Use the KMIPCLI update-vault-auth-method-to-ad command to update the authentication method to Active Directory.

Important: If you are using an older version of KMIPCLI, this command may be called update-tenant-auth-method-to-ad.

Syntax

kmipcli update-vault-auth-method-to-ad [options]

Option

Description

-h or --help

Displays usage text.

-a, --ad-domain-name string

The Active Directory name.

-t, --ad-domain-type string

The Active Directory domain type. This can be one of the following: 

  • Microsoft_AD

  • openLDAP

-j

The Active Directory Domain Controller List JSON File. This is an array of JSON objects, each object representing a Domain Controller. Strings must be enclosed in double quotes.

The following keys are supported:

  • server_url - the (mandatory) full url of the Domain Controller

  • cacert (optional) - the path to the CA Certificate to verify with

  • user_base_dn (optional) - the user base DN

  • group_base_dn (optional) - the group base DN

  • timeout (optional) - the connection timeout in seconds. The default is 5 seconds.

  • tls (optional) - whether to enable StartTLS or not. The default is false.

Example:

[
     {
           "server_url": "ldaps://dc1.mycompany.eng.com",
           "cacert": "/root/cacert.pem",
           "user_base_dn": "DC=mycompany,DC=eng,DC=com",
           "group_base_dn": "DC=mycompany,DC=eng,DC=com",
            "timeout": 10,
            "tls": false,
     }
]

-p, --ad-service-account-pw string

The Active Directory service account user password. Strings must be enclosed in double quotes.

You can enter the value either through the console or by using a flag.

-s, --ad-service_account_name string

The Active Directory service account user name. Strings must be enclosed in double quotes. To clear, set it to "unset".

You can enter the value either through the console or by using a flag.

--u, --ad-uid string

The Active Directory UID attribute. Strings must be enclosed in double quotes.

-k, --initial-ad-member-cn string

The initial Active Directory member CN.

-d, --initial-ad-member-distinguished-name string

The initial Active Directory member distinguished name.

-m, --initial-ad-member-mail string

The initial Active Directory member email address.

-o, --initial-ad-member-upn string

The initial Active Directory member UPN.

-n, --name string

The name of the vault to be updated.