PowerFlex Manager LDAP Integration shows how to integrate the PowerFlex Manager with LDAP for authentication purposes.
Our lab environment has a PowerFlex Manager 4.5.2 and an Active Directory on a Windows Server 2022.
The default username to access the PowerFlex Manager UI is “admin.” It is a local username, and its password is created during the deployment. We can create additional local usernames and associate a role for each (SuperUser, SuperAdmin, Monitor, etc). A role is a set of permissions in the system.
In addition to local users, we can access the PowerFlex Manager UI using remote users, such as LDAP/Active Directory users. This is the focus of this article!
1- Access the PowerFlex Manager UI and click on “Settings”:
data:image/s3,"s3://crabby-images/f960d/f960da18a220c27fafd5a734f985622659edec18" alt=""
2- Click on “Directory Services” under the “User Management”:
data:image/s3,"s3://crabby-images/ee2c7/ee2c70d2b5ee1cb1e43af0d7712fe7f1ff91c278" alt=""
Click “Add”:
data:image/s3,"s3://crabby-images/c5727/c57276092ec02fa6be5ac115aad6457029ad559f" alt=""
On this page, we need to provide all the necessary details about the LDAP server (in this case, for instance, our LDAP server is the Active Directory server):
data:image/s3,"s3://crabby-images/f6166/f6166affb30261d16775c3c846c6eaabee2a5038" alt=""
After clicking “Test Connection,” receiving a “Good” message is desirable. This means that the PowerFlex Manager could connect to the LDAP server.
After that, click on “Submit”:
data:image/s3,"s3://crabby-images/aab81/aab81716bfc6e58be5b001307b6338a71711e009" alt=""
Note: Under the “Bind DN,” we need a specific Active Directory username with minimal permission to reach the Active Directory users and groups. The PowerFlex Manager uses this account to talk with the Active Directory servers:
data:image/s3,"s3://crabby-images/65e29/65e29469f242bd281fe070e539a2d42099b38e16" alt=""
3- Afterward, click on “Remote Users/Groups” under the “User Management”:
data:image/s3,"s3://crabby-images/22192/22192f4076aa51ac56eca9eeb44ab06118743c21" alt=""
Click “Add”:
data:image/s3,"s3://crabby-images/75c94/75c94ff2b08da7d4aa10141bce51a99cff4b2101" alt=""
On this page, we will add two AD groups:
- GG_PF-ADMINS: AD users with a “SystemAdmin” role in the PowerFlex Manager;
- GG_PF-MONITOR: AD users with a “Monitor” role in the PowerFlex Manager.
data:image/s3,"s3://crabby-images/ddc67/ddc67960f1758a6dfb597d2509bfb1b24c499e8a" alt=""
data:image/s3,"s3://crabby-images/569c8/569c84dcc9ef9242dda8809966cd15c26d355513" alt=""
4- Test!
Accessing the PowerFlex Manager UI with an AD user in the group “GG_PF-ADMINS”:
data:image/s3,"s3://crabby-images/3f4a8/3f4a88cfc48c1b2a9c7b1e79f600f05329e1b54b" alt=""
Accessing the PowerFlex Manager UI with an AD user in the group “GG_PF-MONITOR”:
data:image/s3,"s3://crabby-images/8e719/8e71900199ea467baad7b7b8c9989f9ea0763654" alt=""
That’s it 🙂