HP StorageWorks XP Performance Advisor Software v4.6 Install Guide (T1789-96096, July 2010)

Table Of Contents
Windows Domain based Authentication
The Windows Domain based Authentication is required if you want to implement the domain-based
authentication for administrators and user domain groups residing on the same or different domains.
Only users belonging to the domain groups are given privileges to log in to XP Performance Advisor.
By default, XP Performance Advisor refers to these groups as HP Storage Admins and HP Storage
Users.
To implement Windows Domain based Authentication, your domain or site administrator must create
the two default domain groups, or the domain groups of choice on the domain controller.
LDAP Authentication
The LDAP Authentication is required if you want to implement the Lightweight Directory Access Protocol
(LDAP) for centralized authentication, where the LDAP server authenticates and authorizes XP
Performance Advisor users. The following LDAP server implementations and authentication mechanism
are supported by XP Performance Advisor v4.5 and later versions:
OpenLDAP
Microsoft Active Directory
Supported LDAP server implementations
SIMPLE (clear-text password) mechanismSupported LDAP authentication mechanism
To implement the LDAP Authentication, complete the following prerequisites:
Install LDAP v3 (RFC 4510) on a server with an established XP Performance Advisor connection.
Create the StorageAdmins and StorageUsers groups on the LDAP server, and add members
to these groups.
For the SIMPLE (clear-text password) mechanism and a secure connection, enable SSL on both the
LDAP server and XP Performance Advisor management station.
IMPORTANT:
Note the LDAP Distinguished Names (DN)s for the StorageAdmins and StorageUsers
groups. An LDAP group used with XP Performance Advisor must have the DNs of the group
members available in an attribute of the group.
Note the UserBaseDN and GroupBaseDN required for XP Performance Advisor to allow au-
thentication and authorization of users.
UserBaseDN is the location in the LDAP tree that contains all the user entries. XP Performance
Advisor uses UserBaseDN to search user entries in the LDAP directory when authenticating
users.
GroupBaseDN is the location in the LDAP tree that contains all the group entries. XP Perform-
ance Advisor uses GroupBaseDN to search group entries in the LDAP directory when author-
izing users.
RADIUS Authentication
RADIUS Authentication is required if you want to implement RADIUS protocol for centralized
authentication, where the RADIUS server authenticates and authorizes XP Performance Advisor users.
The following RADIUS server implementation and authentication mechanisms are supported by XP
Performance Advisor v4.5 and later versions:
HP StorageWorks XP Performance Advisor Software Installation Guide 27