External authentication

Last Updated : Jun 20, 2024 |

The External Identity Repositories Web page in System Manager contains a summary page for Authentication scheme and Authentication servers. You can configure the authentication scheme and the authentication servers for System Manager.

System Manager supports the following authentication authorities:

  • Local users

  • External RADIUS users

  • External LDAP users

  • External Security Assertion Markup Language (SAML) users

Note:
  • If you are using Microsoft Active Directory for external authentication with System Manager, the userPrincipalName attribute of the user in the external server must contain a valid value.

  • If you are using the LDAP server other than Microsoft Active Directory for external authentication with System Manager, the UID attribute of the user in the external server must contain a valid value.

  • If you have configured external authentication before upgrading to System Manager 10.1.3.3 or 10.2.0.1 and higher releases, reset Password for Root Binding through the web console following the upgrade.

The authentication scheme policy determines the order in which you can use the authentication authorities. The supported order is as follows:

  1. Local users (default)

  2. External RADIUS users then local users

  3. External LDAP users then local users

  4. External Kerberos users, then local users

  5. External LDAP users, then external RADIUS users, then local users

  6. External RADIUS users, then external LDAP users, then local users

  7. External KERBEROS users, then external multiple LDAP users, then local users

The authentication servers policy controls the settings for the external SAML, LDAP, RADIUS, and KERBEROS servers.

Authentication scheme policy

System Manager supports the following authentication authorities:

  • Local servers

  • External RADIUS servers

  • External LDAP servers (including Sun ONE or Microsoft active directory server)

  • KERBEROS server

  • SAML