HPE FlexNetwork 7500 Series Security Configuration Manual page 61

Table of Contents

Advertisement

Setting the LDAP server timeout period
If the device sends a bind or search request to an LDAP server without receiving the server's
response within the server timeout period, the authentication or authorization request times out.
Then, the device tries the backup authentication or authorization method. If no backup method is
configured in the ISP domain, the device considers the authentication or authorization attempt a
failure.
To set the LDAP server timeout period:
Step
1.
Enter system view.
2.
Enter LDAP server view.
3.
Set the LDAP server
timeout period.
Configuring administrator attributes
To configure the administrator DN and password for binding with the LDAP server during LDAP
authentication:
Step
1.
Enter system view.
2.
Enter LDAP server view.
3.
Specify the administrator
DN.
4.
Configure the
administrator password.
Configuring LDAP user attributes
To authenticate a user, an LDAP client must complete the following operations:
1.
Establish a connection to the LDAP server.
2.
Obtain the user DN from the LDAP server.
3.
Use the user DN and the user's password to bind with the LDAP server.
LDAP provides a DN search mechanism for obtaining the user DN. According to the mechanism, an
LDAP client sends search requests to the server based on the search policy determined by the LDAP
user attributes of the LDAP client.
The LDAP user attributes include:
Search base DN.
Search scope.
Username attribute.
Username format.
User object class.
If the LDAP server contains many directory levels, a user DN search starting from the root directory
can take a long time. To improve efficiency, you can change the start point by specifying the search
base DN.
Command
system-view
ldap server server-name
server-timeout time-interval
Command
system-view
ldap server server-name
login-dn dn-string
login-password { cipher |
simple } string
47
Remarks
N/A
N/A
By default, the LDAP server timeout
period is 10 seconds.
Remarks
N/A
N/A
By default, no administrator DN is
specified.
The administrator DN specified on
the device must be the same as the
administrator DN configured on the
LDAP server.
By default, no administrator
password is specified.

Advertisement

Table of Contents
loading

Table of Contents