Novell SENTINEL 6.1 SP2 - INSTALLATION GUIDE 02-2010 Installation Manual page 64

Hide thumbs Also See for SENTINEL 6.1 SP2 - INSTALLATION GUIDE 02-2010:
Table of Contents

Advertisement

Parameter
Anonymous searches on LDAP
directory
LDAP Directory used
This parameter is displayed only if you
have specified 'y' for anonymous
searches.
LDAP subtree to search for users
This parameter is displayed only if you
have specified 'y' for anonymous
searches.
Filename of the LDAP server certificate
64
Sentinel 6.1 Installation Guide
Description/Action
Specify
to perform anonymous searches on the LDAP
y
directory to fetch the LDAP user DN for authentication
based on Sentinel username. Otherwise, specify
default value is
.
y
You can search the LDAP directory anonymously to fetch
the LDAP user DN based on the Sentinel LDAP
username to perform LDAP authentication, by using an
LDAP connection that does not use a username or
password. For more information on anonymous
searches, see
Section 5 "Anonymous authentication"
(http://www.ietf.org/rfc/rfc2829.txt).
For Active Directory, if you specify
LOGON user object must be given appropriate list
permission and read access to
attributes. For more information, see
objectclass
Configuring Active Directory to Allow Anonymous
Queries
(http://support.microsoft.com/kb/320528).
For Windows Server 2003, you must perform additional
configuration. For more information, see
Active Directory on Windows Server 2003 (http://
support.microsoft.com/kb/326690/en-us).
If you specify n, complete the LDAP configuration and
perform the steps mentioned in the section
Authentication Without Performing Anonymous
Searches" on page
65.
Specify 1 for Novell eDirectory or 2 for Active Directory.
The default value is 1.
The subtree in the directory that has the user objects.
The following are examples for specifying the subtree in
eDirectory and Active Directory:
eDirectory:
ou=users,o=novell
NOTE: For eDirectory, if no subtree is specified,
then the search is run on the entire directory.
Active Directory:
CN=users,DC=TESTAD,DC=provo,
DC=novell,DC=com
NOTE: For Active Directory, the subtree cannot be
blank.
The filename of the eDirectory/Active Directory CA
certificate that you have copied in
. The
n
y
, the ANONYMOUS
sAMAccountName
and
Configuring
"LDAP
Step
3.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel 6.1 sp2

Table of Contents