Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

The LDAP Configuration page (Administration: LDAP Configuration, visible only for License Statistics administrator users) lets you define schema settings for LDAP Users Import and LDAP Authentication, described below. The schema settings are fully customizable, and are initially populated with entries according to the Directory Type selected when defining the configuration (Active Directory, LDAP, or LDAP with POSIX). 

LDAP Users Import

To see the schema settings for LDAP Users Import, click the Schema Settings expand button in the Enable LDAP Users Import area of the LDAP Configuration page:

Image Added

The following table defines the available schema settings for LDAP User Import.  Fields are optional unless otherwise noted.

Schema FieldDescriptionExample
User
User Type
The

LDAP user object class type

(Required)

user,!computer

inetOrgPerson

posixAccount

User Name
Username

User name attribute field of the user

(Required)

sAMAccountName

cn

uid

User First NameFirst Name attribute field of the usergivenName
User Last NameLast Name attribute field of the user
sn
surName
User DescriptionDescription attribute field of the userdescription
User EmailEmail attribute field of the usermail
User TelephoneTelephone attribute field of the usertelephoneNumber
User CompanyCompany attribute field of the usercompany
User DepartmentDepartment attribute field of the userdepartment
User TitleTitle attribute field of the usertitle
User CountryCountry attribute field of the user
co
country
User CityCity attribute field of the user
l
city
User Postal CodePostal
Code
code attribute field of the userpostalCode
User Post Office BoxPost
Office Box
office box attribute field of the userpostOfficeBox
User Street AddressStreet
Address
address attribute field of the userstreetAddress
User ProvinceProvince attribute field of the user
st
province
Group
Group Type

LDAP attribute objectClass value

(Required)

group

groupOfUniqueNames

Group
Name
Name 

Name attribute field of the user group

(Required)

cn
Group
Description
Description Description attribute field of the user groupdescription
Group Membership
Group Membership Strategy

Strategy of resolving group membership of the user

  • MEMBER_OF - default, recommended
  • MEMBER - not recommended, use only if MEMBER_OF is not supported by the LDAP server due to potential performance issues  
Group Membership Attribute
Select MEMBER_OF or MEMBER from pick-list
Group Membership Group membership attribute field of the user

memberOf

member

LDAP Authentication

To see the schema settings for LDAP Authentication, click the Schema Settings expand button in the Enable LDAP Authentication area of the LDAP Configuration page:

Image Added

Schema FieldDescriptionExample
Account
Account Type

The LDAP user object class type

(Required)

user

inetOrgPerson

posixAccount

Account Name
Username

Name attribute field of the account

(Required)

sAMAccountName

cn

uid

Account Display Name

Display name attribute field of the account

(Required)

displayName
Account EmailEmail attribute field of the accountmail