Servicing The Network Management Module; Configuring/Commissioning/Testing Ldap; Commissioning - Eaton Network-M2 User Manual

Ups network management card
Hide thumbs Also See for Network-M2:
Table of Contents

Advertisement

4 Servicing the Network Management Module

4.1 Configuring/Commissioning/Testing LDAP

4.1.1 Commissioning

Refer to the
section Contextual help>>>Settings>>>Local users
4.1.1.1 Configuring connection to LDAP database
This step configures the LDAP client of the network module to request data from an LDAP base.
1.
Activate LDAP.
2.
Define security parameters according to LDAP servers' requirements.
3.
Configure primary server (and optionally a secondary one).
4.
If security configuration needs server certificate verification, import your LDAP server certificate.
Refer to the section   to get help on certificate import.
a.
In case LDAP server certificate is self-signed, import the self-signed certificate in the Trusted remote certificate list
for LDAP service.
in case LDAP server certificate has been signed by a CA, import the corresponding CA in the  Certificate authorities
b.
(CA)  list for LDAP service.
5.
Configure credentials to bind with the LDAP server or select anonymous if no credentials are required.
Configure the Search base DN .
6.
7.
Configure the request parameters (see examples below).
4.1.1.1.1 Typical request parameters
Parameter
OpenLDAP
User base DN
ou=users, dc=example, dc=com
User name attribute
uid
UID attribute
uidNumber
Group base DN
ou=groups, dc=example, dc=com
Group name attribute
gid
GID attribute
gidNumber
4.1.1.2 Testing connection to LDAP database
Refer to the section Information>>>CLI>>>ldap-test to get help on the CLI command.
To test connection to the LDAP database:
1.
Connect to the CLI.
2.
Launch ldap-test --checkusername command.
3.
In case of error, use the  verbose option of the command to investigate the reason.
4.1.1.3 Map remote users to profile
This step is mandatory and configures the Network module to give permissions to the LDAP users.
Users not belonging to a group mapped on a profile will be rejected.
to get help on the configuration.
Active Directory™ with POSIX
account activated
ou=users, dc=example, dc=com 
uid
uidNumber
ou=groups, dc=example, dc=com
gid
gidNumber
Servicing the Network Management Module  –  159
Configuring/Commissioning/Testing LDAP
Active Directory™
ou=users, dc=example, dc=com
sAMAccountName
objectSid:S-1-5-xx-yy-zz (domain SID)
ou=groups, dc=example, dc=com
sAMAccountName
objectSid:S-1-5-xx-yy-zz (domain SID)

Hide quick links:

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the Network-M2 and is the answer not in the manual?

Table of Contents

Save PDF