...
User authentication is by default performed in MediationZone. As an alternative, you can connect to connect to an external LDAP directory for delegated authentication. This facilitates automation of administrative tasks such as creation of users and assigning access groups.
...
The
cn
attribute of group entries must match an access group defined in the system.
Note title Note! performs The platform performs case sensitive comparisons of the cn attributes and access groups.
- For each user in a group entry, the
memberUid
attribute must be set. - All group entries must belong to the object class
posixGroup
. All user entries must belong to the objectclass
posixAccount
.The username must be unique. It cannot duplicate a username that already exists in the system.
Note | ||
---|---|---|
| ||
If a user requires administration rights, they must be added to the Administrator access group, which is a default access group in , and you must create a group named Administrator in the LDAP directory. |
...
All user entries must belong to the
objectclass
user .User's groups have to be provided via
memberOf
attribute.User's login has to be provided via
samaccountname
attribute.The username must be unique. It cannot duplicate a username that already exists in the system.
LDAP Configuration
Select LDAP in Authentication Method dropdown list in the Access Controller Advanced tab.
Access Controller - Advanced tab with LDAP Authentication example
...
Setting | Description | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
Authentication Method | Select the authentication method to be used. The following settings are available:
The default setting is authentication performed by by MediationZone.
| ||||||||||
URL | Enter the URL for the external authentication server. The default ports, 389 for LDAP and 686 for LDAPS, are used unless other ports are specified in the URL.
| ||||||||||
Test Connection | Click this button to test the connection to the authentication server. LDAP attributes and other settings than the URL are not used when testing the connection. | ||||||||||
User Base DN | Enter the LDAP attributes for user lookups in the external authentication server. The substring %s in this value will be replaced with the username entered at login to produce an identifier that is passed to the LDAP server.
| ||||||||||
Group Base DN | Enter the LDAP attributes for group lookups in the external authentication server.
| ||||||||||
Use TLS | Select this check box to enable Transport Layer Security.
| ||||||||||
Use Active Directory Naming | Select this check box if you want to use Active directory specific naming. | ||||||||||
Enable Group Search Bind Credentials | Select this check box if you want to enable group search. You must also populate the Bind DN and Password fields. If you want to run an anonymous lookup, leave this check box empty. | ||||||||||
Bind DN | If you want to use a specific Bind DN to search for the group, enter the Bind DN. | ||||||||||
Password | If you want to use a specific Bind DN to search for the group, enter the password to connect LDAP Server. |
...