hitachivantara.vspone_block.sds_block.hv_sds_block_storage_external_auth_server_setting module – Manages external authentication server settings on VSP One SDS Block and Cloud systems.

Note

This module is part of the hitachivantara.vspone_block collection (version 4.8.2).

You might already have this collection installed if you are using the ansible package. It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.

To install it, use: ansible-galaxy collection install hitachivantara.vspone_block. You need further requirements to be able to use this module, see Requirements for details.

To use it in a playbook, specify: hitachivantara.vspone_block.sds_block.hv_sds_block_storage_external_auth_server_setting.

New in hitachivantara.vspone_block 4.6.0

Synopsis

Requirements

The below requirements are needed on the host that executes this module.

  • python >= 3.9

Parameters

Parameter

Comments

connection_info

dictionary / required

Information required to establish a connection to the storage system.

address

string / required

IP address or hostname of the storage system.

connection_type

string

Type of connection to the storage system.

Choices:

  • "direct" ← (default)

password

string / required

Password for authentication. This is a required field.

username

string / required

Username for authentication. This is a required field.

spec

dictionary

Specification for External Auth Server Settings.

auth_protocol

string

Authentication protocol used for external authentication.

Choices:

  • "LDAP" ← (default)

download_location

string

Local filesystem path where the root certificate will be downloaded.

is_enabled

boolean

Whether external authentication is enabled.

Choices:

  • false

  • true

ldap_setting

dictionary

LDAP-specific configuration settings.

base_dn

string

Base distinguished name (DN) for LDAP searches.

bind_dn

string

Distinguished name (DN) used to bind to the LDAP server.

bind_dn_password

string

Password for the bind DN.

external_group_name_attribute

string

LDAP attribute used as the external group name.

is_start_tls_enabled

boolean

Whether STARTTLS is enabled for LDAP communication.

Choices:

  • false

  • true

mapping_mode

string

Specifies how LDAP entries are mapped.

Choices:

  • "User"

  • "Group"

max_retries

integer

Maximum number of retry attempts for LDAP operations.

primary_ldap_server_url

string

URL of the primary LDAP server.

retry_interval_milliseconds

integer

Interval in milliseconds between retry attempts.

secondary_ldap_server_url

string

URL of the secondary LDAP server.

timeout_seconds

integer

Timeout value in seconds for LDAP operations.

user_group_object_class

string

LDAP object class used for group entries.

user_group_tree_dn

string

Base DN under which group entries are searched.

user_id_attribute

string

LDAP attribute used as the user ID.

user_object_class

string

LDAP object class used for user entries.

user_tree_dn

string

Base DN under which user entries are searched.

root_certificate_file_path

string

Absolute path of the root certificate file to be imported.

target_server

string

Hostname or IP address of the external authentication server.

state

string

State of the external authentication server settings.

Choices:

  • "present" ← (default)

  • "download_root_certificate"

  • "import_root_certificate"

Attributes

Attribute

Support

Description

check_mode

Support: none

Determines if the module should run in check mode.

Examples

- name: Update external auth server settings
  hitachivantara.vspone_block.sds_block.hv_sds_block_storage_external_auth_server_setting:
    connection_info:
      address: sdsb.company.com
      username: "admin"
      password: "password"
    spec:
      auth_protocol: "LDAP"
      is_enabled: true
      ldap_setting:
        base_dn: "dc=esd-dc1,dc=sie,dc=hds,dc=com"
        bind_dn: "cn=ldap1,cn=Users,dc=esd-dc1,dc=sie,dc=hds,dc=com"
        bind_password: "CHANGEME_123"
        external_group_name_attribute: "sAMAccountName"
        is_start_tls_enabled: false
        mapping_mode: "Group"
        max_retries: 1
        primary_ldap_server_url: "ldap://esd-dc1.sie.hds.com"
        retry_interval_milliseconds: 100
        secondary_ldap_server_url: ""
        timeout_seconds: 7
        user_group_object_class: "Group"
        user_group_tree_dn: "ou=StorageGroups,dc=esd-dc1,dc=sie,dc=hds,dc=com"
        user_id_attribute: "sAMAccountName"
        user_object_class: "User"
        user_tree_dn: "ou=StorageUsers,dc=esd-dc1,dc=sie,dc=hds,dc=com"

- name: Verify external auth server settings
  hitachivantara.vspone_block.sds_block.hv_sds_block_storage_external_auth_server_setting:
    connection_info:
      address: sdsb.company.com
      username: "admin"
      password: "password"

Return Values

Common return values are documented here, the following are the fields unique to this module:

Key

Description

external_auth_server_settings

dictionary

External authentication server configuration settings.

Returned: success

auth_protocol

string

Authentication protocol used by the external authentication server.

Returned: success

Sample: "LDAP"

is_enabled

boolean

Indicates whether external authentication is enabled.

Returned: success

Sample: false

ldap_setting

dictionary

LDAP-specific configuration settings.

Returned: success

base_dn

string

Base distinguished name used for LDAP searches.

Returned: success

Sample: "dc=example,dc=com"

bind_dn

string

Distinguished name used to bind to the LDAP server.

Returned: success

Sample: "cn=admin,dc=example,dc=com"

external_group_name_attribute

string

LDAP attribute used as the external group name.

Returned: success

Sample: "cn"

is_start_tls_enabled

boolean

Indicates whether STARTTLS is enabled for LDAP connections.

Returned: success

Sample: false

mapping_mode

string

Mapping mode used for LDAP user and group mapping.

Returned: success

Sample: "User"

max_retries

integer

Maximum number of retry attempts for LDAP connections.

Returned: success

Sample: 1

primary_ldap_server_url

string

URL of the primary LDAP server.

Returned: success

Sample: "ldap://ldap-primary.example.com"

retry_interval_milliseconds

integer

Interval between retry attempts in milliseconds.

Returned: success

Sample: 100

secondary_ldap_server_url

string

URL of the secondary LDAP server.

Returned: success

Sample: "ldap://ldap-secondary.example.com"

timeout_seconds

integer

LDAP connection timeout in seconds.

Returned: success

Sample: 7

user_group_object_class

string

LDAP object class used for user groups.

Returned: success

Sample: "group"

user_group_tree_dn

string

Distinguished name for the LDAP user group search tree.

Returned: success

Sample: "ou=groups,dc=example,dc=com"

user_id_attribute

string

LDAP attribute used as the user identifier.

Returned: success

Sample: "cn"

user_object_class

string

LDAP object class used for user entries.

Returned: success

Sample: "person"

user_tree_dn

string

Distinguished name for the LDAP user search tree.

Returned: success

Sample: "ou=users,dc=example,dc=com"

Authors

  • Hitachi Vantara LTD (@hitachi-vantara)