Search the docs

Prerequisites

  • Your organization has an operational LDAP directory. You know its domain name (for example, corp.example.com) and the IP address or DNS name of at least one LDAP server.

  • The LDAP server’s root DSE lists a naming context that matches the domain name in domain-component form. For domain corp.example.com, the server must serve dc=corp,dc=example,dc=com. Hammerspace checks this during the connection test, whatever search base you configure.

  • If your LDAP server does not allow anonymous searches, you have a Bind DN and Bind Secret (password) for an account with read access to the user and group entries.

  • User and group entries use the RFC 2307 or RFC 2307bis schema. User entries must have uidNumber and gidNumber attributes, and Hammerspace matches user names against the uid attribute.

  • The Anvil nodes can reach the LDAP server. If you specify a port, open that port. If you do not specify a port, Hammerspace tries port 389 and then port 636 for each transport mode, so allow both.

  • If you plan to use LDAPS or StartTLS, the CA certificate that issued the LDAP server’s certificate is in the Hammerspace trust store before you add the name service, and the server certificate lists the address you will configure in its Subject Alternative Name (SAN) extension. See Securing LDAP Connections with LDAPS or StartTLS.

  • The cluster is not joined to Active Directory. In Hammerspace 5.3, LDAP name services and Active Directory cannot be configured together.