Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Please make sure you have the following details for the next steps of configuration:

LDAP server(s) IP address(es)Up to 2 IP addresses may be configured - a primary IP address and an alternate one
LDAP server port(s)e.g. 389 or 3268 if using Global Catalog in AD
ReferralsWhether LDAP referrals should be followed or ignored (usually ignored for better performance)
A user distinguished name (DN)
and its password

Used to connect to the LDAP server and can perform queries.
e.g. "cn=LDAP Query User,ou=people,dc=example,dc=org"

...

Please make sure you have the following detailsdetails for the next steps of configuration:

User base entryThe location of user entries in the LDAP tree. Specific locations have better performance than global ones.
e.g. "ou=people,dc=example,dc=org"
Query sub-treeWhether user entries should be queried in the entire sub-tree of the user base entry (usually true).
User search queryThe query to perform in order to find a user entry based on the login username.
Usually the user search query combines 2 conditions: First filter the entries based on "objectClass" attribute and then filter the entries based on the login username.
Usually user entries may be identified by an "objectClass" of "person", "organizationalPerson" or "inetOrgPerson".
The user entry attribute that contains the login username is usually "uid", "sAMAccountName" or "cn".
e.g. "(&(objectClass=person)(sAMAccountName={0}))"
A username user and its password for testingA real user defined in the LDAP user registry who will be using DPOD - will be used to verify that the configuration is valid

...

Please make sure you have the following detailsdetails for the next steps of configuration:

Group base entryThe location of group entries in the LDAP tree. Specific locations have better performance than global ones.
e.g. "ou=groups,dc=example,dc=org"
Query sub-treeWhether group entries should be queried in the entire sub-tree of the group base entry (usually true).
Nested groupsWhether group entries can be nested in each other (usually true).
Group search queryThe query to perform in order to fetch the list of groups a user belongs to once a user has authenticated successfully.
Usually the group search query combines 2 conditions: First filter the entries based on "objectClass" attribute and then filter the entries based on the authenticated user.
Usually group entries may be identified by an "objectClass" of "group" or "groupOfUniqueNames".
The group entry attribute that contains its members is usually "member" or "uniquemember".
e.g. "(&(objectClass=groupOfUniqueNames)(uniqueMember={1}))"

...

If you choose this scenario, please make sure you have the following detailsdetails for the next steps of configuration:

User entry attribute name

The attribute name at the user entry that contains the built-in role name of that user.
e.g. "DPOD_Role"

...

If you choose this scenario, please make sure you have the following detailsdetails for the next steps of configuration:

Group entry attribute nameThe attribute name at the group entry that contains the built-in role name of users that belong to that group.
e.g. "cn"

...