LDAP Settings


From version 5.6.0 onwards, MCM9000 allows LDAP settings. It can be found under, 

System → System Information → LDAP Settings



The network interface option is available from version 6.0.2 onwards.


FieldsDescription

Enabled

When checked, enables LDAP. 

** Version 6.3.13 onwards when checked, enables LDAP proxy interface and LDAP Server Host with a cluster of machine.

Host

LDAP host.

** Version 6.3.13 onwards of MCM9000 allows LDAP Server Host with a cluster of machine besides handling single LDAP server. Configure the LDAP DNS IP under Networks → DNS configuration.

Port

LDAP port.

Secured

When checked, provides secure LDAP connection. Relevant for cloud based LDAP.

Bind DN

User name configured for LDAP authentication.

Bind Password

Password configured for LDAP authentication.

Base DN to Search

The Base DN is the starting point an LDAP server uses when searching for users authentication within your Directory.
Attribute to User LoginThe login attribute is the name used for the bind to the LDAP database. The default login attribute is uid.
User Search FilterSearch Filter is a basic LDAP Query for searching users based on mapping of username to a particular LDAP attribute.
Group Search DNSearch filter to search specific group.
Attribute of Group MembershipSpecifies the naming attribute for a group container, if groups resides in a container.
Network

Select the network interface for LDAP settings. Auto for automatic selection. 

** Available only from version 6.0.2

** Version 6.3.13 onwards, allows activating LDAP proxy interface (other than Auto) which allows the user to pass through specific usage. To ensure the selected interface is activated, SSH to the MCM9000 and use the logger ldap.


To refresh the page, click on the refresh icon  at the top-right corner of the screen.


Note
1. On each client environment the settings can be different.
2. The "Network" section need to be define to the network card that have access to the LDAP server.
3. The "Host" (is specified by name and not IP) and will work only if the DNS and the LDAP server are at the same network card.