JavaScript is required to for searching.
Skip Navigation Links
Exit Print View
Oracle® ZFS Storage Appliance Security Guide
Oracle Technology Network
Library
PDF
Print View
Feedback
search filter icon
search icon

Document Information

Oracle ZFS Storage Appliance Security Overview

Initial installation

Physical Security

Administrative Model

ZFSSA Users

Access Control Lists (ACL)

Storage Area Network (SAN)

Data Services

Directory Services

Network Information Service (NIS)

Lightweight Directory Access Protocol (LDAP)

Identity Mapping

IDMU

Directory-based Mapping

Name-based Mapping

Ephemeral Mapping

System Settings

Remote Administrative Access

Logs

More Information

Documentation Mapping

Lightweight Directory Access Protocol (LDAP)

The ZFSSA uses LDAP to authenticate both administrative users as well as some data services users (ftp, http). LDAP over SSL security is supported by the ZFSSA. LDAP is used to retrieve information about users and groups and is used in the following ways:

LDAP connections can be used as an authentication mechanism. For example, when a user attempts to authenticate to the ZFSSA, the ZFSSA can attempt to authenticate to the LDAP server as that user as a mechanism for verifying the authentication.

There are a variety of controls for LDAP connection security:

Data carried over an LDAP connection is encrypted if Kerberos or TLS is used but otherwise is not encrypted. When TLS is used, the first connection at configuration time is not secured. The server's certificate is collected at that time and is used to authenticate later production connections.

It is not possible to import a Certificate Authority certificate to be used to authenticate multiple LDAP servers; neither is it possible to import a particular LDAP server's certificate manually.

Only raw TLS (LDAPS) is supported. STARTTLS connections, which start on an unsecured LDAP connection and then change over to a secured connection, are not supported. LDAP servers that require a client certificate are not supported.