Application Integration
1751914 Members
5396 Online
108783 Solutions
New Discussion

Re: LDAP authentication in HPE Nimble Storage

 
brbell6238
Occasional Contributor

LDAP authentication in HPE Nimble Storage

Hello, I have a few questions regarding LDAP in my HPE Nimble Storage enviornment.

- First off, what does adding LDAP to my install actualy add in terms of security over AD?

- Can I utilize groups to set a permission a user has individually?

- Do we still need a local user to set permissions but they then authentocate to AD?

- Is local authentication turned off if we enable AD?

- What happens if AD is unreachable?

Thanks

8 REPLIES 8
Nick_Dyer
Honored Contributor

Re: LDAP authentication in HPE Nimble Storage

HI! We have a few blog posts on this site (which have been ported from our old Nimble forums) which detail integration with Microsoft AD.

Here's one that answers many of your questions (fyi do not be alarmed about the comments of requiring SMB1 - we now support SMB2 as of 2018 with NimbleOS 5).

https://community.hpe.com/t5/HPE-Storage-Tech-Insiders/Nimble-OS-3-1-Active-Directory-Integration/ba-p/6986357

Let me know if you have further questions after reading the blog post.

Nick Dyer
twitter: @nick_dyer_
brbell6238
Occasional Contributor

Re: LDAP authentication in HPE Nimble Storage

Thank you sir,

The article you linked was very helpfull. Howerver I still have two questions that I cant seem to find the answers for,

Is local authentication turned off if we enable AD?

What happens if AD is unreachable?

Hopefully you can provide some insight on these,

Cheers

Nick_Dyer
Honored Contributor

Re: LDAP authentication in HPE Nimble Storage

Hello sir,

You'll be pleased to hear that AD authentication doesn't auto-switch off any local accounts created, including the Admin account. Therefore if you do lose connection to AD, you can still access the system via local accounts.

Nick Dyer
twitter: @nick_dyer_
wave2453
Occasional Advisor

Re: LDAP authentication in HPE Nimble Storage

Just to add on to this.

My AD scheme doesn't work with how the Nimble CS3000 uses LDAP. I noticed that even when logging in with a local account while AD was unreachable it would cause severe sluggishness in the UI while trying to sign in and even crash the UI at times. 

I am on the newest OS version BTW.

o35Ltd
Visitor

Re: LDAP authentication in HPE Nimble Storage

Access denied trying to get this - anyone can help here?

Mahesh202
HPE Pro

Re: LDAP authentication in HPE Nimble Storage

Hi o35Ltd

The Array logs and NTP needs to be checked for further troubleshooting, Request you to engage the Nimble support to find out why the " Access Denied " msg is displayed.

Regards
Mahesh

If you feel this was helpful please click the KUDOS! thumb below!

I work for HPE.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

Accept or Kudo


o35Ltd
Visitor

Re: LDAP authentication in HPE Nimble Storage

Hi there,

I think you have not read the case properly – there is a link to set up AD Integration on the HPeNimble website. This link says ‘access denied’. This is not anything that the SAN could log!

The document we want to find ios shown here but says access is denied when you try to access it LDAP authentication in HPE Nimble Storage - Hewlett Packard Enterprise Community<>

If this link is old please can you provide documentation how we can integrate Nimble storage management with Active Directory as we want to use AD accounts to manage the SAN, not local user accounts.

Please let me know

thanks
Mahesh202
HPE Pro

Re: LDAP authentication in HPE Nimble Storage

Hi o35Ltd

May I request you share the link which you tried?
Meanwhile, I would suggest you go through the guidelines for working with Nimble arrays and Active Directory using the below link and refer to Page 155
link for the document: https://infosight.hpe.com/InfoSight/media/cms/active/public/pubs_GUI_Administration_Guide_5_3_x.pdf

Regards
Mahesh

If you feel this was helpful please click the KUDOS! thumb below!

I work for HPE.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

Accept or Kudo