Configuring iSCSI-Based Authentication (Task Map)

Configuring iSCSI-Based Authentication (Task Map)

Authentication is the process that enables a target to determine whether a connection request is truly coming from a given host. A target authenticates an initiator using the Challenge-Handshake Authentication Protocol (CHAP). CHAP authentication uses the notion of a challenge and a response. With this method, the target challenges the initiator to prove its identity. For the challenge-response method to work, the target must know the initiator's secret key and the initiator must be configured to respond to a challenge.

iSCSI supports unidirectional and bidirectional authentication.

  • Unidirectional authentication - Enables the target to authenticate the identity of the initiator. Unidirectional authentication is done on behalf of the target to authenticate the initiator.
  • Bidirectional authentication - Adds a second level of security by providing a means for the initiator to authenticate the identity of the target. Bidirectional authentication is driven from the initiator, which controls whether bidirectional authentication is performed. The only setup required for the target is that the chap-user and chap-secret must be correctly defined.

You can simplify CHAP secret management by using a third-party RADIUS server, which acts as a centralized authentication service. When using RADIUS, the RADIUS server stores the set of node names and matching CHAP secrets. The system performing the authentication forwards the node name of the requester and the supplied secret of the requester to the RADIUS server. The RADIUS server can confirm whether the secret is the appropriate one to authenticate the given node name. Both iSCSI and iSER support the use of a RADIUS server.

Task Description Instructions
1. Configure authentication on the iSCSI initiator. Configure CHAP authentication on the iSCSI initiator. How to Configure CHAP Authentication for an iSCSI Initiator
2. Configure authentication on the iSCSI target. Configure CHAP Authentication on the iSCSI target. How to Configure CHAP Authentication for an iSCSI Target
3. (Optional) Use a RADIUS server. Simplify CHAP management for iSCSI targets and initiators by using a RADIUS server. How to Simplify Target CHAP Management Using a RADIUS Server
How to Simplify Initiator CHAP Management Using a RADIUS Server

These procedures use the the iscsiadm and itadm commands. For more information, see the isciadm(1M) and itadm(1M) man pages.

Where to Go Next

Back to COMSTAR Administration Topics


Labels

concept concept Delete
newuser newuser Delete
configuring configuring Delete
storage storage Delete
Enter labels to add to this page:
Please wait 
Looking for a label? Just start typing.

Sign up or Log in to add a comment or watch this page.


The individuals who post here are part of the extended Sun Microsystems community and they might not be employed or in any way formally affiliated with Sun Microsystems. The opinions expressed here are their own, are not necessarily reviewed in advance by anyone but the individual authors, and neither Sun nor any other party necessarily agrees with them.

Copyright 1994-2009 Sun Microsystems, Inc.
Powered by Atlassian Confluence
Sun Guidelines on Public Discourse Privacy Policy Terms of Use Trademarks Site Map Employment Investor Relations Contact