Previous Topic: RBAC and CA 3Tera AppLogic User InterfacesNext Topic: Managing Users and Groups


Configuring Directory Services

Local Directory Service

Each grid includes its own local directory service. This service is used to manage local users and groups. It is also used to store some information about global users and groups. For example, when a global user authenticates, that user’s global group membership is read from the global directory and cached in the local directory. In addition, global user profile properties are stored in the local directory.

Users and groups are managed using the CLI user and group commands.

When a grid is first created, BFC is used to create an initial local user. This user is made a member of the local group admin. The initial user name and password are provided in the BFC GUI:

Working with Directory Services - Controller Tab

Global Directory Service

A global directory service is managed outside of CA 3Tera AppLogic. A CA 3Tera AppLogic grid can be configured to use a global directory service for user authentication and for determining global group membership. There are several benefits to using a global directory service:

Configuration of the interaction of CA 3Tera AppLogic with a global directory service is performed using the backbone fabric controller (BFC). This configuration is protected and can only be changed by the maintainers of the backbone fabric controller. BFC can be used to perform this configuration at the time of grid creation or any time thereafter. CA 3Tera AppLogic supports both Active Directory and generic LDAP directory services.

The following screen shows a typical configuration that uses Active Directory as a global directory service.

BFC Active Directory Services Authentication Tab

The following screen shows a typical configuration that uses generic LDAP as a global directory service.

Typical configuration that uses generic LDAP as a global directory service

Changes made in the BFC global directory configuration interface take effect as soon as they are propagated to the grid. No controller or grid reboot is required. The follow constraints affect grid inter-operation with a global directory service: