3PAR InForm® OS 2.3.1 CLI Administrator's Manual (320-200180 Rev B, February 2010)

4.35
LDAP Connection on Systems Using Domains
InForm OS Version 2.3.1 3PAR InForm CLI Administrator’s Manual
The example above corresponds to step 3 on page 4.32 and displays the following:
3PARuser is found to be a member of the Software group with edit level privileges. The
Software group is mapped to the Software domain. 3PARuser is assigned edit level
privileges within the
Software domain.
InServ1 cli% checkpassword 3paruser
...
+ temporarily setting name-to-address mapping: domaincontroller.3par.com ->
192.168.10.13
+ attempting to obtain credentials for 3paruser@NTDOM1.3PAR.COM
+ connecting to LDAP server using URI: ldap://192.168.10.13
+ binding to user 3paruser with SASL mechanism GSSAPI
+ searching LDAP using:
search base: OU=Users,DC=3par,DC=COM
filter: (&(objectClass=user)(sAMAccountName=3paruser))
for attributes: memberOf
+ search result DN: CN=3PAR User,OU=Eng,OU=Users,DC=3par,DC=COM
+ search result: memberOf: CN=Software,CN=Users,DC=3par,DC=com
+ search result: memberOf: CN=Eng,CN=Users,DC=3par,DC=com
+ mapping rule: edit mapped to by CN=Software,CN=Users,DC=3par,DC=com
+ rule match: edit mapped to by CN=Software,CN=Users,DC=3par,DC=com
+ mapping rule: browse mapped to by CN=Eng,CN=Users,DC=3par,DC=com
+ rule match: browse mapped to by CN=Eng,CN=Users,DC=3par,DC=com
+ searching LDAP using:
search base: CN=Software,CN=Users,DC=3par,DC=com
filter: (objectClass=group)
for attributes: description
+ search result DN: CN=Software,CN=Users,DC=3par,DC=com
+ search result: description: Software
+ group "CN=Software,CN=Users,DC=3par,DC=com" has potential domain Software
+ searching LDAP using:
search base: CN=Eng,CN=Users,DC=3par,DC=com
filter: (objectClass=group)
for attributes: description
+ search result DN: CN=Eng,CN=Users,DC=3par,DC=com
+ search result: description: Engineering Group, InServDomain=engineering-group-
dom
+ group "CN=Eng,CN=Users,DC=3par,DC=com" has potential domain engineering-group-dom
(transformed from "Engineering Group, InServDomain=engineering-group-dom")
+ domain match: Engineering mapped to browse
+ domain match: Software mapped to edit
user 3paruser is authenticated and authorized