Please review as page 408 goes on the describe in depth, the process of assigning Console usersand Console Roles.
On a side note, please ensure to backup your NMC database prior to making the changes as I have seen Admins lock themselves out of NMC while trying to enable LDAP authentications.
1. Log in to the Console server as a user, such as the default administrator, who belongs to the Console Security Administrator role.
2. On each NetWorker server, add an external LDAP user to the NetWorker server Administrator's user group. This step ensures that once LDAP is enabled, at least one user will be able manage the NetWorker server and to add additional NetWorker users as required.
The LDAP user that you add should also belong to the LDAP user roles or LDAP user names that you specify later in step 7.
a. Click the Enterprisebutton on the taskbar.
b. Highlight a host in the navigation tree, right-click NetWorker, and selectLaunch Application. The Administration window appears.
c. Click the Configurationbutton on the taskbar.
d. In the navigation tree, select User Groups.
e. In the User Groupslist, right-click Administratorsand select Properties.
f. Add the LDAP user to theUserattribute. Use the following format to add the user:
User=LDAP_username, host=console_host
where console_hostis the name of the Console server host.
g. Click OK.
3. From the Console Setupmenu, select Configure Login Authentication to launch the Configure Login Authenticationwizard.
The Select Authentication Methodpanel appears.
4. Select the External Repositoryradio button and click Next. The Manage Authentication Authoritiespanel appears.
5. Click Addand then provide information about your authentication authority in the remaining fields. For help on a field, click the question mark (?) at the bottom left side of the wizard panel.
6. Click Nextwhen finished. The Setup Console Security Administratorpanel appears.
7. Enter the LDAP user roles or LDAP user names that will be mapped to the Console Security Administrator role and click Finish.
Note: The LDAP user that was added to the Networker Server Administrator's list instep 2 MUST also be added to the Console Security Administratorrole.
The manual is not easy to understand and i understand just how hard this can be. I spent 2 days with my AD guru getting this working.
Ok so from a busty memory i will try and help you.
Firstly i created 2 accounts, this first is the user to be able to lookup AD on the config LDAP screen. The second pointed to a Backup group in AD. Now both group and users, including the AD lookup user need to be in the same OU.
On the roles based screen add the accounts / groups that are in the AD ou that you want to be added to networker. I have 3, Backup Security admins, Backup Admins and Backup Users. Each once added allows me to add users in AD to the groups and then they can logon to Networker. You will also have to go in to networker and add the groups/users to the admin console under "user groups"
This is just an example. ***** Replace with Networker server name.
If your continually getting errors when you try and go forward from that page as it tries to verify the user/group you have a miss config. go back a page and review your config. for LDAP.
The key here is to make sure the account that you use to do the LDAP lookups is never moved or deleted or your in big trouble. Also make sure you keep a wel documented record of the original administrator account. You may need it one day.
normal2
20 Posts
2280
0
Posted July 3rd, 2010 06:00