HP 5920 Series Configuration Manual page 21

Hide thumbs Also See for 5920 Series:
Table of Contents

Advertisement

The search operation constructs search conditions and obtains the directory resource information of
the LDAP server.
In LDAP authentication, the client completes the following operations:
1.
Uses the LDAP server administrator DN to bind with the LDAP server. After the binding is created,
the client establishes a connection to the server and obtains the right to search.
2.
Constructs search conditions by using the username in the authentication information of a user. The
specified root directory of the server is searched and a user DN list is generated.
3.
Binds with the LDAP server by using each user DN and password. If a binding is created, the user
is considered legal.
The LDAP authorization, the client performs the same operations as in LDAP authentication. When the
client constructs search conditions, it obtains both authorization information and the user DN list.
If the authorization information meets the authorization requirements, the authorization process
ends.
If the authorization information does not meet the authorization requirements, the client sends an
administrator bind request to the LDAP server. This operation obtains the right to search for
authorization information about users on the user DN list.
Basic LDAP packet exchange process
The following example illustrates the basic packet exchange process during LDAP authentication and
authorization for a Telnet user.
Figure 7 Basic packet exchange process for LDAP authentication of a Telnet user
Host
1) The user logs in by Telnet
10) The user logs in successfully
The basic packet exchange process is as follows:
1.
A Telnet user initiates a connection request and sends the username and password to the LDAP
client.
2.
After receiving the request, the LDAP client establishes a TCP connection with the LDAP server.
LDAP client
2) Establish a TCP connection
3) Administrator bind request
4) Bind response
5) User DN search request
6) Search response
7) User DN bind request
8) Bind response
9) Authorization
10
LDAP server

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

5900 series

Table of Contents