User's Manual

284 Using the CMC Directory Service
4
Unbind and perform a bind with the user's DN and password.
5
If the bind fails, then the login fails.
If these steps succeed then the user is considered authenticated. The next
phase is authorization. CMC stores a maximum of 5 groups and their
corresponding privileges. A user has the option to be added to multiple
groups within the directory service. If the user is a member of multiple
groups, then the user obtains the privileges of all their groups.
The authorization steps are:
1
Search through each configured group for the user's DN within the
member
or
uniqueMember
attributes. This field can be configured by the
administrator.
2
For every group the user is a member of, add their privileges together.
Configuring Generic LDAP Directory Service Using CMC Web-Based
Interface
You can use the Generic Lightweight Directory Access Protocol (LDAP)
Service to configure your software to provide access to CMC. LDAP allows
you to add and control the CMC user privileges of your existing users.
NOTE: To configure LDAP settings for CMC, you must have Chassis Configuration
Administrator privilege.
For more information about LDAP configuration configuring Generic LDAP,
see "Using CMC with Generic LDAP" on page 282.
To view and configure LDAP, follow these steps:
1
Log in to the Web interface.
2
Click the
User Authentication
tab, and then click the
Directory Services
subtab. The
Directory Services
page appears.
3
Click the radio button associated with Generic LDAP.
4
Configure the options shown and click
Apply
.
The following configuration options are available.