User's Manual
Using the CMC Directory Service 281
4
Unbind and perform a bind with the user's DN and password.
5
If the bind fails, then the login fails.
If these steps succeed then the user is considered authenticated. The next
phase is authorization. The CMC stores a maximum of 5 groups and their
corresponding privileges. A user has the option to be added to multiple
groups within the directory service. If the user is a member of multiple
groups, then the user obtains the privileges of all their groups.
The authorization steps are:
1
Search through each configured group for the user's DN within the
member
or
uniqueMember
attributes. This field can be configured by the
administrator.
2
For every group the user is a member of, add their privileges together.
Configuring Generic LDAP Directory Service Using CMC Web-Based
Interface
You can use the Generic Lightweight Directory Access Protocol (LDAP)
Service to configure your software to provide access to the CMC. LDAP
allows you to add and control the CMC user privileges of your existing users.
NOTE: To configure LDAP settings for the CMC, you must have Chassis
Configuration Administrator privilege.
For more information about LDAP configuration configuring Generic LDAP,
see "Using the CMC with Generic LDAP" on page 279.
To view and configure LDAP, follow these steps:
1
Log in to the Web interface.
2
Click the
User Authentication
tab, and then click the
Directory Services
subtab. The
Directory Services
page appears.
3
Click the radio button associated with Generic LDAP.
4
Configure the options shown and click
Apply
.
The following configuration options are available.