How to join JumpCloud's LDAP-as-a-Service with a QNAP QTS NAS
This article explains how to join JumpCloud’s LDAP-as-a-Service with a QNAP QTS NAS.
Contents
- JumpCloud and QNAP – Background and Integration Basics
- Setting up a JumpCloud Samba Service Account: Enable a User as an LDAP Bind DN
- Configuring QTS for Microsoft Networking
- Integrating a JumpCloud LDAP Instance in QTS
- Reference Materials
JumpCloud and QNAP – Background and Integration Basics
To connect your QNAP NAS and authenticate JumpCloud’s LDAP service, it is important to understand the relationship between the products and how they are integrated. The diagram below, in conjunction with the instructions that follow, show the basic interoperation of JumpCloud’s LDAP authentication service, the QNAP NAS, and the client attempting to access files.
Setting up a JumpCloud Samba Service Account: Enable a User as an LDAP Bind DN
- Select or create a new user to setup a Samba service account to be used for LDAP authentication with QTS.
- Specify an initial password for the account.
Tip: Consider setting the password to never expire. - Enable the account as an LDAP Bind DN.
- Specify an initial password for the account.
- In Groups, select the user groups that will be synced to QTS.
- Highlight the Group of Users, and then go to the DETAILS tab.
- Select Create Linux group for this user group on a per-group basis.
A corresponding user group will be created on the NAS in Domain Groups.
The QTS NAS reserves a GID range from 0 to 99. When adding a new account, ensure that the UID and GID does not conflict with an existing UID or GID. - Select Enable Samba Authentication to allow all users added to the group to access shared folders on the NAS using their JumpCloud username and password.
Configuring QTS for Microsoft Networking
In order to access file shares on Windows, the name of the workgroup configured in QTS must be identical to the name of the workgroup configured in your JumpCloud LDAP Instance.
- To view the name of the QNAP QTS Workgroup, go to Control Panel > Network & File Services > Win/Mac/NFS > Microsoft Networking.
- To view the name of the JumpCloud workgroup, go to Directories > JumpCloud LDAP > DETAILS in the JumpCloud administrative portal.
Integrating a JumpCloud LDAP Instance in QTS
- In QTS, go to Control Panel > Privilege > Domain Security.
- Select LDAP authentication.
- For Select the type of LDAP server, select Remote LDAP server.
- For LDAP server host, enter ldap.jumpcloud.com.
- For LDAP security, select a security type such as ldap://(ldap+TLS).
- For Base DN, enter the string displayed in JumpCloud under ORG DN in Directories > JumpCloud LDAP > DETAILS.
- For Root DN, enter the string displayed in JumpCloud under SAMBA SERVICE ACCOUNT DN in DIRECTORIES > JumpCloud LDAP > DETAILS.
- Enter the password for the SAMBA SERVICE ACCOUNT (the JumpCloud LDAP administrator password).
- For Users base DN and Group base DN, enter the same string, starting from "ou=Users,o=<Org ID>,dc=jumpcloud,dc=com”.
- Click Apply.
The LDAP authentication options window appears. - Select LDAP users only: Only LDAP users can access the NAS via Microsoft Networking.
- Click Finish.
The NAS connects to the JumpCloud LDAP directory. The connection is established when the Status displays Online.
- JumpCloud users will be displayed in Users or Shared Folders under Domain Users. JumpCloud user groups will be displayed in User Groups under Domain Groups.
Reference Materials
JumpCloud LDAP
Because a QNAP NAS will defer its authentication to an external LDAP server, it is important to understand the basics of enabling and configuring JumpCloud’s LDAP service.
JumpCloud LDAP NAS/Samba Integration Step-by-Step Worksheet
Using JumpCloud’s LDAP-as-a-Service
Enabling JumpCloud’s Samba/SMB
Once LDAP has been configured, you must enable Samba/SMB-specific authentication attributes. This allows JumpCloud’s LDAP service to securely use Windows or macOS clients to access shared folders on a NAS via Samba/SMB.
Enabling Samba Support with JumpCloud LDAP
Configuring QNAP for Microsoft Networking
Configuring a QNAP NAS to use JumpCloud
JumpCloud has specific documentation on configuring a QNAP NAS to authenticate its LDAP services.
Configuring a QNAP NAS to use JumpCloud’s LDAP-as-a-Service