Veritas Access Appliance 8.2 Administrator's Guide
- Section I. Introducing Access Appliance
- Section II. Configuring Access Appliance
- Managing users
- Managing licenses
- Configuring the network
- Configuring authentication services
- Configuring user authentication using digital certificates or smart cards
- Section III. Managing Access Appliance storage
- Configuring storage
- Managing disks
- Access Appliance as an iSCSI target
- Configuring storage
- Section IV. Managing Access Appliance file access services
- Configuring the NFS server
- Setting up Kerberos authentication for NFS clients
- Using Access Appliance as a CIFS server
- About configuring CIFS for Active Directory (AD) domain mode
- About setting trusted domains
- About managing home directories
- About CIFS clustering modes
- About migrating CIFS shares and home directories
- Using Access Appliance as an Object Store server
- Configuring the S3 server using GUI
- Configuring the NFS server
- Section V. Managing Access Appliance security
- Managing security
- Setting up FIPS mode
- Configuring STIG
- Setting the banner
- Setting the password policy
- Immutability in Access Appliance
- Deploying certificates on Access Appliance
- Single Sign-On (SSO)
- Configuring multifactor authentication
- Section VI. Monitoring and troubleshooting
- Monitoring the appliance
- Configuring event notifications and audit logs
- About alert management
- Appliance log files
- Section VII. Provisioning and managing Access Appliance file systems
- Creating and maintaining file systems
- Considerations for creating a file system
- About managing application I/O workloads using maximum IOPS settings
- Modifying a file system
- Managing a file system
- Creating and maintaining file systems
- Section VIII. Provisioning and managing Access Appliance shares
- Creating shares for applications
- Creating and maintaining NFS shares
- About the NFS shares
- Creating and maintaining CIFS shares
- About the CIFS shares
- About managing CIFS shares for Enterprise Vault
- Integrating Access Appliance with Data Insight
- Section IX. Managing Access Appliance storage services
- Configuring episodic replication
- Configuring an episodic replication job using the GUI
- Episodic replication job failover and failback
- Configuring continuous replication
- How Access Appliance continuous replication works
- Configuring a continuous replication job using the GUI
- Continuous replication failover and failback
- Using snapshots
- Using instant rollbacks
- Configuring episodic replication
- Section X. Reference
Configuring SSO on Access Appliance
Configuring SSO on Access Appliance involves the following steps:
Table:
Task | Description |
---|---|
Configuring SSO on an Access Appliance cluster | |
Adding users/group | |
Configuring an identity provider | |
Logging into Access Appliance with SSO | See Login with SSO |
To configure SSO on an Access Appliance cluster
- Go to Settings > Security management > Single sign-on (SSO). Click Add.
- Give the IDP name and upload the IDP metadata xml and optionally provide the custom user field and group field values. The user field and group field values should be same as configured on the IDP. Click Save.
The UI displays a message that confirms that the add identity provider task is triggered. You can click View Details to see the progress of the task. Alternatively, you can also click the Recent Activity icon from the top right of the UI to see the status of the most recent operations.
- Once the configuration is complete, the SSO identify provider details are displayed on the screen. Click Download service provider xml to download the details and upload it on IDP server, if required.
To configure an identity provider
- Login with SSO works only if the configuration on the IDP side is done. Each IDP has different steps for configuration.
Note:
The IDP should always sign the assertation to ensure that the configuration is trustworthy.
Refer to the following links for the configuration steps for each identity provider.
ADFS: Enrolling Access Appliance primary server as a service provider to ADFS
Azure: Enrolling Access Appliance primary server as a service provider to Azure
Okta: Enrolling Access Appliance primary server as a service provider to Okta
Pingfederate: Enrolling Access Appliance primary server as a service provider to Pingfederate
Login with SSO
- Navigate to GUI login page. Click Sign-in with single sign-on (SSO).
- Enter SSO credentials and click Sign in.