This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde. (Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique. (Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica. (Aviso legal)
此内容已经过机器动态翻译。 放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다. 책임 부인
Este texto foi traduzido automaticamente. (Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt. (Haftungsausschluss)
Ce article a été traduit automatiquement. (Clause de non responsabilité)
Este artículo ha sido traducido automáticamente. (Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
加入域并添加用户
在为用户或组帐户分配 RBAC 角色之前,必须通过 RBAC 将该帐户添加到 XenServer®。此过程包括以下任务:
-
将池或服务器加入域。该域可以是以下之一:
- 用户或组所属的域
- 位于同一 Active Directory 林中的域
- 与用户域具有信任关系的域
-
将用户的 Active Directory 帐户或组添加到 XenServer。
将用户的 Active Directory 帐户或组添加到 XenServer 后,该用户将被分配一个固定的池管理员角色。在 XenServer Premium Edition 中,您必须手动为用户或组分配角色。有关详细信息,请参阅为用户和组分配角色。
要更改域,请离开当前域,然后加入新域。
安全 LDAP (LDAPS)
LDAPS 通过在端口 636 上使用 TLS 来保护 XenServer 与 Active Directory 域控制器之间的 LDAP 流量。
在启用 LDAPS 之前,请确保已在域控制器上配置 LDAPS 证书,并且已在池中安装所需的 CA 证书。有关详细的先决条件和证书要求,请参阅安全 LDAP (LDAPS)。
启用 LDAPS 后,XenServer 会根据您在池中安装的受信任 CA 证书验证每个域控制器证书。
注意:
XenServer 仅根据 CA 证书验证证书链。 不支持叶证书或自签名(非 CA)证书。
将 XenServer 或池加入域
- 在 资源窗格 中,选择要为其授予权限的池或服务器。
- 选择 用户 选项卡。
- 选择 加入域。
- 输入具有足够权限的 Active Directory 凭据,以将服务器添加到要加入的域。要加入的域必须指定为完全限定域名 (FQDN),而不是 NetBIOS 名称。例如,输入
your_domain.net而不是your_domain。 -
要使用 LDAPS 加入,请选中 使用 TLS 上的 LDAP (LDAPS) 进行安全的 AD 通信 复选框,然后单击 确定。此复选框仅在您的 XenServer 版本支持 LDAPS 时显示。
如果出现证书错误,请在错误对话框中单击 安装证书…,浏览到 PEM 格式的 CA 证书,然后单击 安装。安装证书后,XenCenter 会自动重试域加入。
当池或服务器加入域时,用户 选项卡会显示访问协议(LDAP 或 LDAPS)。要更改 LDAPS 设置,请单击 配置…,选中或清除 使用 TLS 上的 LDAP (LDAPS) 进行安全的 AD 通信 复选框,然后单击 确定。
将 Active Directory 用户或组添加到池
- 加入用户域后,在 用户 选项卡中,单击 添加。
- 在 添加用户 对话框中,输入一个或多个用户或组名称。多个名称之间用逗号分隔。要在不同的受信任域(当前已加入的域除外)中指定用户,请提供域名和用户名。例如,指定
other_domain\jsmith。或者,您可以输入完全限定域名 (FQDN)。例如,指定jsmith@other_domain.com。 - 选择 授予访问权限。
- 按照 将角色分配给用户和组 为帐户分配角色并授予访问权限。
离开域
注意:
当您离开域时,任何使用 Active Directory 凭据向池或服务器进行身份验证的用户都将断开连接。
- 在资源窗格中,选择要从其 Active Directory 域断开连接的池或服务器。
- 选择离开域,然后选择是以继续。
- 输入具有足够权限的 Active Directory 凭据,以禁用您要离开的域中的服务器。
- 决定是否禁用 Active Directory 服务器中的计算机帐户,然后单击以下选项之一:
- 禁用。将池或服务器从域中移除,并禁用 Active Directory 数据库中服务器或池协调器的计算机帐户。
- 忽略。如果您未填写用户名/密码或不知道具有足够权限的帐户,请选择此选项以从 Active Directory 数据库中移除服务器或池协调器的计算机帐户。此选项会将池或服务器从域中移除,但会将服务器或池协调器的计算机帐户保留在 Active Directory 中。
相关文档
XenServer 当前版本
共享
共享
This Preview product documentation is Cloud Software Group Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Cloud Software Group Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Cloud Software Group product purchase decisions.
If you do not agree, select I DO NOT AGREE to exit.