Black Box iCOMPEL 2U Series User Manual page 129

Table of Contents

Advertisement

To begin with, it is important to understand the difference between the iCOMPEL and the LDAP security models:
The basic iCOMPEL security model prevents access to system features unless a user is authenticated and has explicit
permissions.
In the LDAP security model, a user is considered to have permission if an LDAP filter matches entries in the directory.
Typically, an LDAP filter establishes that a user is a member of a group.
Caution: If you use LDAP, the authentication method switches to HTTP Basic authentication (passwords are not
encrypted). If this is a concern, communicate over HTTPS.
What follows is guidance for completing each of the fields on the LDAP tab:
Configuration
129
Fallback User
129
Bind
129
FTP User
130
HTTP User
130
HTTP Permissions
131
Ad Hoc Users
131
Configuration:
You must check the Enable LDAP box to allow the iCOMPEL to use LDAP.
You must enter the Primary LDAP Server hostname and port and choose the Server Encryption.
The Server Encryption types are:
None – No encryption (passwords are sent in clear text) (standard LDAP port is 389).
SSL – iCOMPEL encrypts all communications with the LDAP server using SSL (standard LDAP port is 636).
TLS – iCOMPEL encrypts all communications with the LDAP server using TLS (standard LDAP port is 389).
The Certification Authority (CA) Certificate is required when SSL or TLS encryption is used. The certificate is required to be
in PEM format.
Note: Microsoft Active Directory does not support LDAP over TLS and by default LDAP requires additional configuration
of the Active Directory server.
Fallback User:
The fallback user can always login to the iCOMPEL and perform management tasks, even when LDAP authentication is not
working.
Enter the username and password that you wish to use to manage the iCOMPEL in the event of problems with the LDAP
setup.
Recommendation: Use a very strong password for the fallback user password.
Bind:
Select Allow Anonymous Bind to use anonymous binding to the LDAP server. Otherwise select Bind using DN and
Copyright © 2010-2013 Black Box Network Services. All Rights Reserved.
724-746-5500 | blackbox.com
Setup
129

Advertisement

Table of Contents
loading

This manual is also suitable for:

Icompel vesa seriesIcompel ops series

Table of Contents