Go to main content
Oracle® ZFS Storage Appliance Administration Guide, Release OS8.7.0

Exit Print View

Updated: July 2017
 
 

Identity Mapping Best Practices

  • Configure user-specific identity mapping rules when you want a user to have access to a common set of files through both NFS and SMB clients. If NFS and SMB clients are accessing disjointed filesystems, there is no need to configure any identity mapping rules.

  • Reconfiguring the identity mapping service does not affect active SMB sessions. Connected users remain connected, and their previous name mapping is available for authorizing access to additional shares for up to 10 minutes. To prevent unauthorized access, configure the mappings before exporting shares.

  • The security that your identity mappings provide is only as good as their synchronization with your directory services. For example, if you create a name-based mapping that denies access to a particular user, and the user's name changes, the mapping no longer denies access to that user.

  • You can only have one bidirectional mapping for each Windows domain that maps all users in the Windows domain to all UNIX identities. If you want to create multiple domain-wide rules, be sure to specify that those rules map only from Windows to UNIX.

  • Use the IDMU mapping mode instead of directory-based mapping whenever possible.