This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde. (Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique. (Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica. (Aviso legal)
此内容已经过机器动态翻译。 放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다. 책임 부인
Este texto foi traduzido automaticamente. (Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt. (Haftungsausschluss)
Ce article a été traduit automatiquement. (Clause de non responsabilité)
Este artículo ha sido traducido automáticamente. (Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
管理用户
首次安装 XenServer 时,会自动向 XenServer 添加一个用户帐户。此帐户是本地超级用户 (LSU),即 root,XenServer 系统会在本地对其进行身份验证。您可以通过在 XenCenter 的“用户”选项卡中添加 Active Directory 帐户来创建其他用户。
注意:
“用户”一词指拥有 XenServer® 帐户的任何人,即任何管理 XenServer 主机的人员,无论其角色级别如何。
如果您想在服务器或池上拥有多个用户帐户,则必须使用 Active Directory 用户帐户进行身份验证。此功能允许 XenServer 用户使用其 Windows 域凭据登录到池中的服务器。
注意:
不支持混合身份验证池。也就是说,您不能拥有一个池,其中一些服务器使用 Active Directory 而另一些不使用。
在 XenServer 中创建用户时,必须先为新创建的用户分配角色,然后他们才能使用该帐户。XenServer 不会自动为新创建的用户分配角色。因此,在您为这些帐户分配角色之前,它们无法访问 XenServer 池。
使用基于角色的访问控制 (RBAC) 功能,您可以根据用户的角色为 Active Directory 帐户分配不同级别的权限。如果您的环境中不使用 Active Directory,则只能使用 LSU 帐户。
XenServer 环境中的 AD 身份验证
尽管 XenServer 服务器基于 Linux,但 XenServer 允许您将 Active Directory 帐户用于 XenServer 用户帐户。为此,它会将 Active Directory 凭据传递给 Active Directory 域控制器。
注意:
您可以在 AD 域控制器上启用 LDAP 通道绑定和 LDAP 签名。有关详细信息,请参阅Microsoft 安全公告。
添加到 XenServer 后,Active Directory 用户和组将成为 XenServer 主体,在 XenCenter 中称为用户。当主体在 XenServer 中注册时,用户和组会在登录时通过 Active Directory 进行身份验证。这些用户和组无需使用域名限定其用户名。
要限定用户名,您必须以向下兼容登录名格式输入用户名,例如 mydomain\myuser。
注意:
默认情况下,如果您未限定用户名,XenCenter 会尝试使用其加入的域登录 Active Directory 身份验证服务器上的用户。此规则的例外是 LSU 帐户,XenCenter 始终首先在本地(即在 XenServer 上)对其进行身份验证。
外部身份验证过程工作方式如下:
- 连接到服务器时提供的凭据会传递给 Active Directory 域控制器以进行身份验证。
- 域控制器会检查凭据。如果凭据无效,身份验证会立即失败。
- 如果凭据有效,系统会查询 Active Directory 控制器以获取与凭据关联的主体标识符和组成员身份。
- 如果主体标识符与 XenServer 中存储的标识符匹配,身份验证将成功完成。
当您加入域时,您将为池启用 Active Directory 身份验证。但是,当池加入域时,只有该域中的用户(或与其具有信任关系的域中的用户)才能连接到池。
相关文档
XenServer 当前版本
共享
共享
This Preview product documentation is Cloud Software Group Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Cloud Software Group Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Cloud Software Group product purchase decisions.
If you do not agree, select I DO NOT AGREE to exit.