HP MSR Series Configuration Manual page 59

Hpe flexnetwork msr router series
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Username format.
User object class.
If the LDAP server contains many directory levels, a user DN search starting from the root directory
can take a long time. To improve efficiency, you can change the start point by specifying the search
base DN.
To configure LDAP user attributes:
Step
1.
Enter system view.
2.
Enter LDAP server view.
3.
Specify the user search base
DN.
4.
(Optional.) Specify the user
search scope.
5.
(Optional.) Specify the
username attribute.
6.
(Optional.) Specify the
username format.
7.
(Optional.) Specify the user
object class.
Configuring an LDAP attribute map
Configure an LDAP attribute map to define a list of LDAP-AAA attribute mapping entries. To apply the
LDAP attribute map, specify the name of the LDAP attribute map in the LDAP scheme used for
authorization.
The LDAP attribute map feature enables the device to convert LDAP attributes obtained from an
LDAP authorization server to device-recognizable AAA attributes based on the mapping entries.
Because the device ignores unrecognized LDAP attributes, configure the mapping entries to include
important LDAP attributes that should not be ignored.
An LDAP attribute can be mapped only to one AAA attribute. Different LDAP attributes can be
mapped to the same AAA attribute.
To configure an LDAP attribute map:
Step
1.
Enter system view.
2.
Create an LDAP attribute
map and enter LDAP
attribute map view.
Command
system-view
ldap server server-name
search-base-dn base-dn
search-scope { all-level |
single-level }
user-parameters
user-name-attribute
{ name-attribute | cn | uid }
user-parameters
user-name-format
{ with-domain |
without-domain }
user-parameters
user-object-class
object-class-name
Command
system-view
ldap attribute-map map-name
44
Remarks
N/A
N/A
By default, no user search base
DN is specified.
By default, the user search scope
is all-level.
By default, the username attribute
is cn.
By default, the username format is
without-domain.
By default, no user object is
specified, and the default user
object class on the LDAP server is
used.
The default user object class for
this command varies by device
model.
Remarks
N/A
By default, no LDAP attribute maps
exist.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents