Setting Up LDAP for Authorization

Learn how to set up LDAP for authorization with File Storage.

  1. Ensure that you have the LDAP infrastructure required and gathered the required information. See Prerequisites for more information.
  2. Add the required IAM policies.
  3. Upload the LDAP password to OCI Vault in plain-text format. For more information, see Overview of Vault.
  4. Create two outbound connectors to contact the LDAP server.
    Note

    Using LDAP for authorization requires at least one outbound connector. A second outbound connector can be used as a backup or for failover. See Secondary Group Lookup and Caching for details on how File Storage responds when it can't reach an LDAP server.
  5. Add LDAP communication details to a mount target.
  6. Create or update a file system that uses the LDAP-enabled mount target.
  7. Enable LDAP on the file system export.
  8. Set any optional NFS export options.
  9. Mount the file system.

Configuring LDAP for a Mount Target

Add LDAP information to a mount target for use in authorization.

Note

When you update an existing mount target to use LDAP, it can take some time for the updates to be fully reflected throughout File Storage.