Brocade Network Advisor IP User Manual 389
53-1003056-01
AAA Settings tab 12
5. Enter the password for the Management application service account configured on the AD
server in the Password and Confirm Password fields.
6. Enter the Kerberos SPN in the Kerberos Service Principal Name field.
The SPN name uses the following syntax: <Service_Name>/<Hostname>, where hostname is
the Management application server’s host name with domain name. For example:
NetworkManagementSPN/DCM-VNext-65.JCB.COM
7. Test the established active connection with the server by clicking Test.
The Test Authentication dialog box displays. Test performs the following functions and
verifications:
Obtains the Kerberos Ticket Granting Ticket (TGT) of the currently logged in user from
Windows cached credentials.
Sends the TGT to the AD server to which the Management application server is connected
and requests the session ticket for the SPN configured on AD server.
Kerberos encryptsthe session ticket with the credentials of the AD server user account
mapped to this SPN.
Logs on to the AD of the Management application server using the AD server
single-sign-on (SSO) service account.
Verifies the service ticket by decrypting it using AD server SSO service account credentials.
8. Click Apply to save the configuration.
To display the authentication audit trail, refer to “Displaying the client authentication audit
trail” on page 391.
9. Click Close to close the Server Management Console.
Configuring switch authentication
Switch authentication enables you to authenticate a user account against the switch database and
the Management application server. You can configure up to three switches and specify the fall
back order if one or more of the switches is not available.
NOTE
Switch authentication is only supported on Fabric OS devices.
To configure switch authentication, complete the following steps.
1. Select the AAA Settings tab.
2. For Primary Authentication, select Switch.
3. Click Add.
4. Enter the switch IP address and click OK.
You can add up to three switches.
5. Select a switch and click the Up or Down button to set the fall back order.
6. Select a switch and click Delete to remove a switch from the list.
7. Set secondary authentication by selecting one of the following options from the Secondary
Authentication list: