackup appliance
- Managing a NetBackup appliance from the NetBackup Appliance Web Console
- About the Manage views
- About storage configuration
- Manage > Storage
- Manage > Storage > Shares
- About Universal shares migration
- Checking partition details
- Resizing a partition
- Resize dialog
- Troubleshooting resize-related issues
- Moving a partition
- Move dialog
- Moving the MSDP partition from a base disk to an expansion disk for optimum performance
- Scanning storage devices from the NetBackup Appliance Web Console
- Adding the storage space from a newly available disk
- Removing an existing storage disk
- Monitoring the progress of storage manipulation tasks
- Scanning storage devices using the NetBackup Appliance Shell Menu
- About Copilot functionality and Share management
- About viewing storage space information using the Show command
- About storage email alerts
- About appliance supported tape devices
- About configuring Host parameters for your appliance
- Manage > Appliance Restore
- Manage > Appliance License
- About the Migration Utility
- Software release updates for NetBackup Appliances
- About installing EEBs
- About installing NetBackup Administration Console and client software
- Manage > Additional Servers
- Manage > File Manager
- Manage > High Availability
- Managing NetBackup appliance using the NetBackup Appliance Shell Menu
- Expanding the bandwidth on the NetBackup appliance
- About configuring the maximum transmission unit size
- About OpenStorage plugin installation
- About mounting a remote NFS
- About running NetBackup commands from the appliance
- About NetBackup administrator capabilities
- Running NetBackup commands from the NetBackup appliance
- Creating a NetBackup touch file from the NetBackup appliance
- About NetBackup operating system commands
- Best practices for running NetBackup commands from the NetBackup appliance
- Known limitations of running NetBackup commands from the NetBackup appliance
- Creating NetBackup administrator user accounts
- Deleting NetBackup administrator user accounts
- Viewing NetBackup administrator user accounts
- About NetBackup administrator capabilities
- About Auto Image Replication between appliances
- About forwarding logs to an external server
- About high availability configuration
- Understanding the NetBackup appliance settings
- About modifying the appliance settings
- Settings > Notifications
- Settings > Network
- Settings > Date and Time
- Settings > Authentication
- About configuring user authentication
- About authorizing NetBackup appliance users
- Settings > Authentication
- Settings > Authentication > LDAP
- Adding an LDAP server configuration
- Importing an LDAP server configuration
- Setting the SSL certification
- Exporting an LDAP configuration
- Unconfiguring LDAP user authentication
- Enabling the LDAP server configuration
- Disabling the LDAP server configuration
- Deleting LDAP configuration parameters
- Adding LDAP configuration parameters
- Adding an LDAP attribute mapping
- Deleting an LDAP attribute mapping
- Settings > Authentication > Active Directory
- Settings > Authentication > User Management
- Settings > Password Management
- Troubleshooting
- Deduplication pool catalog backup and recovery
- Index
Adding an LDAP server configuration
You can use the tab to add the details of an LDAP server and configure it with your appliance. The LDAP server enables you to access and maintain distributed directory information services for your appliance. The following procedure describes the steps to configure LDAP user authentication.
To configure an LDAP server
- Log on to the NetBackup Appliance Web Console.
- Click Settings > Authentication >LDAP to expand the LDAP Server Configuration.
- Select Add new configuration.
The appliance displays the fields to create a new configuration.
- Enter the configuration information based on the following fields:
Field
Description
Example
Server Name/IP
Enter the FQDN or IP address of your LDAP server.
Note:
The specified LDAP server should comply with RFC2307bis. The RFC2307bis specifies that hosts with IPv6 addresses must be written in their preferred form, such that all components of the address are indicated and leading zeros are omitted.
Base DN
Enter the base directory name which is the top level of the LDAP directory tree.
OU= ExampleUsers, dc= mydomain
Bind DN
Enter the bind directory name. The Bind DN is used as an authentication to externally search the LDAP directory within the defined search base.
DC=com
Password
Enter the password to access the LDAP server.
Common User Name
Enter the name of an existing LDAP user on your LDAP server.
NBUApplianceAdmin
Common Group Name
Enter the name of an existing LDAP user group on your LDAP server.
SSL Certificate Required
Displays a drop-down list to enable SSL certificate for your LDAP server. The drop-down list displays the following options:
Yes - Select to enable adding an SSL certificate
No - Select to continue configuring the LDAP server without the SSL certificate
Start TLS
Note:
When you use the Start TLS and Yes options during LDAP configuration, the initial setup is done over a non-SSL channel. After the LDAP connection and initial discover phase is over, the SSL channel is turned on. Even at this phase, the established SSL channel doesn't do the server-side certificate validation. This validation starts after the server's root certificate is explicitly set using the Set Certificate option. For more information, refer to See Setting the SSL certification.
Directory Type
Select the LDAP directory type from the drop-down list. The available options are:
OpenLDAP
ActiveDirectory
Others
Select OpenLDAP if you use a typical OpenLDAP directory service.
Select ActiveDirectory if you use AD as an LDAP directory service.
Select Others if you use a different type of LDAP directory service.
Validate UIDs and GIDs for Conflicts
Select the check-box to validate the User IDs and Group IDs and identify conflicting entires between the NetBackup appliance and the LDAP server.
Note:
The Common User Name and Common Group Name fields are not required to complete LDAP configuration. However, if you do not complete those fields, no LDAP users or LDAP groups appear under Settings > Authentication > User Management until you manually add them.
- Click Configure to configure LDAP authentication using the entered parameters.
The appliance configures and enables the new LDAP server and displays the Attribute Mappings and Configuration Parameters table.
Note:
When the directory type is ActiveDirectory and the Settings > Security > Authentication > LDAP > Users Add command is used to add an LDAP user, you must use the following command to add the groups that the user belongs to on the LDAP server to the appliance: Settings > Security > Authentication > LDAP > Groups Add