1
0
mirror of https://github.com/minio/docs.git synced 2025-07-30 07:03:26 +03:00

DOCS-1022: Use 'mc idp ldap policy' for AD/LDAP policy assignments (#1026)

---------

Co-authored-by: Daryl White <53910321+djwfyi@users.noreply.github.com>
This commit is contained in:
Ravind Kumar
2023-10-05 16:59:43 -04:00
committed by GitHub
parent 091a321e32
commit 6a1697c9f5
4 changed files with 35 additions and 7 deletions

View File

@ -66,12 +66,15 @@ Use either of the following methods to create a new access key:
Mapping Policies to User DN
---------------------------
Consider the following policy assignments:
The following commands use :mc-cmd:`mc idp ldap policy attach` to associate an existing MinIO :ref:`policy <minio-policy>` to an AD/LDAP User DN.
.. code-block:: shell
mc admin policy attach myminio consoleAdmin --user='cn=sisko,cn=users,dc=example,dc=com'
mc admin policy attach myminio readwrite,diagnostics --user='cn=dax,cn=users,dc=example,dc=com'
mc idp ldap policy attach myminio consoleAdmin \
--user='cn=sisko,cn=users,dc=example,dc=com'
mc idp ldap policy attach myminio readwrite,diagnostics \
--user='cn=dax,cn=users,dc=example,dc=com'
- MinIO would assign an authenticated user with DN matching
``cn=sisko,cn=users,dc=example,dc=com`` the :userpolicy:`consoleAdmin`
@ -88,12 +91,15 @@ Consider the following policy assignments:
Mapping Policies to Group DN
----------------------------
Consider the following policy assignments:
The following commands use :mc-cmd:`mc idp ldap policy attach` to associate an existing MinIO :ref:`policy <minio-policy>` to an AD/LDAP Group DN.
.. code-block:: shell
mc admin policy attach myminio consoleAdmin --group='cn=ops,cn=groups,dc=example,dc=com'
mc admin policy attach myminio diagnostics --group='cn=engineering,cn=groups,dc=example,dc=com'
mc idp ldap policy attach myminio consoleAdmin \
--group='cn=ops,cn=groups,dc=example,dc=com'
mc idp ldap policy attach myminio diagnostics \
--group='cn=engineering,cn=groups,dc=example,dc=com'
- MinIO would assign any authenticating user with membership in the
``cn=ops,cn=groups,dc=example,dc=com`` AD/LDAP group the