User's Manual
Using the CMC Directory Service 251
The Association Object allows for as many or as few users and/or groups as
well as RAC Device Objects. However, the Association Object only includes
one Privilege Object per Association Object. The Association Object
connects the "Users" who have "Privileges" on the RACs (CMCs).
Additionally, you can configure Active Directory objects in a single domain or
in multiple domains. For example, you have two CMCs (RAC1 and RAC2)
and three existing Active Directory users (user1, user2, and user3). You want
to give user1 and user2 an administrator privilege to both CMCs and give
user3 a login privilege to the RAC2 card. Figure 8-3 illustrates how you set up
the Active Directory objects in this scenario.
When adding Universal Groups from separate domains, create an Association
Object with Universal Scope. The Default Association objects created by the
Dell Schema Extender Utility are Domain Local Groups and does not work
with Universal Groups from other domains.
Figure 8-3. Setting Up Active Directory Objects in a Single Domain
AO1 AO2
Priv2Priv1Group1
RAC2RAC1User3User2User1