hitachivantara.vspone_block.sds_block.hv_sds_block_storage_external_auth_server_setting module – Manages external authentication server settings on VSP One SDS Block and Cloud systems.
Note
This module is part of the hitachivantara.vspone_block collection (version 4.8.2).
You might already have this collection installed if you are using the ansible package.
It is not included in ansible-core.
To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install hitachivantara.vspone_block.
You need further requirements to be able to use this module,
see Requirements for details.
To use it in a playbook, specify: hitachivantara.vspone_block.sds_block.hv_sds_block_storage_external_auth_server_setting.
New in hitachivantara.vspone_block 4.6.0
Synopsis
This module allows to configure external authentication server settings.
For examples go to URL https://github.com/hitachi-vantara/vspone-block-ansible/blob/main/playbooks/sds_block_direct/external_auth_server_setting.yml
Requirements
The below requirements are needed on the host that executes this module.
python >= 3.9
Parameters
Parameter |
Comments |
|---|---|
Information required to establish a connection to the storage system. |
|
IP address or hostname of the storage system. |
|
Type of connection to the storage system. Choices:
|
|
Password for authentication. This is a required field. |
|
Username for authentication. This is a required field. |
|
Specification for External Auth Server Settings. |
|
Authentication protocol used for external authentication. Choices:
|
|
Local filesystem path where the root certificate will be downloaded. |
|
Whether external authentication is enabled. Choices:
|
|
LDAP-specific configuration settings. |
|
Base distinguished name (DN) for LDAP searches. |
|
Distinguished name (DN) used to bind to the LDAP server. |
|
Password for the bind DN. |
|
LDAP attribute used as the external group name. |
|
Whether STARTTLS is enabled for LDAP communication. Choices:
|
|
Specifies how LDAP entries are mapped. Choices:
|
|
Maximum number of retry attempts for LDAP operations. |
|
URL of the primary LDAP server. |
|
Interval in milliseconds between retry attempts. |
|
URL of the secondary LDAP server. |
|
Timeout value in seconds for LDAP operations. |
|
LDAP object class used for group entries. |
|
Base DN under which group entries are searched. |
|
LDAP attribute used as the user ID. |
|
LDAP object class used for user entries. |
|
Base DN under which user entries are searched. |
|
Absolute path of the root certificate file to be imported. |
|
Hostname or IP address of the external authentication server. |
|
State of the external authentication server settings. Choices:
|
Attributes
Attribute |
Support |
Description |
|---|---|---|
Support: none |
Determines if the module should run in check mode. |
Examples
- name: Update external auth server settings
hitachivantara.vspone_block.sds_block.hv_sds_block_storage_external_auth_server_setting:
connection_info:
address: sdsb.company.com
username: "admin"
password: "password"
spec:
auth_protocol: "LDAP"
is_enabled: true
ldap_setting:
base_dn: "dc=esd-dc1,dc=sie,dc=hds,dc=com"
bind_dn: "cn=ldap1,cn=Users,dc=esd-dc1,dc=sie,dc=hds,dc=com"
bind_password: "CHANGEME_123"
external_group_name_attribute: "sAMAccountName"
is_start_tls_enabled: false
mapping_mode: "Group"
max_retries: 1
primary_ldap_server_url: "ldap://esd-dc1.sie.hds.com"
retry_interval_milliseconds: 100
secondary_ldap_server_url: ""
timeout_seconds: 7
user_group_object_class: "Group"
user_group_tree_dn: "ou=StorageGroups,dc=esd-dc1,dc=sie,dc=hds,dc=com"
user_id_attribute: "sAMAccountName"
user_object_class: "User"
user_tree_dn: "ou=StorageUsers,dc=esd-dc1,dc=sie,dc=hds,dc=com"
- name: Verify external auth server settings
hitachivantara.vspone_block.sds_block.hv_sds_block_storage_external_auth_server_setting:
connection_info:
address: sdsb.company.com
username: "admin"
password: "password"
Return Values
Common return values are documented here, the following are the fields unique to this module:
Key |
Description |
|---|---|
External authentication server configuration settings. Returned: success |
|
Authentication protocol used by the external authentication server. Returned: success Sample: |
|
Indicates whether external authentication is enabled. Returned: success Sample: |
|
LDAP-specific configuration settings. Returned: success |
|
Base distinguished name used for LDAP searches. Returned: success Sample: |
|
Distinguished name used to bind to the LDAP server. Returned: success Sample: |
|
LDAP attribute used as the external group name. Returned: success Sample: |
|
Indicates whether STARTTLS is enabled for LDAP connections. Returned: success Sample: |
|
Mapping mode used for LDAP user and group mapping. Returned: success Sample: |
|
Maximum number of retry attempts for LDAP connections. Returned: success Sample: |
|
URL of the primary LDAP server. Returned: success Sample: |
|
Interval between retry attempts in milliseconds. Returned: success Sample: |
|
URL of the secondary LDAP server. Returned: success Sample: |
|
LDAP connection timeout in seconds. Returned: success Sample: |
|
LDAP object class used for user groups. Returned: success Sample: |
|
Distinguished name for the LDAP user group search tree. Returned: success Sample: |
|
LDAP attribute used as the user identifier. Returned: success Sample: |
|
LDAP object class used for user entries. Returned: success Sample: |
|
Distinguished name for the LDAP user search tree. Returned: success Sample: |