Novell SENTINEL 6.1 SP2 - INSTALLATION GUIDE 02-2010 Installation Manual page 65

Hide thumbs Also See for SENTINEL 6.1 SP2 - INSTALLATION GUIDE 02-2010:
Table of Contents

Advertisement

9 Enter one of the following:
: to accept the entered values
 y
: to enter new values
 n
 q
: to quit the configuration
On successful configuration:
The LDAP server certificate is added to a keystore named
config/ldap_server.keystore
The
auth.login
<Install_Directory>/config
10 Enter
to restart the Sentinel service.
y
IMPORTANT: If there are any errors, revert the changes made to the
configuration.xml
cp -p auth.login.sav auth.login
cp -p configuration.xml.sav configuration.xml
LDAP Authentication Without Performing Anonymous Searches
1 Ensure that you have performed Step 1 through Step 10 in section
6.1 Server for LDAP Authentication" on page
on LDAP
directory.
2 Specify the LDAP user DN that is used for non anonymous LDAP authentication, while
creating the LDAP user account in Sentinel Control Center. For more information, see
"Creating an LDAP User Account for
Alternatively, for Active Directory, you can perform LDAP authentication without anonymous
searches by using the
userPrinicipalName
1 Ensure that you have performed Step 1 through Step 10 in section
6.1 Server for LDAP Authentication" on page
on LDAP
directory.
2 Ensure that the
userPrinicipalName
Active Directory user.
For more information, see
library/ms680857(VS.85).aspx).
3 On the Sentinel server, edit the
file:
auth.login
LdapLogin {
com.sun.security.auth.module.LdapLoginModule required
userProvider="ldap://LDAP server IP:636/DN of the Container that
contains the user objects"
authIdentity="{USERNAME}@Domain Name"
userFilter="(&(sAMAccountName={USERNAME})(objectclass=user))"
useSSL=true;
};
For example:
.
and
configuration.xml
directory are updated to enable LDAP authentication.
configuration files in the
62, and you specified
Sentinel" in the Sentinel 6.1 User Guide.
attribute:
62, and you specified
attribute is set to <sAMAccountName@domain> for the
User-Principal-Name Attribute (http://msdn.microsoft.com/en-us/
section in the
LdapLogin
<Install_Directory>/
configuration files in the
auth.login
directory:
config
"Configuring the Sentinel
for
n
"Configuring the Sentinel
for
n
<Install Directory>/config/
and
Anonymous searches
Anonymous searches
Installing Sentinel 6.1 SP2
65

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel 6.1 sp2

Table of Contents