1. There is not client configuration profile exist. We never use this function in the environment. How to configure the profile??
sorry - forgot the attachment.
How to create that client profile should be covered in the iPlanet documentation.
2. I want to set up a stand alone cifs server, and while the client access the folders/files on the server should be authenticated first from the LDAP server. Can we archive this goal ??
No, not this way. If you want full Windows functionality (ACLs, Unicode, large files) then you need a Windows authentication using either Kerberos or NTLM.
LDAP can only provide Unix password encryption that isnt compatible with Windows. So you would have to use the Celerra with old user mode authentication, where you cant use all the modern CIFS features and have to change every Windows client registry to accept plaintext passwords.
If you use a standalone CIFS server than authentication gets done using this servers local users that you created with mmc.
Dont you have a Windows domain that you can join ?
below is the cmd has been issued: [nasadmin@mdnas emc]$ server_ldap server_2 -set -p -domain midea.com.cn -servers 182.1.99.29 -binddn "uid=mdnas,ou=people,o=midea.com.cn,o=isp"
The correct Base DN should be:
Base DN: ou=people,o=midea.com.cn,o=isp. Group DN: ou=group,o=midea.com.cn,o=isp
1. There is not client configuration profile exist. We never use this function in the environment. How to configure the profile?? 2. I want to set up a stand alone cifs server, and while the client access the folders/files on the server should be authenticated first from the LDAP server. Can we archive this goal ??
We have no AD/domain... So we have to use the standalone server with local user function? Is that any way we can do to let the standalone server use the users on LDAP server ? Is that just modify the nsswitch.conf can archive this?
I read the nas cli v5.6 doc, the cmd "server_ldap" can set Base DN with the "-basedn" option. Maybe we should upgrade to v5.6.
BTW, can you give guidlines about how to setup the nfs export on NAS compatible with iPlanet?
We have about 200 of unix and window clients. We were going to setup LDAP for authentication, and now we decide to setup NFS on NAS integation with LDAP by your suggestion.
well, it really depends how much Windows features and functions you need.
This really isnt a Celerra limitation - the only user directory and authentication schemes that Windows can work with are NT domains or Active Directory domains.
You can use 3rdparty products like Centrify or others to sync AD with LDAP or NIS or you can use AD's LDAP to authenticate Unix clients. Or a Samba domain controller (unsupported) that uses a common LDAP
Your other option would be to use the old datamover UNIX authentication method. It think with a properly configured ldap.conf on the data mover it could very well authenticate with LDAP.
But be sure to read the limitations - see attached manual.
You're basically working with a LAN Manager level similar to Windows for Worksgroups ....
NFS is very very different - with NFS v2/3 the client authenticates the user and the NFS server just believes the UID/GID it gets in the NFS request. A NFS server doesnt have to authenticate - it only has to make sure the clients computer is allowed to mount/access. It doesnt have to deal with passwords.
Rainer_EMC
6 Operator
•
8645 Posts
808
0
Posted May 9th, 2008 04:00
sorry - forgot the attachment.
How to create that client profile should be covered in the iPlanet documentation.
server should be authenticated first from the LDAP server. Can we archive this goal ??
No, not this way. If you want full Windows functionality (ACLs, Unicode, large files) then you need a Windows authentication using either Kerberos or NTLM.
LDAP can only provide Unix password encryption that isnt compatible with Windows.
So you would have to use the Celerra with old user mode authentication, where you cant use all the modern CIFS features
and have to change every Windows client registry to accept plaintext passwords.
If you use a standalone CIFS server than authentication gets done using this servers local users that you created with mmc.
Dont you have a Windows domain that you can join ?
1 Attachment
NameSvcs.pdf
NameSvcs.pdf