Use the Crypto CLI update-tenant-auth-method-to-ad command to change the authentication mode of the vault from local to managed.

Syntax

cryptocli update-tenant-auth-method-to-ad [options]

Option

Description

-h or --help

Displays usage text.

-a or --ad-domain-name string

The Active Directory setting ID or name. Strings must be enclosed in double quotes.

-n or --ad-domain-type string

The Active Directory AD type. Strings must be enclosed in double quotes.

-j, -ad-servers string

The Active Directory Domain Controller List JSON File. This is an array of JSON objects, each object representing a Domain Controller. Strings must be enclosed in double quotes.

The following keys are supported:

  • server_url - the (mandatory) full url of the Domain Controller

  • cacert (optional) - the path to the CA Certificate to verify with

  • user_base_dn (optional) - the user base DN

  • group_base_dn (optional) - the group base DN

  • timeout (optional) - the connection timeout in seconds. The default is 5 seconds.

  • tls (optional) - whether to enable StartTLS or not. The default is false.

Example:

[
     {
           "server_url": "ldaps://dc1.mycompany.eng.com",
           "cacert": "/root/cacert.pem",
           "user_base_dn": "DC=mycompany,DC=eng,DC=com",
           "group_base_dn": "DC=mycompany,DC=eng,DC=com",
            "timeout": 10,
            "tls": false,
     }
]

-s, --ad-service-account-name string

The Active Directory service account user name. Strings must be enclosed in double quotes.

-p, --ad-service-account-pw string

The Active Directory service account user password. Strings must be enclosed in double quotes.

-u, --ad-uid string

The Active Directory UID Attribute. Strings must be enclosed in double quotes.

-k, --initial-ad-member-cn string

The initial Active Directory member CN. Strings must be enclosed in double quotes.

-d, --initial-ad-member-distinguished-name string

The initial Active Directory member distinguished name. Strings must be enclosed in double quotes.

-m, --initial-ad-member-mail string

The email address for the initial Active Directory member. Strings must be enclosed in double quotes.

-o, --initial-ad-member-upn string

The initial Active Directory member UPN. Strings must be enclosed in double quotes.

-t, --name string

The name of the tenant to be updated. Strings must be enclosed in double quotes.